Some checks failed
CI / skinny-install (aco) (push) Successful in 1m12s
CI / skinny-install (api) (push) Successful in 30s
CI / skinny-install (bcda) (push) Successful in 36s
CI / skinny-install (bib) (push) Successful in 35s
CI / skinny-install (bls) (push) Successful in 27s
CI / skinny-install (ccw) (push) Successful in 32s
CI / skinny-install (cli) (push) Successful in 41s
CI / skinny-install (cms) (push) Successful in 37s
CI / skinny-install (conf) (push) Successful in 38s
CI / skinny-install (opps) (push) Successful in 33s
CI / skinny-install (perf) (push) Successful in 38s
CI / skinny-install (pfs) (push) Successful in 38s
CI / skinny-install (rex) (push) Successful in 34s
Deploy / build-scan-report (push) Failing after 46s
Infra CI / notebooks (push) Failing after 25s
Infra CI / zotero (push) Successful in 12s
Infra CI / docs (push) Failing after 16s
CI / lint-test (push) Failing after 11m2s
Infra CI / mc (push) Successful in 21s
Infra CI / api (push) Successful in 29s
Package Supply Chain / pkg-supply-chain (push) Failing after 41s
Mail: Maddy on DO (corwins.media+Resend, fhirworx.io+Postmark), touchless/stateless/idempotent. Gitea SMTP via env_file. CMS inbox at cmsupdates@mail.fhirworx.io with IMAP→bib poller. Bib: regulations.gov v4 client, Federal Register discovery, 164K comment backfill (running), IMAP email ingest, Zotero sync routing. PRISMA: altcha PoW solver, CrossRef DOI resolution, 83/129 PDFs. Zotero: schema parity, ops module, CLI, fail-fast guard. CI: docs.Dockerfile COPY glob fix (tracks #341). Infra: Gitea+marimo fhirworx themes, IOM/OIG modules.
161 lines
5.9 KiB
YAML
161 lines
5.9 KiB
YAML
{{- $domain := env "DOMAIN" | default "fhirworx.io" -}}
|
|
{{- $reef := dict
|
|
"dashboard" (dict "port" "80" "theme" true "extra_hosts" (list $domain) "mw" "secure-headers")
|
|
"docs" (dict "port" "80" "theme" true "mw" "git-sso,secure-headers")
|
|
"git" (dict "port" "3000" "theme" false "mw" "secure-headers")
|
|
"woodpecker-server" (dict "port" "8000" "theme" true "subdomain" "ci" "mw" "git-sso,secure-headers")
|
|
"notebooks" (dict "port" "2718" "theme" true "mw" "git-sso,secure-headers")
|
|
"zotero" (dict "port" "8080" "theme" true "mw" "git-sso,secure-headers")
|
|
"webdav" (dict "port" "8080" "theme" false "mw" "secure-headers")
|
|
"api" (dict "port" "8000" "theme" false "mw" "secure-headers")
|
|
"nessie" (dict "port" "19120" "theme" false "mw" "git-sso,infra-headers")
|
|
"trino" (dict "port" "8080" "theme" true "mw" "git-sso,infra-headers")
|
|
"polaris" (dict "port" "8181" "theme" false "mw" "git-sso,infra-headers")
|
|
"grafana" (dict "port" "3000" "theme" true "mw" "git-sso,secure-headers")
|
|
"prometheus" (dict "port" "9090" "theme" true "mw" "git-sso,infra-headers")
|
|
"jaeger" (dict "port" "16686" "theme" true "mw" "git-sso,infra-headers")
|
|
"loki" (dict "port" "3100" "theme" false "mw" "git-sso,infra-headers")
|
|
-}}
|
|
{{- $multi := dict
|
|
"rustfs-api" (dict "container" "rustfs" "port" "9000" "subdomain" "s3" "theme" false "mw" "git-sso,infra-headers")
|
|
"rustfs-console" (dict "container" "rustfs" "port" "9001" "subdomain" "s3console" "theme" true "mw" "git-sso,infra-headers")
|
|
-}}
|
|
http:
|
|
middlewares:
|
|
secure-headers:
|
|
headers:
