--- # Services hosted on `storage` that the DMZ reverseproxy should forward # public traffic to. See application/traefik.yml for the mechanism. # The garage-webui ForwardAuth no longer needs an auth FQDN pinned here — # it talks to the storage-local proxy outpost over the docker network # (see garage.yml), and the outpost reaches authentik via the public FQDN # over the reverseproxy (firewall now permits backend -> DMZ). traefik_dmz_exposed_services: - name: garage-s3 domain: s3.mbaz.souveredu.ch backend_host: s3.int.mbaz.souveredu.ch port: 443 protocol: https - name: garage-webui domain: console.s3.mbaz.souveredu.ch # Internal name so the DMZ verifies the storage backend cert against a # matching SAN (acme cert_mode, no insecureSkipVerify). garage now # serves this SAN via garage_webui_domains (see garage.yml). backend_host: console.s3.int.mbaz.souveredu.ch port: 443 protocol: https