55 lines
3.0 KiB
Plaintext
55 lines
3.0 KiB
Plaintext
# traefik Stack — Secrets Reference
|
|
# Source: traefik.env.template (rendered by deploy/provision-stack.py per
|
|
# secrets/secrets-map.yaml — see secrets-map.yaml header for how
|
|
# this works). traefik/traefik.env is rendered fresh on every
|
|
# provisioning run and is NEVER committed to git.
|
|
#
|
|
# Add SECRET values to Woodpecker at:
|
|
# https://woodpecker.bryanmail.net
|
|
# homelab/compose-files → Settings → Secrets
|
|
#
|
|
# ⚠️ HIGH RISK: Traefik is the entry point for all homelab services.
|
|
# If this stack fails, nothing is reachable from outside.
|
|
# Migrate carefully. The Keepalived VIP (192.168.4.30) depends on this stack.
|
|
#
|
|
# ⚠️ 2026-09-12 INCIDENT: traefik.env was previously committed to git with a
|
|
# literal "***REDACTED***" placeholder as KEEPALIVED_PASSWORD. Every
|
|
# git-guard resync/checkout restored that broken value onto disk,
|
|
# diverging from keepalived-backup's stale-but-correct in-memory value
|
|
# and causing continuous VRRP auth failures + VIP instability. This was
|
|
# the trigger for migrating this stack to Pattern C. If you ever see
|
|
# KEEPALIVED_PASSWORD as a literal placeholder-looking string on disk
|
|
# again, do NOT hand-edit it — check `git log traefik/` for a stray
|
|
# commit and fix the template in Gitea instead.
|
|
|
|
# ── SECRETS (add to Woodpecker) ─────────────────────────────────────────
|
|
|
|
# Woodpecker secret name: traefik_keepalived_password
|
|
# Used for: Keepalived VRRP authentication password
|
|
# Must match across all 3 nodes (docker-1, docker-2, docker-3)
|
|
# NOTE: classic VRRP simple-auth is silently
|
|
# truncated to 8 chars by keepalived itself — keep
|
|
# the value <= 8 characters, or be aware only the
|
|
# first 8 are actually significant on the wire.
|
|
# Env var in .env.template: KEEPALIVED_PASSWORD (via TRAEFIK_KEEPALIVED_PASSWORD)
|
|
traefik_keepalived_password=
|
|
|
|
# ── NON-SECRETS (safe in compose file or .env.template) ─────────────────
|
|
|
|
# KEEPALIVED_VIRTUAL_IPS Python2BASH list of VIP addresses (192.168.4.30) — literal in template
|
|
# ACME_EMAIL Let's Encrypt certificate email
|
|
# TRUSTED_IPS Trusted proxy CIDR ranges
|
|
# TRAEFIK_HOST Traefik dashboard hostname
|
|
# SPEEDTEST_HOST Speedtest Traefik hostname
|
|
# WHOAMI_HOST Whoami Traefik hostname
|
|
|
|
# ── Provisioning (manifest-driven, deploy/provision-stack.py) ───────────
|
|
#
|
|
# This stack is migrated — provisioning happens automatically via:
|
|
# secrets/secrets-map.yaml (traefik: entry)
|
|
# traefik/traefik.env.template (authoritative key list)
|
|
# deploy/provision-stack.py (renders + ships traefik/traefik.env)
|
|
#
|
|
# The .woodpecker/deploy.yml provision-secrets step calls this with a
|
|
# single line: `python3 deploy/provision-stack.py traefik`
|