From 27171a9ae1991756f8293a6e110f8c718751972a Mon Sep 17 00:00:00 2001 From: trivernis Date: Sat, 25 Nov 2023 16:38:28 +0100 Subject: [PATCH] Change traefik forwarded headers configuration --- apps/traefik/app/traefik-config.yaml | 20 ++++++++++++++++++-- 1 file changed, 18 insertions(+), 2 deletions(-) diff --git a/apps/traefik/app/traefik-config.yaml b/apps/traefik/app/traefik-config.yaml index bc03fb0..f8e0534 100644 --- a/apps/traefik/app/traefik-config.yaml +++ b/apps/traefik/app/traefik-config.yaml @@ -6,24 +6,40 @@ metadata: spec: valuesContent: |- additionalArguments: - - "--entryPoints.web.proxyProtocol.trustedIPs=10.0.0.254,167.235.111.84" - - "--entryPoints.web.forwardedHeaders.trustedIPs=10.0.0.254,167.235.111.84" - "--providers.kubernetescrd.allowCrossNamespace=true" ports: web: exposedPort: 8000 + forwardedHeaders: + trustedIPs: + - "10.0.0.254" + - "167.235.111.84" + proxyProtocol: + trustedIPs: + - "10.0.0.254" + - "167.235.111.84" websecure: exposedPort: 8443 + forwardedHeaders: + trustedIPs: + - "10.0.0.254" + - "167.235.111.84" + proxyProtocol: + trustedIPs: + - "10.0.0.254" + - "167.235.111.84" ssh: port: 8022 expose: true exposedPort: 8022 protocol: TCP + sct-discovery: port: 21027 expose: true exposedPort: 21027 protocol: UDP + sct-listen: port: 22000 expose: true