Skip to content

Commit

Permalink
created traefik tls file for prod and block tls 1.0 and 1.1 (#40)
Browse files Browse the repository at this point in the history
  • Loading branch information
joshdentremont authored May 29, 2024
1 parent 5745dfb commit 4ac3d57
Show file tree
Hide file tree
Showing 3 changed files with 13 additions and 1 deletion.
File renamed without changes.
4 changes: 3 additions & 1 deletion docker-compose.yml
Original file line number Diff line number Diff line change
Expand Up @@ -627,7 +627,7 @@ services:
- label=type:container_runtime_t # Required for selinux to access the docker socket.
volumes:
- ./certs:/etc/ssl/traefik:Z,ro
- ./tls.yml:/etc/traefik/tls.yml:Z,ro
- ./dev-tls.yml:/etc/traefik/tls.yml:Z,ro
- /var/run/docker.sock:/var/run/docker.sock:z
networks:
default:
Expand Down Expand Up @@ -664,6 +664,7 @@ services:
--entryPoints.http.address=:80
--entryPoints.https.address=:443
--entrypoints.https.http.tls.certResolver=resolver
--providers.file.filename=/etc/traefik/tls.yml
--providers.docker
--providers.docker.network=default
--providers.docker.exposedByDefault=false
Expand All @@ -677,6 +678,7 @@ services:
volumes:
- /var/run/docker.sock:/var/run/docker.sock:z,rw
- ./certs:/acme:Z
- ./prod-tls.yml:/etc/traefik/tls.yml:Z,ro
networks:
default:
aliases:
Expand Down
10 changes: 10 additions & 0 deletions prod-tls.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,10 @@
tls:
options:
default:
minVersion: VersionTLS12
cipherSuites:
- TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256
- TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256
- TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
- TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA
- TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA

0 comments on commit 4ac3d57

Please sign in to comment.