Compare commits

..
66 Commits
Author SHA1 Message Date
renovate_bot 898a4bed54 Merge pull request 'Update traefik Docker tag to v3.7.13' (#35) from renovate/traefik-3.x into main 2026-09-05 02:02:54 +02:00
renovate_bot 7c9bc84b06 Update traefik Docker tag to v3.7.13 2026-09-05 00:02:52 +00:00
renovate_bot 716c344b6d Merge pull request 'Update henrygd/beszel-agent Docker tag to v0.19.0' (#34) from renovate/henrygd-beszel-agent-0.x into main 2026-09-04 02:06:05 +02:00
renovate_bot 41ef3bcaaf Merge pull request 'Update crowdsecurity/crowdsec Docker tag to v1.8.1' (#33) from renovate/crowdsecurity-crowdsec-1.x into main 2026-09-04 02:06:00 +02:00
renovate_bot b5db2630b1 Update henrygd/beszel-agent Docker tag to v0.19.0 2026-09-04 00:05:58 +00:00
renovate_bot 2a6d22db93 Update crowdsecurity/crowdsec Docker tag to v1.8.1 2026-09-04 00:05:57 +00:00
renovate_bot 51e09b6bc4 Merge pull request 'Update crowdsecurity/crowdsec Docker tag to v1.8.0' (#32) from renovate/crowdsecurity-crowdsec-1.x into main 2026-09-02 02:02:20 +02:00
renovate_bot 6418832075 Update crowdsecurity/crowdsec Docker tag to v1.8.0 2026-09-02 00:02:18 +00:00
renovate_bot 3e073440ea Merge pull request 'Update traefik Docker tag to v3.7.12' (#31) from renovate/traefik-3.x into main 2026-08-27 02:03:01 +02:00
renovate_bot 00895f75d8 Update traefik Docker tag to v3.7.12 2026-08-27 00:02:59 +00:00
renovate_bot af1f7de2da Merge pull request 'Update traefik Docker tag to v3.7.11' (#30) from renovate/traefik-3.x into main 2026-08-21 00:03:54 +02:00
renovate_bot e193c79fc4 Merge pull request 'Update henrygd/beszel-agent Docker tag to v0.18.8' (#29) from renovate/henrygd-beszel-agent-0.x into main 2026-08-21 00:03:53 +02:00
renovate_bot 462ea903b0 Update traefik Docker tag to v3.7.11 2026-08-20 22:03:52 +00:00
renovate_bot 9044116b56 Update henrygd/beszel-agent Docker tag to v0.18.8 2026-08-20 22:03:51 +00:00
chriswin c9b81b9dbf typo 2026-08-10 17:20:40 +02:00
chriswin 4baa4f28d3 update remediation 2026-08-10 17:10:03 +02:00
chriswin f281c8bc0d update remediation 2026-08-10 17:06:26 +02:00
chriswin f617beff36 :Merge branch 'main' of https://gitea.crescentec.ch/chriswin/vps-server 2026-08-10 14:33:05 +00:00
chriswin e3b0cf5dcf update bouncer config 2026-08-10 14:32:36 +00:00
chriswin 35b183643c fix paths beszel 2026-08-10 00:42:05 +02:00
chriswin 4bf49aa6ab hub ip address 2026-08-09 23:20:48 +02:00
chriswin ee6f6ebfa5 fix auto configure crowdsec 2026-08-09 23:10:27 +02:00
chriswin c86b943d94 comment crowdsec middleware 2026-08-09 17:32:30 +02:00
chriswin 14ff5c355b update headscale template 2026-08-09 16:01:07 +02:00
renovate_bot 5b53db472e Merge pull request 'Update traefik Docker tag to v3.7.10' (#28) from renovate/traefik-3.x into main 2026-08-01 02:03:23 +02:00
