feat: Add traefik configuration for consensus TCP port, open it in

firewall
This commit is contained in:
Yury Akudovich
2024-08-13 13:32:10 +02:00
parent bf186104d4
commit 5bdeb0fcfa
2 changed files with 19 additions and 3 deletions

View File

@ -49,6 +49,14 @@
source: "{{ loadbalancer_ip | mandatory }}" source: "{{ loadbalancer_ip | mandatory }}"
jump: ACCEPT jump: ACCEPT
- name: Allow consensus port traffic from any IP
when: enable_consensus
ansible.builtin.iptables:
chain: INPUT
protocol: tcp
destination_port: "{{ consensus_port }}"
jump: ACCEPT
- name: Set default policy to DROP - name: Set default policy to DROP
ansible.builtin.iptables: ansible.builtin.iptables:
chain: INPUT chain: INPUT

View File

@ -8,10 +8,13 @@ services:
- "--log.level=INFO" - "--log.level=INFO"
- "--providers.docker=true" - "--providers.docker=true"
- "--providers.docker.exposedbydefault=false" - "--providers.docker.exposedbydefault=false"
- "--entrypoints.web.address=:80" - "--entryPoints.web.address=:80"
- "--entrypoints.external_node_health.address=:3080" - "--entryPoints.external_node_health.address=:3080"
{% if enable_consensus %}
- "--entryPoints.external_node_consensus.address=:{{ consensus_port }}"
{% endif %}
{% if enable_tls %} {% if enable_tls %}
- "--entrypoints.websecure.address=:443" - "--entryPoints.websecure.address=:443"
- "--certificatesresolvers.en_resolver.acme.tlschallenge=true" - "--certificatesresolvers.en_resolver.acme.tlschallenge=true"
- "--certificatesresolvers.en_resolver.acme.storage=/letsencrypt/acme.json" - "--certificatesresolvers.en_resolver.acme.storage=/letsencrypt/acme.json"
- "--certificatesresolvers.myresolver.acme.email={{ acme_email }}" - "--certificatesresolvers.myresolver.acme.email={{ acme_email }}"
@ -76,6 +79,11 @@ services:
{% if enable_basic_auth %} {% if enable_basic_auth %}
- "traefik.http.routers.external_node_main.middlewares=external_node_auth" - "traefik.http.routers.external_node_main.middlewares=external_node_auth"
- "traefik.http.middlewares.external_node_auth.basicauth.users={{ basic_auth_secret }}" - "traefik.http.middlewares.external_node_auth.basicauth.users={{ basic_auth_secret }}"
{% endif %}
{% if enable_consensus %}
- "traefik.tcp.services.external_node_consensus.loadbalancer.server.port={{ consensus_port }}"
- "traefik.tcp.routers.external_node_consensus.entrypoints=external_node_consensus"
- "traefik.tcp.routers.external_node_consensus.service=external_node_consensus"
{% endif %} {% endif %}
expose: expose:
- {{ rpc_http_port }} - {{ rpc_http_port }}