# Traefik static configuration — DEV host (prkl10) ONLY. # # Identical to traefik.yml except for the ACME challenge type. Select it with # TRAEFIK_STATIC_CONFIG=./traefik.dev.yml in .env. # # Keep any other change in BOTH files, or dev stops mirroring prod. api: dashboard: true debug: false experimental: plugins: bouncer: moduleName: github.com/maxlerebourg/crowdsec-bouncer-traefik-plugin version: v1.3.5 geoblock: moduleName: github.com/PascalMinder/geoblock version: v0.2.8 entryPoints: http: address: ":80" http: redirections: entryPoint: to: https scheme: https permanent: true # priority 1 keeps this redirect BELOW normal routers, which default # to a priority derived from rule length. That is what allows basil's # Host(`localhost`) HTTP router to keep serving without redirecting. # Do not raise this value. priority: 1 https: address: ":443" # Backends here use self-signed certs (harbor, etc). This disables verification # of upstream TLS for ALL services — matches prod, but it is a real weakening. # Prefer per-service serversTransport if you ever narrow this. serversTransport: insecureSkipVerify: true providers: docker: endpoint: "unix:///var/run/docker.sock" exposedByDefault: false network: traefik httpClientTimeout: 0 file: filename: /config.yml watch: true certificatesResolvers: letsencrypt: acme: email: pkartch@gmail.com storage: acme.json # DNS-01, not HTTP-01. Public port 80 forwards to prod (10.20.10.18) so # that it can renew production certs, which means an HTTP-01 challenge for # a dev hostname lands on prod's Traefik, finds no matching router, and # returns 404. DNS-01 proves control via a Route 53 TXT record instead and # needs no inbound connectivity at all. # # Credentials come from AWS_* in .env (IAM user traefik-dev-dns01, scoped # to the backyardhoneycomb.com and pkartchner.com zones). dnsChallenge: provider: route53 # Check propagation against public resolvers. The LAN resolvers # (Pi-hole / Technitium) answer authoritatively for internal names and # will not see the _acme-challenge TXT records, so leaving this unset # makes the pre-check hang until it times out. resolvers: - "1.1.1.1:53" - "8.8.8.8:53" log: level: INFO accessLog: filePath: "/var/log/traefik/access.log"