dccdb746ea
Dockerfile.traefik: extends traefik:v3.3.0 with baked default
static config (entrypoints 127.0.0.1:8080/8443/8081, file provider
watching /etc/traefik/dynamic, json log). Host-side traefik.yml
mounted :ro at runtime to override baked default (preserves
traefik-on-public-ip opt-out, REQ-100, C-58).
No certificatesResolvers — traefik v3.3 only supports acme/tailscale
(research finding). tls: {} in dynamic config for v0.14; real mTLS
deferred to v0.15 (grill G-003, confidence 0.55 < 0.60).
release.sh: second docker block builds+pushes orca-traefik image.
.coreci.yml: container-publish-traefik step mirrors container-publish.
Verified: docker build -f Dockerfile.traefik . succeeds; image starts
traefik v3.3.0 with --configFile=/etc/traefik/traefik.yml.
---ci---
project: orca
phase: 1
milestone: v0.14
status: execute
---/ci---
33 lines
1.4 KiB
Docker
33 lines
1.4 KiB
Docker
# Dockerfile.traefik — custom orca-traefik image (R-024)
|
|
#
|
|
# Extends the official traefik:v3.3.0 image with a baked default static
|
|
# config. The host-side /etc/traefik/traefik.yml (rendered by
|
|
# emitter.RenderTraefikStaticConfig) is mounted :ro at runtime to
|
|
# override this default — preserving the traefik-on-public-ip opt-out
|
|
# (REQ-100) and any site-local customisation.
|
|
#
|
|
# Dynamic config (routers, services, certs) is mounted from
|
|
# /etc/traefik/dynamic on the host — orca writes to it atomically via
|
|
# the SSH-push transport (C-10 protocol).
|
|
#
|
|
# Build:
|
|
# docker build -f Dockerfile.traefik -t git.cloudinit.dev/coreci/orca-traefik:v0.13.1 .
|
|
#
|
|
# Run (hybrid R-017 mode — nft DNATs :443/:80 to loopback):
|
|
# podman run -d --name orca-traefik --restart=unless-stopped \
|
|
# --network host \
|
|
# -v /etc/traefik/traefik.yml:/etc/traefik/traefik.yml:ro \
|
|
# -v /etc/traefik/dynamic:/etc/traefik/dynamic:ro \
|
|
# -v /etc/orca/step-ca-root.crt:/etc/orca/step-ca-root.crt:ro \
|
|
# git.cloudinit.dev/coreci/orca-traefik:v0.13.1
|
|
|
|
FROM traefik:v3.3.0
|
|
|
|
LABEL org.opencontainers.image.title="orca-traefik"
|
|
LABEL org.opencontainers.image.description="Custom Traefik image for Orca ingress (R-024)"
|
|
LABEL org.opencontainers.image.source="https://git.cloudinit.dev/coreci/orca"
|
|
|
|
COPY docker/orca-traefik/traefik.yml /etc/traefik/traefik.yml
|
|
COPY docker/orca-traefik/step-ca-root.crt /etc/orca/step-ca-root.crt
|
|
|
|
CMD ["--configFile=/etc/traefik/traefik.yml"] |