auot02 with frakin' nginx doesnt work
This commit is contained in:
@@ -1,6 +1,6 @@
|
|||||||
systemd:
|
systemd:
|
||||||
service:
|
service:
|
||||||
homeassistant:
|
container-homeassistant:
|
||||||
Unit:
|
Unit:
|
||||||
Description: Homeassistant
|
Description: Homeassistant
|
||||||
After: network-online.target local-fs.target
|
After: network-online.target local-fs.target
|
||||||
@@ -10,7 +10,7 @@ systemd:
|
|||||||
ExecStop: /usr/bin/podman stop homeassistant
|
ExecStop: /usr/bin/podman stop homeassistant
|
||||||
Install:
|
Install:
|
||||||
WantedBy: multi-user.target
|
WantedBy: multi-user.target
|
||||||
homeassistant-configurator:
|
container-homeassistant-configurator:
|
||||||
Unit:
|
Unit:
|
||||||
Description: Homeassistant Configurator
|
Description: Homeassistant Configurator
|
||||||
After: network-online.target local-fs.target
|
After: network-online.target local-fs.target
|
||||||
@@ -20,7 +20,7 @@ systemd:
|
|||||||
ExecStop: /usr/bin/podman stop homeassistant-configurator
|
ExecStop: /usr/bin/podman stop homeassistant-configurator
|
||||||
Install:
|
Install:
|
||||||
WantedBy: multi-user.target
|
WantedBy: multi-user.target
|
||||||
pihole:
|
container-pihole:
|
||||||
Unit:
|
Unit:
|
||||||
Description: pihole
|
Description: pihole
|
||||||
After: network-online.target local-fs.target
|
After: network-online.target local-fs.target
|
||||||
@@ -30,7 +30,7 @@ systemd:
|
|||||||
ExecStop: /usr/bin/podman stop pihole
|
ExecStop: /usr/bin/podman stop pihole
|
||||||
Install:
|
Install:
|
||||||
WantedBy: multi-user.target
|
WantedBy: multi-user.target
|
||||||
docker-registry:
|
container-docker-registry:
|
||||||
Unit:
|
Unit:
|
||||||
Description: Docker Registry
|
Description: Docker Registry
|
||||||
After: network-online.target local-fs.target
|
After: network-online.target local-fs.target
|
||||||
@@ -40,73 +40,111 @@ systemd:
|
|||||||
ExecStop: /usr/bin/podman stop docker-registry
|
ExecStop: /usr/bin/podman stop docker-registry
|
||||||
Install:
|
Install:
|
||||||
WantedBy: multi-user.target
|
WantedBy: multi-user.target
|
||||||
haproxy:
|
container-zwave2mqtt:
|
||||||
enabled: True
|
Unit:
|
||||||
overwrite: True
|
Description: zwave2mqtt - yes
|
||||||
global:
|
After: network-online.target local-fs.target
|
||||||
stats:
|
Requires: io.podman.service
|
||||||
enable: True
|
Service:
|
||||||
socketpath: /var/lib/haproxy/stats
|
ExecStart: /usr/bin/podman start -a zwave2mqtt
|
||||||
mode: 660
|
ExecStop: /usr/bin/podman stop zwave2mqtt
|
||||||
level: admin
|
Install:
|
||||||
# Optional extra bind parameter, for example to set the owner/group on the socket file
|
WantedBy: multi-user.target
|
||||||
extra: user haproxy group haproxy
|
nginx:
|
||||||
ssl-default-bind-ciphers: "ECDHE-RSA-AES128-GCM-SHA256:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-RSA-AES128-SHA256:ECDHE-RSA-AES256-SHA384"
|
install_from_repo: False
|
||||||
ssl-default-bind-options: "no-sslv3 no-tlsv10 no-tlsv11"
|
server:
|
||||||
|
config:
|
||||||
user: haproxy
|
events:
|
||||||
group: haproxy
|
worker_connections: 100
|
||||||
chroot:
|
|
||||||
enable: True
|
|
||||||
path: /var/lib/haproxy
|
|
||||||
daemon: True
|
|
||||||
defaults:
|
|
||||||
stats:
|
|
||||||
- enable
|
|
||||||
- uri: '/admin?stats'
|
|
||||||
- realm: 'Haproxy\ Statistics'
|
|
||||||
- auth: 'admin1:AdMiN123'
|
|
||||||
errorfiles:
|
|
||||||
400: /etc/haproxy/errors/400.http
|
|
||||||
403: /etc/haproxy/errors/403.http
|
|
||||||
408: /etc/haproxy/errors/408.http
|
|
||||||
500: /etc/haproxy/errors/500.http
|
|
||||||
502: /etc/haproxy/errors/502.http
|
|
||||||
503: /etc/haproxy/errors/503.http
|
|
||||||
504: /etc/haproxy/errors/504.http
|
|
||||||
resolvers:
|
|
||||||
local_dns:
|
|
||||||
options:
|
|
||||||
- nameserver resolvconf 192.168.10.1:53
|
|
||||||
- resolve_retries 3
|
|
||||||
- timeout retry 1s
|
|
||||||
- hold valid 10s
|
|
||||||
listens:
|
|
||||||
stats:
|
|
||||||
bind:
|
|
||||||
- "0.0.0.0:8998"
|
|
||||||
mode: http
|
|
||||||
stats:
|
|
||||||
enable: True
|
|
||||||
uri: "/admin?stats"
|
|
||||||
refresh: "20s"
|
|
||||||
frontends:
|
|
||||||
frontend1:
|
|
||||||
name: auto
|
|
||||||
bind: "*:80"
|
|
||||||
default_backend: auto
|
|
||||||
acls:
|
|
||||||
- host_auto hdr_beg(host) -i auto.
