From 38fa4e7ca790cd8550310e6666fc8070fa89a69d Mon Sep 17 00:00:00 2001 From: FoxxMD Date: Wed, 16 Apr 2025 12:33:12 -0400 Subject: [PATCH] feat: Examples and more readme instructions --- README.md | 52 ++++++++++++++++++- example_services/README.md | 4 ++ .../compose-ext-auth-service.yaml | 16 ++++++ .../compose-external-service.yaml | 0 .../compose-internal-service.yaml | 0 traefik_external/compose.yaml | 2 +- traefik_internal/logdy/logdy.json | 2 +- .../traefik/static_config/traefik.yaml | 10 ++-- {traefik-kop => traefik_kop}/.env.example | 0 {traefik-kop => traefik_kop}/compose.yaml | 0 10 files changed, 78 insertions(+), 8 deletions(-) create mode 100644 example_services/README.md create mode 100644 example_services/compose-ext-auth-service.yaml rename {traefik-kop => example_services}/compose-external-service.yaml (100%) rename {traefik-kop => example_services}/compose-internal-service.yaml (100%) rename {traefik-kop => traefik_kop}/.env.example (100%) rename {traefik-kop => traefik_kop}/compose.yaml (100%) diff --git a/README.md b/README.md index 9188193..2b966f7 100644 --- a/README.md +++ b/README.md @@ -42,4 +42,54 @@ While not *necessary* you should also create two more [externally-managed](https ```shell docker network create --driver=overlay --internal --attachable kop_overlay docker network create --driver=overlay --internal --attachable crowdsec_overlay -``` \ No newline at end of file +``` + +# Setup + +If you do not plan on using a certain feature (authentik, crowdsec) make sure to comment out or remove all mentions of it. + +### Placeholders + +There are two placeholder sites used in the examples stacks: + +* `CHANGEME.casa` represents the internal-only (LAN-accessible) domain used with [traefik_internal](/traefik_internal/) +* `CHANGEME.com` represents the public-facing domain used with [traefik_external](/traefik_external/) through Cloudflare Tunnel, Authentik, and Crowdsec + +You need to Find-And-Replace all instances of these sites with your own domains. + +Additionally: + +* Find-And-Replace all *other* instances of `CHANGEME` with your own values +* Find-And-Replace instances of `192.168.` with your own IP:HOST + +### Required Stacks + +To run any of the end-user examples in [example_services](/example_services/) you will, at a minimum, need to setup + +* [traefik_internal](/traefik_internal/) and/or [traefik_external](/traefik_external/) +* and an instance of [traefik_kop](/traefik_kop/) running on this host + +# Usage + +* View **internal** network Traefik dashboard at `https://traefik-internal.CHANGEME.casa` +* View **internal** network access logs at `https://traefik-log-internal.CHANGEME.casa` +* View **external** network Traefik dashboard at `https://traefik-external.CHANGEME.casa` +* View **external** network access logs at `https://traefik-log-external.CHANGEME.casa` + +Create a service on the internal network viewable at `http://echo1.CHANGEME.casa` + +```shell +docker compose -f examples_services/compose-internal-service.yaml up +``` + +Create a service on the external network viewable at `http://echo1.CHANGEME.com` + +```shell +docker compose -f examples_services/compose-external-service.yaml up +``` + +Create a service on the external network, behind Authentik, viewable at `http://echo2.CHANGEME.com` + +```shell +docker compose -f examples_services/compose-ext-auth-service.yaml up +``` diff --git a/example_services/README.md b/example_services/README.md new file mode 100644 index 0000000..e314414 --- /dev/null +++ b/example_services/README.md @@ -0,0 +1,4 @@ +These are examples of end-user services that utilize all of the other parts of this repository. To use any of these uou will, at minimum, need to setup: + +* [traefik_internal](/traefik_internal/) and/or [traefik_external](/traefik_external/) +* and an instance of [traefik_kop](/traefik_kop/) running on this host \ No newline at end of file diff --git a/example_services/compose-ext-auth-service.yaml b/example_services/compose-ext-auth-service.yaml new file mode 100644 index 0000000..e2ac905 --- /dev/null +++ b/example_services/compose-ext-auth-service.yaml @@ -0,0 +1,16 @@ +# example service that is routed through Internal Traefik +services: + echo: + image: mendhak/http-https-echo:36 + networks: + - public_overlay + labels: + traefik.enable: true + traefik.http.routers.echo2.rule: Host(`echo2.CHANGEME.com`) + traefik.http.services.echo2.loadbalancer.server.port: 8080 + traefik.http.routers.echo2.middlewares: authentik-proxy@docker + traefik.docker.network: public_overlay + kop.namespace: public +networks: + internal_overlay: + external: true \ No newline at end of file diff --git a/traefik-kop/compose-external-service.yaml b/example_services/compose-external-service.yaml similarity index 100% rename from traefik-kop/compose-external-service.yaml rename to example_services/compose-external-service.yaml diff --git a/traefik-kop/compose-internal-service.yaml