Skip to content

Commit 263cbb3

Browse files
committed
Use client ip private ips as a rule
1 parent 641c025 commit 263cbb3

File tree

2 files changed

+2
-4
lines changed

2 files changed

+2
-4
lines changed

services/rabbit/docker-compose.loadbalancer.yml.j2

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -32,8 +32,8 @@ services:
3232
- traefik.http.routers.rabbit_dashboard.tls=true
3333
- traefik.http.middlewares.rabbit_dashboard_replace_regex.replacepathregex.regex=^/rabbit/(.*)$$
3434
- traefik.http.middlewares.rabbit_dashboard_replace_regex.replacepathregex.replacement=/$${1}
35-
- traefik.http.routers.rabbit_dashboard.middlewares=rabbit_dashboard_replace_regex@swarm, ops_gzip@swarm, ops_whitelist_private_ips@swarm
36-
- traefik.tcp.routers.rabbit.rule=Host(`${RABBIT_HOST}`)
35+
- traefik.http.routers.rabbit_dashboard.middlewares=rabbit_dashboard_replace_regex@swarm, ops_gzip@swarm
36+
- traefik.tcp.routers.rabbit.rule=ClientIP(`10.0.0.0/8`) || ClientIP(`172.16.0.0/12`) || ClientIP(`192.168.0.0/16`)
3737
- traefik.tcp.routers.rabbit.entrypoints=rabbitmq
3838
- traefik.tcp.routers.rabbit.tls=false
3939
- traefik.tcp.routers.rabbit.service=rabbit

services/traefik/docker-compose.yml.j2

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -109,8 +109,6 @@ services:
109109
- traefik.http.middlewares.ops_gzip.compress=true
110110
# ip whitelisting
111111
- traefik.http.middlewares.ops_whitelist_ips.ipallowlist.sourcerange=${TRAEFIK_IPWHITELIST_SOURCERANGE}
112-
# ip whitelisting: only private ips
113-
- traefik.http.middlewares.ops_whitelist_private_ips.ipallowlist.sourcerange=10.0.0.0/8,172.16.0.0/12,192.168.0.0/16
114112
# traefik UI
115113
- traefik.http.routers.api.service=api@internal
116114
- traefik.http.routers.api.rule=Host(`${MONITORING_DOMAIN}`) &&

0 commit comments

Comments
 (0)