No description
- Shell 100%
|
|
||
|---|---|---|
| .forgejo/workflows | ||
| docs | ||
| image | ||
| rootfs | ||
| tests | ||
| adopt.sh | ||
| app.func | ||
| CHANGELOG.md | ||
| ct.sh | ||
| iac.json | ||
| install.sh | ||
| packages.list | ||
| README.md | ||
| rootfs.perms | ||
| update.sh | ||
| vm.sh | ||
iac-traefik
Traefik als LXC oder VM auf Proxmox VE, auf Debian 13.
Teil von iac – Konzept: iac-core/docs/CONCEPT.md.
Installation (auf der Proxmox-Node)
# LXC
bash -c "$(curl -fsSL https://git.heyer.systems/iac/iac-traefik/raw/branch/main/ct.sh)"
# VM (fertiges Image)
bash -c "$(curl -fsSL https://git.heyer.systems/iac/iac-traefik/raw/branch/main/vm.sh)"
Ohne Dialog: IAC_NONINTERACTIVE=1 und var_*-Variablen (siehe iac-core/lib/host.func).
Update (im Gast)
update
Das aktualisiert Debian-Pakete, Traefik (innerhalb der Major-Version) und die iac-Konfiguration.
Bestehende Installation übernehmen
bash -c "$(curl -fsSL https://git.heyer.systems/iac/iac-traefik/raw/branch/main/adopt.sh)"
Wenn das nicht automatisch geht: docs/MIGRATION.md.
Standard-Einrichtung
| Binary | /usr/local/bin/traefik (GitHub-Release, Prüfsumme geprüft) |
| Dienst | traefik.service als User traefik |
| Statische Konfiguration | /etc/traefik/traefik.yaml (iac) – eigene: /etc/traefik/traefik.local.yaml |
| Dynamische Konfiguration | /etc/traefik/conf.d/*.yaml |
| Daten (z. B. acme.json) | /var/lib/traefik/ |
| Entrypoints | web :80, websecure :443, dashboard :8080 |
| Dashboard | http://<ip>:8080/dashboard/ – Firewall: nur aus privaten Netzen |
| Firewall | nftables: SSH, 80, 443 offen; 8080 privat; Rest gesperrt |
Dateien mit # managed by iac werden bei update überschrieben – eigene Anpassungen
gehören in die genannten local-Dateien bzw. eigene Dateien in conf.d/ und nftables.d/90-local.nft.