Files
terraform/modules/apps/gateway/lib/scripts/install-traefik.sh
JulienAldon a56911b896 Add(module): add girasol module
Add(module): add amap module
Add(module): add common lib and services
Add(module): add base structure for keycloak
Add(module): add base structure for rocket
Add(module): add n8n and windmill modules
Add(docker): add install docker script in common module
Add(template): add root for aldon.fr and mathieu.wiki in traefik.service template
2026-04-21 16:52:41 +02:00

67 lines
1.6 KiB
Bash

#!/bin/bash
# DYNAMIC_CONFIG_LOCATION (path on vm)
# GATEWAY_REPOSITORY (path on gitea)
# TRAEFIK_USER
# TRAEFIK_BINARY
# TRAEFIK_VERSION
# TRAEFIK_CONF
source /opt/environment/.env
if ! id -u $TRAEFIK_USER >/dev/null 2>&1; then
adduser \
--system \
--shell /bin/bash \
--gecos 'Traefik reverse proxy user' \
--group \
--disabled-password \
--home /home/$TRAEFIK_USER \
$TRAEFIK_USER
fi
if [ ! -f $TRAEFIK_BINARY ]; then
wget -O /tmp/traefik.tar.gz "https://github.com/traefik/traefik/releases/download/$TRAEFIK_VERSION/traefik_${TRAEFIK_VERSION}_linux_amd64.tar.gz"
tar -zxvf /tmp/traefik.tar.gz -C /usr/local/bin traefik
chmod +x $TRAEFIK_BINARY
fi
mkdir -p /etc/traefik/certs
touch /etc/traefik/acme.json
chown $TRAEFIK_USER:$TRAEFIK_USER /etc/traefik/acme.json
chmod 600 /etc/traefik/acme.json
setcap 'cap_net_bind_service=+ep' /usr/local/bin/traefik
sudo mkdir -p /var/log/traefik
sudo touch /var/log/traefik/access.log
sudo chown -R traefik:adm /var/log/traefik
cat > "$TRAEFIK_CONF" <<EOF
entryPoints:
web:
address: ":80"
websecure:
address: ":443"
providers:
file:
filename: $DYNAMIC_CONFIG_LOCATION
watch: true
api:
dashboard: false
insecure: false
log:
level: INFO
accessLog:
filePath: "/var/log/traefik/access.log"
bufferingSize: 100
certificatesResolvers:
letsencrypt:
acme:
email: julien.aldon@wanadoo.fr
storage: /etc/traefik/acme.json
httpChallenge:
entryPoint: web
EOF
systemctl enable traefik.service
systemctl start traefik.service