infrastructure/ansible/roles/traefik/files/docker-compose.yml
Jake Howard 4eab0d4f01
Don't mount docker socket to traefik
It was already configured to use the proxy, and was running as non-root
anyway, so likely didn't have access to it in the first place.
2022-08-16 09:38:27 +01:00

63 lines
1.2 KiB
YAML

version: "2.3"
services:
traefik:
image: traefik:v2.8
user: "{{ docker_user.id }}"
environment:
- CF_DNS_API_TOKEN={{ cloudflare_api_token }}
volumes:
- /tmp/traefik-logs:/var/log/traefik
- ./traefik:/etc/traefik
restart: unless-stopped
ports:
- 80:80
- 443:443
- "{{ private_ip }}:8080:8080"
depends_on:
- docker_proxy
- shenanigans
networks:
- default
- traefik
- proxy_private
docker_proxy:
image: tecnativa/docker-socket-proxy:latest
restart: unless-stopped
environment:
- CONTAINERS=1
- INFO=1
volumes:
- /var/run/docker.sock:/var/run/docker.sock:ro
networks:
- proxy_private
logging:
driver: none
shenanigans:
image: nginx:alpine
restart: unless-stopped
volumes:
- /opt/traefik/nginx.conf:/etc/nginx/conf.d/default.conf:ro
networks:
- proxy_private
logging:
driver: none
certs:
image: slocomptech/traefik-cert-extract:latest
restart: unless-stopped
networks: []
volumes:
- ./traefik:/data:ro
- ./certs:/config/certs
logging:
driver: none
networks:
traefik:
external: true
proxy_private:
internal: true