renovate_bot 9ad2613d19 Update traefik Docker tag to v3.7.10 2026-08-01 00:03:22 +00:00
renovate_bot 47b6cde201 Merge pull request 'Update traefik Docker tag to v3.7.9' (#27) from renovate/traefik-3.x into main 2026-07-25 02:03:30 +02:00
renovate_bot 8261ba61fb Update traefik Docker tag to v3.7.9 2026-07-25 00:03:27 +00:00
renovate_bot a71465e20b Merge pull request 'Update traefik Docker tag to v3.7.8' (#26) from renovate/traefik-3.x into main 2026-07-16 02:03:12 +02:00
renovate_bot 0595d8bbf8 Update traefik Docker tag to v3.7.8 2026-07-16 00:03:10 +00:00
renovate_bot 5964e47efa Merge pull request 'Update traefik Docker tag to v3.7.7' (#25) from renovate/traefik-3.x into main 2026-07-09 02:03:12 +02:00
renovate_bot 730834c375 Update traefik Docker tag to v3.7.7 2026-07-09 00:03:10 +00:00
renovate_bot 60526d0bf5 Merge pull request 'Update traefik Docker tag to v3.7.6' (#24) from renovate/traefik-3.x into main 2026-07-01 02:03:01 +02:00
renovate_bot d08cd0faa8 Update traefik Docker tag to v3.7.6 2026-07-01 00:02:59 +00:00
chriswin e5181bbfa8 add beszel agent 2026-06-15 15:54:49 +00:00
renovate_bot cd54d60847 Merge pull request 'Update traefik Docker tag to v3.7.5' (#23) from renovate/traefik-3.x into main 2026-06-11 02:03:16 +02:00
renovate_bot 3436cc1485 Update traefik Docker tag to v3.7.5 2026-06-11 00:03:13 +00:00
renovate_bot 661b2252e1 Merge pull request 'Update traefik Docker tag to v3.7.4' (#22) from renovate/traefik-3.x into main 2026-06-06 02:03:33 +02:00
renovate_bot c5f4427dfe Update traefik Docker tag to v3.7.4 2026-06-06 00:03:31 +00:00
renovate_bot 622389eea2 Merge pull request 'Update traefik Docker tag to v3.7.3' (#21) from renovate/traefik-3.x into main 2026-06-05 17:38:05 +02:00
renovate_bot a2d25ac0fb Update traefik Docker tag to v3.7.3 2026-06-05 15:38:03 +00:00
renovate_bot 5c3a35ad52 Merge pull request 'Update traefik Docker tag to v3.7.1' (#20) from renovate/traefik-3.x into main 2026-05-30 02:03:18 +02:00
renovate_bot 2c21022a70 Update traefik Docker tag to v3.7.1 2026-05-30 00:03:17 +00:00
chriswin 78473473ac update config traefik 2026-05-29 22:05:54 +00:00
renovate_bot 2746a8e2cd Merge pull request 'Update crowdsecurity/crowdsec Docker tag to v1.7.8' (#19) from renovate/crowdsecurity-crowdsec-1.x into main 2026-05-12 02:06:42 +02:00
renovate_bot 5f4903ca0b Update crowdsecurity/crowdsec Docker tag to v1.7.8 2026-05-12 00:06:36 +00:00
chriswin c39b96ca26 :Merge branch 'main' of https://gitea.crescentec.ch/chriswin/vps-server 2026-04-03 17:20:59 +00:00
chriswin 6deb59db17 disable dashboard traefik 2026-04-03 17:20:10 +00:00
renovate_bot 513af6503f Merge pull request 'Update hhftechnology/traefik-log-dashboard-agent Docker tag to v3.1.0' (#18) from renovate/hhftechnology-traefik-log-dashboard-agent-3.x into main 2026-04-02 02:03:44 +02:00