b/example_services/compose-internal-service.yaml similarity index 100% rename from traefik-kop/compose-internal-service.yaml rename to example_services/compose-internal-service.yaml diff --git a/traefik_external/compose.yaml b/traefik_external/compose.yaml index 0e5396b..9606105 100644 --- a/traefik_external/compose.yaml +++ b/traefik_external/compose.yaml @@ -28,7 +28,7 @@ services: traefik.enable: true traefik.http.routers.traefik-dashboard-external.rule: Host(`traefik-external.CHANGEME.casa`) traefik.http.services.traefik-dashboard-external.loadbalancer.server.port: 8080 - kop.traefik-dashboard-external.bind.ip: "192.168.TRAEFIK_INTERNAL.HOST" + kop.traefik-dashboard-external.bind.ip: "192.168.TRAEFIK_INTERNAL_HOST.IP" homepage.group: Monitoring homepage.name: Traefik (External) homepage.icon: https://cdn.jsdelivr.net/gh/selfhst/icons/png/traefik.png diff --git a/traefik_internal/logdy/logdy.json b/traefik_internal/logdy/logdy.json index d022317..d96cdc2 100644 --- a/traefik_internal/logdy/logdy.json +++ b/traefik_internal/logdy/logdy.json @@ -311,7 +311,7 @@ { "id": "m_632328", "name": "additional_info", - "handlerTsCode": "(line: Message): Message | void => {\n\n let external = true;\n let me = false;\n\n const client = line.json_content.ClientHost;\n const host = line.json_content.RequestHost;\n const uaString = line.json_content['request_User-Agent'];\n\n external = !client.includes('192.168.0') && client !== \"2600:1700:1e1f:YOUR:IPV6\";\n me = client === \"192.168.YOUR.IP\" || client === \"2600:1700:1e1f:YOUR:IPV6\"\n\n const urlPattern = /^(?:([A-Za-z]+?):\\/\\/)?(?:[^@\\n]+@)?(?:([A-Za-z]+?)\\.)?([^:\\/\\n?]+)(.*)/;\n\n let hostname = '-',\n subdomain = '-',\n uaUrl;\n\n if (host !== '-') {\n\n const urlMatch = host.match(urlPattern);\n\n if (urlMatch) {\n if (urlMatch[3].includes('.')) {\n subdomain = urlMatch[2];\n hostname = urlMatch[3];\n } else {\n hostname = `${urlMatch[2]}.${urlMatch[3]}`;\n }\n if (external && hostname === \"CHANGEME.casa\") {\n external = false;\n }\n }\n }\n\n const regUrlPattern = /\\+([(http(s)?):\\/\\/(www\\.)?a-zA-Z0-9@:%._\\+~#=]{2,256}\\.[a-z]{2,20}\\b([-a-zA-Z0-9@:%_\\+.~#?&//=]*))/;\n const uaMatch = uaString.match(regUrlPattern);\n if (uaMatch) {\n uaUrl = uaMatch[1];\n }\n\n line.json_content.subdomain = subdomain;\n line.json_content.hostname = hostname;\n line.json_content.external = external;\n line.json_content.me = me;\n line.json_content.uaUrl = uaUrl;\n\n return line;\n}" + "handlerTsCode": "(line: Message): Message | void => {\n\n let external = true;\n let me = false;\n\n const client = line.json_content.ClientHost;\n const host = line.json_content.RequestHost;\n const uaString = line.json_content['request_User-Agent'];\n\n external = !client.includes('192.168.0') && client !== \"2600:1700:1e1f:YOUR:IPV6\";\n me = client === \"192.168.YOUR_HOST.IP\" || client === \"2600:1700:1e1f:YOUR:IPV6\"\n\n const urlPattern = /^(?:([A-Za-z]+?):\\/\\/)?(?:[^@\\n]+@)?(?:([A-Za-z]+?)\\.)?([^:\\/\\n?]+)(.*)/;\n\n let hostname = '-',\n subdomain = '-',\n uaUrl;\n\n if (host !== '-') {\n\n const urlMatch = host.match(urlPattern);\n\n if (urlMatch) {\n if (urlMatch[3].includes('.')) {\n subdomain = urlMatch[2];\n hostname = urlMatch[3];\n } else {\n hostname = `${urlMatch[2]}.${urlMatch[3]}`;\n }\n if (external && hostname === \"CHANGEME.casa\") {\n external = false;\n }\n }\n }\n\n const regUrlPattern = /\\+([(http(s)?):\\/\\/(www\\.)?a-zA-Z0-9@:%._\\+~#=]{2,256}\\.[a-z]{2,20}\\b([-a-zA-Z0-9@:%_\\+.~#?&//=]*))/;\n const uaMatch = uaString.match(regUrlPattern);\n if (uaMatch) {\n uaUrl = uaMatch[1];\n }\n\n line.json_content.subdomain = subdomain;\n line.json_content.hostname = hostname;\n line.json_content.external = external;\n line.json_content.me = me;\n line.json_content.uaUrl = uaUrl;\n\n return line;\n}" } ], "entriesOrder": "desc" diff --git a/traefik_internal/traefik/static_config/traefik.yaml b/traefik_internal/traefik/static_config/traefik.yaml index 510ea52..99ea64b 100644 --- a/traefik_internal/traefik/static_config/traefik.yaml +++ b/traefik_internal/traefik/static_config/traefik.yaml @@ -52,14 +52,14 @@ entryPoints: - main: CHANGEME.casa sans: - "*.CHANGEME.casa" - # remove if you only need one domain - - main: CHANGEME.com - sans: - - "*.CHANGEME.com" + # add if you only need certs for more than one domain + # - main: CHANGEME.dev + # sans: + # - "*.CHANGEME.dev" certificatesResolvers: internalresolver: acme: - email: "info@CHANGEME.com" + email: "info@CHANGEME.casa" storage: "/letsencrypt/acme.json" dnsChallenge: provider: cloudflare diff --git a/traefik-kop/.env.example b/traefik_kop/.env.example similarity index 100% rename from traefik-kop/.env.example rename to traefik_kop/.env.example diff --git a/traefik-kop/compose.yaml b/traefik_kop/compose.yaml similarity index 100% rename from traefik-kop/compose.yaml rename to traefik_kop/compose.yaml -- 2.51.2