--- # The garage-webui ForwardAuth middleware fires a subrequest to authentik # (see garage.yml). It must reach the app-host's `authentik` router # directly — going via the DMZ reverseproxy strips X-Forwarded-Host, which # breaks the embedded outpost's app matching. The internal DNS view points # auth.gymb.* at the reverseproxy, so pin it to the application host here # to force the single direct hop that preserves the forwarded headers. traefik_extra_hosts: - "auth.gymb.souveredu.ch:172.16.19.101" # Services hosted on `storage` that the DMZ reverseproxy should forward # public traffic to. See application/traefik.yml for the mechanism. traefik_dmz_exposed_services: - name: garage-s3 domain: s3.gymb.souveredu.ch backend_host: s3.int.gymb.souveredu.ch port: 443 protocol: https - name: garage-webui domain: console.s3.gymb.souveredu.ch # Pre-existing limitation, orthogonal to the DNS cleanup: the DMZ # verifies the storage backend cert (acme cert_mode), but with no # backend_host set it connects by IP, which the storage cert has no # SAN for, so this route fails the TLS verify. Fixing it needs the # garage role to expose a console extra_domain (e.g. console.s3.int.*) # for the backend_host + cert SAN — tracked separately. port: 443 protocol: https