|
|
||||||
use_backends:
|
|
||||||
- auto if host_auto
|
|
||||||
backends:
|
|
||||||
backend1:
|
|
||||||
name: auto
|
|
||||||
balance: roundrobin
|
|
||||||
servers:
|
servers:
|
||||||
server1:
|
managed:
|
||||||
name: auto02
|
default:
|
||||||
host: 127.0.0.1
|
enabled: false
|
||||||
port: 8123
|
status:
|
||||||
check: check
|
enabled: true
|
||||||
|
config:
|
||||||
|
- server:
|
||||||
|
- server_name: _
|
||||||
|
- listen:
|
||||||
|
- 127.0.0.1:80
|
||||||
|
- location /stub_status:
|
||||||
|
- stub_status: ''
|
||||||
|
proxy_auto:
|
||||||
|
enabled: true
|
||||||
|
config:
|
||||||
|
- server:
|
||||||
|
- server_name: auto2 auto2.chaos
|
||||||
|
- listen:
|
||||||
|
- 80 default_server
|
||||||
|
- location /:
|
||||||
|
- proxy_pass: http://127.0.0.1:8123
|
||||||
|
- proxy_set_header: "Host $host"
|
||||||
|
- proxy_http_version: "1.1"
|
||||||
|
- proxy_set_header: "X-Real-IP $remote_addr"
|
||||||
|
- proxy_set_header: "X-Forwarded-For $proxy_add_x_forwarded_for"
|
||||||
|
- proxy_set_header: "Ugrade $http_upgrade"
|
||||||
|
- proxy_set_header: "Connection \"Upgrade\""
|
||||||
|
- location /api/websocket:
|
||||||
|
- proxy_pass: http://127.0.0.1:8123/api/websocket
|
||||||
|
- proxy_set_header: "Host $host"
|
||||||
|
- proxy_http_version: "1.1"
|
||||||
|
- proxy_set_header: "X-Real-IP $remote_addr"
|
||||||
|
- proxy_set_header: "X-Forwarded-For $proxy_add_x_forwarded_for"
|
||||||
|
- proxy_set_header: "Ugrade $http_upgrade"
|
||||||
|
- proxy_set_header: "Connection \"Upgrade\""
|
||||||
|
proxy_auto-conf:
|
||||||
|
enabled: true
|
||||||
|
config:
|
||||||
|
- server:
|
||||||
|
- server_name: auto-conf auto-conf.chaos
|
||||||
|
- listen:
|
||||||
|
- '80'
|
||||||
|
- location /:
|
||||||
|
- proxy_redirect: "off"
|
||||||
|
- proxy_pass: http://127.0.0.1:3218
|
||||||
|
proxy_pihole:
|
||||||
|
enabled: true
|
||||||
|
config:
|
||||||
|
- server:
|
||||||
|
- server_name: pihole pihole.chaos
|
||||||
|
- listen:
|
||||||
|
- '80'
|
||||||
|
- location /admin:
|
||||||
|
- proxy_redirect: "off"
|
||||||
|
- proxy_pass: http://127.0.0.1:8080/admin
|
||||||
|
- add_header: 'Access-Control-Allow-Origin: "*"'
|
||||||
|
- proxy_set_header: 'Access-Control-Allow-Origin: "*"'
|
||||||
|
proxy_docker-reg:
|
||||||
|
enabled: true
|
||||||
|
config:
|
||||||
|
- server:
|
||||||
|
- server_name: docker-registry docker-registry.chaos docker-registry.lan
|
||||||
|
- listen:
|
||||||
|
- '80'
|
||||||
|
- location /:
|
||||||
|
- proxy_redirect: "off"
|
||||||
|
- proxy_pass: http://127.0.0.1:5000
|
||||||
|
- client_max_body_size: '10G'
|
||||||
|
- proxy_set_header: 'Host $host'
|
||||||
|
- proxy_set_header: 'X-Forwarded-For $remote_addr'
|
||||||
|
- proxy_set_header: 'Proxy-Connection ""'
|
||||||
|
- proxy_set_header: 'Access-Control-Allow-Origin "*"'
|
||||||
|
- proxy_set_header: 'Access-Control-Allow-Methods "HEAD, GET, OPTIONS, DELETE"'
|
||||||
|
- proxy_set_header: 'Access-Control-Allow-Headers "Authorization, Accept"'
|
||||||
|
- proxy_set_header: 'Access-Control-Allow-Credentials true'
|
||||||
|
- proxy_set_header: 'Access-Control-Expose-Headers "Docker-Content-Digest"'
|
||||||
|
- add_header: 'Access-Control-Allow-Origin "*"'
|
||||||
|
- add_header: 'Access-Control-Allow-Methods "HEAD, GET, OPTIONS, DELETE"'
|
||||||
|
- add_header: 'Access-Control-Allow-Headers "Authorization, Accept"'
|
||||||
|
- add_header: 'Access-Control-Allow-Credentials true'
|
||||||
|
- add_header: 'Access-Control-Expose-Headers "Docker-Content-Digest"'
|
||||||
|
proxy_zwave2mqtt:
|
||||||
|
enabled: true
|
||||||
|
config:
|
||||||
|
- server:
|
||||||
|
- server_name: zwave2mqtt zwave2mqtt.chaos
|
||||||
|
- listen:
|
||||||
|
- '80'
|
||||||
|
- location /:
|
||||||
|
- proxy_redirect: "off"
|
||||||
|
- proxy_pass: http://127.0.0.1:8091
|
||||||
|
|||||||
Reference in New Issue
Block a user