renovate_bot 2be8a8b959 Update hhftechnology/traefik-log-dashboard-agent Docker tag to v3.1.0 2026-04-02 00:03:43 +00:00
renovate_bot 6f40d82809 Merge pull request 'Update crowdsecurity/crowdsec Docker tag to v1.7.7' (#16) from renovate/crowdsecurity-crowdsec-1.x into main 2026-04-02 02:03:41 +02:00
renovate_bot 4568ffc169 Update crowdsecurity/crowdsec Docker tag to v1.7.7 2026-04-02 00:03:40 +00:00
renovate_bot 920ff896ca Merge pull request 'Update traefik Docker tag to v3.6.12' (#15) from renovate/traefik-3.x into main 2026-03-27 01:03:32 +01:00
renovate_bot 11767ad927 Update traefik Docker tag to v3.6.12 2026-03-27 00:03:29 +00:00
renovate_bot e07da8c310 Merge pull request 'Update traefik Docker tag to v3.6.11' (#14) from renovate/traefik-3.x into main 2026-03-20 01:02:55 +01:00
renovate_bot 0795db7472 Update traefik Docker tag to v3.6.11 2026-03-20 00:02:52 +00:00
chriswin b02d44dc51 Merge pull request 'Update hhftechnology/traefik-log-dashboard Docker tag to v3' (#12) from renovate/hhftechnology-traefik-log-dashboard-3.x into main
Reviewed-on: #12
2026-03-18 18:24:38 +01:00
chriswin 9bb6784449 Merge pull request 'Update hhftechnology/traefik-log-dashboard-agent Docker tag to v3' (#13) from renovate/hhftechnology-traefik-log-dashboard-agent-3.x into main
Reviewed-on: #13
2026-03-18 18:24:29 +01:00
renovate_bot 75be54438c Update hhftechnology/traefik-log-dashboard-agent Docker tag to v3 2026-03-17 00:03:07 +00:00
renovate_bot 444f387ca3 Update hhftechnology/traefik-log-dashboard Docker tag to v3 2026-03-17 00:03:05 +00:00
renovate_bot ddf912a4e9 Merge pull request 'Update traefik Docker tag to v3.6.10' (#11) from renovate/traefik-3.x into main 2026-03-07 01:03:47 +01:00
renovate_bot 15f47d5554 Update traefik Docker tag to v3.6.10 2026-03-07 00:03:44 +00:00
renovate_bot 6992333c6f Merge pull request 'Update traefik Docker tag to v3.6.9' (#10) from renovate/traefik-3.x into main 2026-02-24 01:03:20 +01:00
renovate_bot 2af1f4c5d9 Update traefik Docker tag to v3.6.9 2026-02-24 00:03:18 +00:00
renovate_bot e74476439d Merge pull request 'Update traefik Docker tag to v3.6.8' (#9) from renovate/traefik-3.x into main 2026-02-12 01:03:03 +01:00
renovate_bot c51f5a6d0d Update traefik Docker tag to v3.6.8 2026-02-12 00:02:59 +00:00
10 changed files with 116 additions and 90 deletions
+1
View File
@@ -10,3 +10,4 @@ lib/
**/headscale/run/ **/headscale/run/
**/crowdsec/config/ **/crowdsec/config/
**/crowdsec/data/ **/crowdsec/data/
**/beszel/data/
+1
View File
@@ -8,6 +8,7 @@ include:
- path: - path:
- ${SERVICE_PATH}/crowdsec/crowdsec.yml - ${SERVICE_PATH}/crowdsec/crowdsec.yml
- ${SERVICE_PATH}/headscale/headscale.yml - ${SERVICE_PATH}/headscale/headscale.yml
- ${SERVICE_PATH}/beszel/beszel.yml
- ${SERVICE_PATH}/traefik/traefik.yml - ${SERVICE_PATH}/traefik/traefik.yml
