infrastructure/ansible/roles/traefik/files/file-provider-main.yml
Jake Howard b2656bdf43
All checks were successful
/ terraform (push) Successful in 33s
/ ansible (push) Successful in 1m36s
Make vaultwarden VPN only
The first service to go dark...
2024-03-21 23:20:27 +00:00

25 lines
594 B
YAML

http:
middlewares:
compress:
compress: {}
# https://paramdeo.com/blog/opting-your-website-out-of-googles-floc-network
floc-block:
headers:
customResponseHeaders:
Permissions-Policy: interest-cohort=()
tailscale-only:
ipWhiteList:
sourceRange:
- "{{ tailscale_cidr }}"
- "{{ tailscale_cidr_ipv6 }}"
private-access:
ipWhiteList:
sourceRange:
- "{{ tailscale_cidr }}"
- "{{ tailscale_cidr_ipv6 }}"
- "{{ nebula.cidr }}"
- "{{ pve_hosts.internal_cidr }}"