|
|
frameDeny: true
|
|
browserXssFilter: true
|
|
contentTypeNosniff: true
|
|
# SSO: auth-handler (nginx) wraps oauth2-proxy to convert 401 → 302.
|
|
# Same logic as corwins.media: auth_request + error_page 401 = @signin.
|
|
git-sso:
|
|
forwardAuth:
|
|
address: "http://auth-handler:4181"
|
|
trustForwardHeader: true
|
|
authResponseHeaders:
|
|
- "X-Auth-Request-User"
|
|
- "X-Auth-Request-Email"
|
|
infra-headers:
|
|
headers:
|
|
frameDeny: true
|
|
browserXssFilter: true
|
|
contentTypeNosniff: true
|
|
referrerPolicy: "strict-origin-when-cross-origin"
|
|
customResponseHeaders:
|
|
X-Robots-Tag: "noindex, nofollow"
|
|
inject-fhirworx:
|
|
plugin:
|
|
rewrite-body:
|
|
lastModified: true
|
|
rewrites:
|
|
- regex: "</head>"
|
|
replacement: '<link rel="icon" type="image/png" sizes="32x32" href="//dashboard.{{ $domain }}/fav32.png"><link rel="stylesheet" type="text/css" href="//dashboard.{{ $domain }}/fhirworx.css"></head>'
|
|
routers:
|
|
# auth.DOMAIN — oauth2-proxy public endpoints (login, callback, sign_out)
|
|
auth-host:
|
|
rule: "Host(`auth.{{ $domain }}`)"
|
|
service: oauth2-proxy
|
|
entryPoints:
|
|
- web
|
|
auth-host-tls:
|
|
rule: "Host(`auth.{{ $domain }}`)"
|
|
service: oauth2-proxy
|
|
entryPoints:
|
|
- websecure
|
|
tls: {}
|
|
{{- range $name, $svc := $reef }}
|
|
{{ $name }}:
|
|
rule: "Host(`{{ get $svc "subdomain" | default $name }}.{{ $domain }}`){{ range get $svc "extra_hosts" | default list }} || Host(`{{ . }}`){{ end }}"
|
|
service: {{ $name }}
|
|
entryPoints:
|
|
- web
|
|
{{- $mwList := list -}}
|
|
{{- if get $svc "theme" }}{{ $mwList = append $mwList "inject-fhirworx" }}{{ end -}}
|
|
{{- $extra := get $svc "mw" | default "" -}}
|
|
{{- if ne $extra "" }}{{ range splitList "," $extra }}{{ $mwList = append $mwList (trim .) }}{{ end }}{{ end -}}
|
|
{{- if $mwList }}
|
|
middlewares:
|
|
{{- range $mwList }}
|
|
- {{ . }}
|
|
{{- end }}
|
|
{{- end }}
|
|
{{ $name }}-tls:
|
|
rule: "Host(`{{ get $svc "subdomain" | default $name }}.{{ $domain }}`){{ range get $svc "extra_hosts" | default list }} || Host(`{{ . }}`){{ end }}"
|
|
service: {{ $name }}
|
|
entryPoints:
|
|
- websecure
|
|
tls: {}
|
|
{{- if $mwList }}
|
|
middlewares:
|
|
{{- range $mwList }}
|
|
- {{ . }}
|
|
{{- end }}
|
|
{{- end }}
|
|
{{- end }}
|
|
{{- range $name, $svc := $multi }}
|
|
{{ $name }}:
|
|
rule: "Host(`{{ get $svc "subdomain" }}.{{ $domain }}`)"
|
|
service: {{ $name }}
|
|
entryPoints:
|
|
- web
|
|
{{- $mwList := list -}}
|
|
{{- if get $svc "theme" }}{{ $mwList = append $mwList "inject-fhirworx" }}{{ end -}}
|
|
{{- $extra := get $svc "mw" | default "" -}}
|
|
{{- if ne $extra "" }}{{ range splitList "," $extra }}{{ $mwList = append $mwList (trim .) }}{{ end }}{{ end -}}
|
|
{{- if $mwList }}
|
|
middlewares:
|
|
{{- range $mwList }}
|
|
- {{ . }}
|
|
{{- end }}
|
|
{{- end }}
|
|
{{ $name }}-tls:
|
|
rule: "Host(`{{ get $svc "subdomain" }}.{{ $domain }}`)"
|
|
service: {{ $name }}
|
|
entryPoints:
|
|
- websecure
|
|
tls: {}
|
|
{{- if $mwList }}
|
|
middlewares:
|
|
{{- range $mwList }}
|
|
- {{ . }}
|
|
{{- end }}
|
|
{{- end }}
|
|
{{- end }}
|
|
traefik-dashboard:
|
|
rule: "Host(`traefik.{{ $domain }}`)"
|
|
service: api@internal
|
|
entryPoints:
|
|
- web
|
|
middlewares:
|
|
- inject-fhirworx
|
|
- git-sso
|
|
- infra-headers
|
|
traefik-dashboard-tls:
|
|
rule: "Host(`traefik.{{ $domain }}`)"
|
|
service: api@internal
|
|
entryPoints:
|
|
- websecure
|
|
tls: {}
|
|
middlewares:
|
|
- inject-fhirworx
|
|
- git-sso
|
|
- infra-headers
|
|
services:
|
|
{{- range $name, $svc := $reef }}
|
|
{{ $name }}:
|
|
loadBalancer:
|
|
servers:
|
|
- url: "http://{{ $name }}:{{ get $svc "port" }}"
|
|
{{- end }}
|
|
{{- range $name, $svc := $multi }}
|
|
{{ $name }}:
|
|
loadBalancer:
|
|
servers:
|
|
- url: "http://{{ get $svc "container" }}:{{ get $svc "port" }}"
|
|
{{- end }}
|
|
oauth2-proxy:
|
|
loadBalancer:
|
|
servers:
|
|
- url: "http://oauth2-proxy:4180"
|