env_file: ${SERVICE_PATH}/.env env_file: ${SERVICE_PATH}/.env
+17
View File
@@ -0,0 +1,17 @@
services:
beszel-agent:
extends:
file: ${TEMPLATES_PATH}
service: default
image: henrygd/beszel-agent:0.19.0
container_name: beszel-agent
network_mode: host
volumes:
- ${SERVICE_PATH}/beszel/data:/var/lib/beszel-agent
- ${SERVICE_PATH}/beszel/socket:/beszel_socket
- /var/run/docker.sock:/var/run/docker.sock:ro
environment:
LISTEN: /beszel_socket/beszel.sock
HUB_URL: http://100.64.0.3:3004
TOKEN: ${BESZEL_VPS_TOKEN}
KEY: ${BESZEL_VPS_KEY}
+1 -1
View File
@@ -47,5 +47,5 @@ api:
prometheus: prometheus:
enabled: true enabled: true
level: full level: full
listen_addr: "[::]" listen_addr: "100.64.0.3"
listen_port: 6060 listen_port: 6060
+2 -4
View File
@@ -4,10 +4,10 @@ services:
file: ${TEMPLATES_PATH} file: ${TEMPLATES_PATH}
service: default service: default
container_name: crowdsec container_name: crowdsec
image: crowdsecurity/crowdsec:v1.7.6 image: crowdsecurity/crowdsec:v1.8.1
environment: environment:
COLLECTIONS: crowdsecurity/traefik crowdsecurity/appsec-virtual-patching crowdsecurity/appsec-generic-rules crowdsecurity/http-cve COLLECTIONS: crowdsecurity/traefik crowdsecurity/appsec-virtual-patching crowdsecurity/appsec-generic-rules crowdsecurity/http-cve
CROWDSEC_BOUNCER_API_KEY: ${CROWDSEC_API_KEY} BOUNCER_KEY_traefik: ${CROWDSEC_API_KEY}
CUSTOM_HOSTNAME: crowdsec CUSTOM_HOSTNAME: crowdsec
ports: ports:
- 6061:8080 - 6061:8080
@@ -15,8 +15,6 @@ services:
networks: networks:
- ip4net - ip4net
volumes: volumes:
- ${SERVICE_PATH}/crowdsec/config/acquis.yaml:/etc/crowdsec/acquis.yaml:ro
- ${SERVICE_PATH}/crowdsec/config/config.yaml:/etc/crowdsec/config.yaml
- ${SERVICE_PATH}/crowdsec/config:/etc/crowdsec - ${SERVICE_PATH}/crowdsec/config:/etc/crowdsec
- ${SERVICE_PATH}/crowdsec/data:/var/lib/crowdsec/data - ${SERVICE_PATH}/crowdsec/data:/var/lib/crowdsec/data
- /var/log/traefik:/var/log/crowdsec:ro - /var/log/traefik:/var/log/crowdsec:ro
+4 -6
View File
@@ -137,7 +137,10 @@ derp:
disable_check_updates: false disable_check_updates: false
# Time before an inactive ephemeral node is deleted? # Time before an inactive ephemeral node is deleted?
ephemeral_node_inactivity_timeout: 30m # ephemeral_node_inactivity_timeout: 30m
node:
ephemeral:
inactivity_timeout: 30m
database: database:
# Database type. Available options: sqlite, postgres # Database type. Available options: sqlite, postgres
@@ -398,8 +401,3 @@ logtail:
# As there is currently no support for overriding the log server in headscale, this is # As there is currently no support for overriding the log server in headscale, this is
# disabled by default. Enabling this will make your clients send logs to Tailscale Inc. # disabled by default. Enabling this will make your clients send logs to Tailscale Inc.
