about summary refs log tree commit diff
path: root/docker-compose.yml
diff options
context:
space:
mode:
Diffstat (limited to 'docker-compose.yml')
-rw-r--r--docker-compose.yml7
1 files changed, 6 insertions, 1 deletions
diff --git a/docker-compose.yml b/docker-compose.yml
index e51cee8..0514cbe 100644
--- a/docker-compose.yml
+++ b/docker-compose.yml
@@ -10,7 +10,9 @@ services:
             - "--providers.docker.exposedbydefault=false"
             - "--entrypoints.web.address=:80"
             - "--entrypoints.websecure.address=:443"
-            - "--certificatesresolvers.mytlschallenge.acme.tlschallenge=true"
+            - "--certificatesresolvers.mytlschallenge.acme.dnschallenge=true"
+            - "--certificatesresolvers.mytlschallenge.acme.dnschallenge.delaybeforecheck=0"
+            - "--certificatesresolvers.mytlschallenge.acme.dnschallenge.provider=cloudflare"
             - "--certificatesresolvers.mytlschallenge.acme.email=hanemile@protonmail.com"
             - "--certificatesresolvers.mytlschallenge.acme.storage=/letsencrypt/acme.json"
             - "--metrics.prometheus=true"
@@ -21,14 +23,17 @@ services:
         volumes:
             - "./letsencrypt:/letsencrypt"
             - "/var/run/docker.sock:/var/run/docker.sock:ro"
+            - "./traefik_users:/traefik_users"
         labels:
             - "traefik.enable=true"
             - "traefik.http.routers.traefik.entrypoints=web"
             - "traefik.http.routers.traefik.rule=Host(`traefik.${HOSTNAME}`)"
+            - "traefik.http.middlewares.traefik-auth.basicauth.usersFile=/traefik_users"
             - "traefik.http.middlewares.traefik-https-redirect.redirectscheme.scheme=https"
             - "traefik.http.routers.traefik.middlewares=traefik-https-redirect"
             - "traefik.http.routers.traefik-secure.entrypoints=websecure"
             - "traefik.http.routers.traefik-secure.rule=Host(`traefik.${HOSTNAME}`)"
+            - "traefik.http.routers.traefik-secure.middlewares=traefik-auth"
             - "traefik.http.routers.traefik-secure.tls=true"
             - "traefik.http.routers.traefik-secure.tls.certresolver=mytlschallenge"
             - "traefik.http.routers.traefik-secure.service=api@internal"