redirect-to-https
redirectScheme: scheme: https
files-basic-auth
headers:
customRequestHeaders:
Authorization: Basic YWRtaW46TFZYZnpYRlA0dzdzZDk=
authentik
forwardAuth:
address: http://authentik:9000/outpost.goauthentik.io/auth/traefik
trustForwardHeader: true
authResponseHeaders:
- X-authentik-username
- X-authentik-groups
- X-authentik-entitlements
- X-authentik-email
- X-authentik-name
- X-authentik-uid
- X-authentik-jwt
- X-authentik-meta-jwks
- X-authentik-meta-outpost
- X-authentik-meta-provider
- X-authentik-meta-app
- X-authentik-meta-version
maxResponseBodySize: 4096
crowdsec-bouncer
plugin:
crowdsec-bouncer:
enabled: true
crowdsecMode: "stream"
updateIntervalSeconds: 60
crowdsecLapiKey: "nQftMYvc7uJtgTaRZsL47JDwn0NAeSd1uhZOY8/8V/o"
crowdsecLapiHost: "crowdsec:8080"
# THIS SAVES YOU FROM LOCKOUTS:
clientTrustedIPs:
- "127.0.0.1/32"
- "172.19.0.0/16"
- "192.168.2.0/24"
- "172.16.23.0/24"
- "108.70.51.191/32"
- "2606:a300:9010:cb51::/64"
- "2606:a300:9010:cb50::/64"
- "146.85.156.191/32"
- "172.16.50.0/24"
- "2600:1700:4dd0:945f::/64"
- "2606:a300:9010:cb50:c662:37ff:fe02:4c13/128"
captchaProvider: "turnstile"
captchaSiteKey: "0x4AAAAAACJYAUokokdaXJe7"
captchaSecretKey: "0x4AAAAAACJYAYr6gX6hQqka3Ec7zns4jO0"
captchaGracePeriodSeconds: 3600
securityHeaders
headers:
customResponseHeaders:
X-Robots-Tag: "none,noarchive,nosnippet,notranslate,noimageindex"
X-Forwarded-Proto: "https"
server: ""
customRequestHeaders:
X-Forwarded-Proto: "https"
sslProxyHeaders:
X-Forwarded-Proto: "https"
referrerPolicy: "same-origin"
hostsProxyHeaders:
- "X-Forwarded-Host"
contentTypeNosniff: true
browserXssFilter: true
forceSTSHeader: true
stsIncludeSubdomains: true
stsSeconds: 63072000
stsPreload: true
uli-auth
headers:
customRequestHeaders:
X-ULI-Proxy-Auth: 5416af2414015728636505945b4bddeaede47c34d8af4dad4d8f9c9f88fcb093
jellyfin-mw
headers:
# Privacy: Prevent search engines from indexing your login page
customResponseHeaders:
X-Robots-Tag: "noindex, nofollow, nosnippet, noarchive, notranslate, noimageindex"
X-XSS-Protection: "1; mode=block"
# Protocol Security
sslRedirect: true
# HTTP Strict Transport Security (HSTS)
stsSeconds: 315360000
stsIncludeSubdomains: true
stsPreload: true
forceSTSHeader: true
# Clickjacking & Sniffing Protection
frameDeny: true
contentTypeNosniff: true
customFrameOptionsValue: "allow-from https://vcdx71.com"
No middlewares found
Middleware Templates
Dashboard settings
Assign a route to a group with the pencil on its card. A group disappears when nothing uses it.
Hidden apps stay off the dashboard only. They keep running and still appear on the Routes tab.
Card settings
These settings change how this app appears on the dashboard. They do not touch the route itself.
Useful when the route has a wildcard host, or the app lives on a different port.
Loading services...
Loading docker routes...
Loading Kubernetes routes...
Loading Swarm routes...
Loading Nomad routes...
Loading ECS routes...
Loading Consul Catalog routes...
Loading Redis routes...
Loading etcd routes...
Loading Consul KV routes...
Loading ZooKeeper routes...
Loading HTTP provider routes...
Loading file provider routes...
Loading certificates...
Loading TLS profiles...
Add Decision
Single IP or CIDR range.
Stored as the decision scenario.
Loading plugins...
Add Plugin
Edit the middleware before saving - replace all placeholder values and any {{ }} template blocks with real values or Traefik will crash
Loading...
Access logs not loaded
Configure Access Log Path in Settings
Log Detail
Raw Line