enabled: false enabled: false
# Enabling this option makes devices prefer a random port for WireGuard traffic over the
# default static port 41641. This option is intended as a workaround for some buggy
# firewall devices. See https://tailscale.com/kb/1181/firewalls/ for more information.
randomize_client_port: false
+1 -1
View File
@@ -23,4 +23,4 @@ services:
- "traefik.http.routers.headscale.entrypoints=https" - "traefik.http.routers.headscale.entrypoints=https"
- "traefik.http.routers.headscale.tls.certresolver=myresolver" - "traefik.http.routers.headscale.tls.certresolver=myresolver"
- "traefik.http.routers.headscale.tls=true" - "traefik.http.routers.headscale.tls=true"
- "traefik.http.routers.headscale.middlewares=crowdsec-bouncer@file" # - "traefik.http.routers.headscale.middlewares=crowdsec-bouncer@file"
+15 -5
View File
@@ -8,7 +8,8 @@ http:
enabled: true enabled: true
logLevel: INFO logLevel: INFO
updateIntervalSeconds: 60 updateIntervalSeconds: 60
crowdsecMode: live metricsUpdateIntervalSeconds: 600
crowdsecMode: stream
crowdsecAppsecEnabled: true crowdsecAppsecEnabled: true
crowdsecAppsecFailureBlock: true crowdsecAppsecFailureBlock: true
crowdsecAppsecUnreachableBlock: true crowdsecAppsecUnreachableBlock: true
@@ -20,13 +21,14 @@ http:
forwardedHeadersTrustedIPs: forwardedHeadersTrustedIPs:
- 10.0.0.0/8 - 10.0.0.0/8
clientTrustedIPs: clientTrustedIPs:
- 192.168.178.0/24 - 192.168.1.0/24
- 100.64.0.0/24
# captchaProvider: hcaptcha # captchaProvider: hcaptcha
# captchaSiteKey: b2d20610-8dda-4f40-8688-7ca8e1e628f8 # found in hcaptcha account # captchaSiteKey: b2d20610-8dda-4f40-8688-7ca8e1e628f8 # found in hcaptcha account
# captchaSecretKey: {{ env "TRAEFIK_CAPTCHA_KEY" }} # captchaSecretKey: {{ env "TRAEFIK_CAPTCHA_KEY" }}
# captchaGracePeriodSeconds: 1800 captchaGracePeriodSeconds: 1800
# captchaHTMLFilePath: /captcha.html captchaHTMLFilePath: /captcha.html
# banHTMLFilePath: /ban.html banHTMLFilePath: /ban.html
routers: routers:
authelia: authelia:
@@ -117,6 +119,14 @@ http:
certresolver: myresolver certresolver: myresolver
middlewares: crowdsec-bouncer@file middlewares: crowdsec-bouncer@file
quiz:
rule: "Host(`split.{{ env "TRAEFIK_PUBLIC_DOMAIN" }}`)"
service: node
entrypoints: https,http
tls:
certresolver: myresolver
middlewares: crowdsec-bouncer@file
radicale: radicale:
rule: "Host(`radicale.{{ env "TRAEFIK_PUBLIC_DOMAIN" }}`)" rule: "Host(`radicale.{{ env "TRAEFIK_PUBLIC_DOMAIN" }}`)"
service: node service: node
+1 -1
View File
@@ -74,4 +74,4 @@ experimental:
plugins: plugins:
crowdsec-bouncer-traefik-plugin: crowdsec-bouncer-traefik-plugin:
moduleName: "github.com/maxlerebourg/crowdsec-bouncer-traefik-plugin" moduleName: "github.com/maxlerebourg/crowdsec-bouncer-traefik-plugin"
version: "v1.5.0-beta1" version: "v1.7.1"
+73 -72
View File
@@ -3,14 +3,15 @@ services:
extends: extends:
file: ${TEMPLATES_PATH} file: ${TEMPLATES_PATH}
service: default service: default
image: traefik:v3.6.7 image: traefik:v3.7.13
container_name: traefik container_name: traefik
ports: ports:
- "80:80" - "80:80"
- "443:443" - "443:443"
- "8079:8080" - "8079:8080"
networks: networks:
- ip4net ip4net:
ipv4_address: 10.6.0.10
environment: environment:
TRAEFIK_EMAIL: ${EMAIL} TRAEFIK_EMAIL: ${EMAIL}
TRAEFIK_PUBLIC_DOMAIN: ${PUBLIC_DOMAIN} TRAEFIK_PUBLIC_DOMAIN: ${PUBLIC_DOMAIN}
@@ -37,73 +38,73 @@ services:
- "traefik.http.routers.traefik.entrypoints=https" - "traefik.http.routers.traefik.entrypoints=https"
- "traefik.http.routers.traefik.tls=true" - "traefik.http.routers.traefik.tls=true"
traefik-agent: # traefik-agent:
extends: # extends:
file: ${TEMPLATES_PATH} # file: ${TEMPLATES_PATH}
service: default # service: default
image: hhftechnology/traefik-log-dashboard-agent:2.5.0 # image: hhftechnology/traefik-log-dashboard-agent:2.4.1
container_name: traefik-log-dashboard-agent # container_name: traefik-agent
networks: # networks:
- ip4net # - ip4net
ports: # ports:
- "8078:5000" # - "8078:5000"
volumes: # volumes:
- "/var/log/traefik/:/logs:ro" # - "/var/log/traefik/:/logs:ro"
- "${SERVICE_PATH}/traefik/log-dashboard/positions:/data" # - "${SERVICE_PATH}/traefik/log-dashboard/positions:/data"
environment: # environment:
TRAEFIK_LOG_DASHBOARD_ACCESS_PATH: /logs/access.log # TRAEFIK_LOG_DASHBOARD_ACCESS_PATH: /logs/access.log
TRAEFIK_LOG_DASHBOARD_AUTH_TOKEN: ${TRAEFIK_DASHBOARD_TOKEN} # TRAEFIK_LOG_DASHBOARD_AUTH_TOKEN: ${TRAEFIK_DASHBOARD_TOKEN}
TRAEFIK_LOG_DASHBOARD_SYSTEM_MONITORING: true # TRAEFIK_LOG_DASHBOARD_SYSTEM_MONITORING: true
TRAEFIK_LOG_DASHBOARD_LOG_FORMAT: json # TRAEFIK_LOG_DASHBOARD_LOG_FORMAT: json
deploy: # deploy:
resources: # resources:
limits: # limits:
cpus: "0.10" # cpus: "0.15"
memory: 50M # memory: 50M
healthcheck: # healthcheck:
test: # test:
[ # [
"CMD", # "CMD",
"wget", # "wget",
"--no-verbose", # "--no-verbose",
"--tries=1", # "--tries=1",
"--spider", # "--spider",
"http://localhost:5000/api/logs/status", # "http://localhost:5000/api/logs/status",
] # ]
interval: 2m # interval: 2m
timeout: 10s # timeout: 10s
retries: 3 # retries: 3
start_period: 30s # start_period: 30s
#
traefik-dashboard: # traefik-dashboard:
extends: # extends:
file: ${TEMPLATES_PATH} # file: ${TEMPLATES_PATH}
service: default # service: default
image: hhftechnology/traefik-log-dashboard:2.5.0 # image: hhftechnology/traefik-log-dashboard:2.4.1
container_name: traefik-log-dashboard # container_name: traefik-dashboard
networks: # networks:
- ip4net # - ip4net
ports: # ports:
- "8077:3000" # - "8077:3000"
volumes: # volumes:
- "${SERVICE_PATH}/traefik/log-dashboard/dashboard:/app/data" # - "${SERVICE_PATH}/traefik/log-dashboard/dashboard:/app/data"
- "${SERVICE_PATH}/traefik/log-dashboard/positions:/data" # - "${SERVICE_PATH}/traefik/log-dashboard/positions:/data"
environment: # environment:
AGENT_API_URL: http://traefik-agent:5000 # AGENT_API_URL: http://traefik-agent:5000
AGENT_API_TOKEN: ${TRAEFIK_DASHBOARD_TOKEN} # AGENT_API_TOKEN: ${TRAEFIK_DASHBOARD_TOKEN}
# Display Configuration # # Display Configuration
NEXT_PUBLIC_SHOW_DEMO_PAGE: false # NEXT_PUBLIC_SHOW_DEMO_PAGE: false
depends_on: # depends_on:
traefik-agent: # traefik-agent:
condition: service_healthy # condition: service_healthy
deploy: # deploy:
resources: # resources:
limits: # limits:
cpus: "0.1" # cpus: "0.1"
memory: 50M # memory: 120M
labels: # labels:
# traefik # # traefik
- "traefik.enable=true" # - "traefik.enable=true"
- "traefik.http.routers.traefik-log-dashboard.rule=Host(`traefik-dashboard.${LOCAL_VPS_DOMAIN}`)" # - "traefik.http.routers.traefik-log-dashboard.rule=Host(`traefik-dashboard.${LOCAL_VPS_DOMAIN}`)"
- "traefik.http.routers.traefik-log-dashboard.entrypoints=https" # - "traefik.http.routers.traefik-log-dashboard.entrypoints=https"
- "traefik.http.routers.traefik-log-dashboard.tls=true" # - "traefik.http.routers.traefik-log-dashboard.tls=true"