Traefik internal only traffic
I have an Ubuntu 16.04 Docker host running Traefik and Free-ipa server, i want to use trafek to block extranal access to free-ips server but allow internal ranges.
is this possible?
Thanks
Mo
traefik
add a comment |
I have an Ubuntu 16.04 Docker host running Traefik and Free-ipa server, i want to use trafek to block extranal access to free-ips server but allow internal ranges.
is this possible?
Thanks
Mo
traefik
add a comment |
I have an Ubuntu 16.04 Docker host running Traefik and Free-ipa server, i want to use trafek to block extranal access to free-ips server but allow internal ranges.
is this possible?
Thanks
Mo
traefik
I have an Ubuntu 16.04 Docker host running Traefik and Free-ipa server, i want to use trafek to block extranal access to free-ips server but allow internal ranges.
is this possible?
Thanks
Mo
traefik
traefik
asked Nov 11 '18 at 23:14
Maurice Manning
15
15
add a comment |
add a comment |
1 Answer
1
active
oldest
votes
You can use docker's network to isolate your environment, for exemple,
services:
traefik:
networks:
- traefik-net
free-ipa:
networks:
- internal-net
others:
networks:
- traefik-net
- internal-net
Here, others
can access free-ipa
just by using free-ipa
as dns name, and it's accessible by traefik as well. traefik
can't see free-ipa
because they are not in the same network.
Ok that fixes part of the puzle, but the ports 443 still clash on Traefik & freeipa, I need for the public facing sites, and intenal via accessible only names suche as domain/freeipa. Freeipa breaks if you expose/port map on anything else except 443.
– Maurice Manning
Nov 12 '18 at 21:44
add a comment |
Your Answer
StackExchange.ifUsing("editor", function ()
StackExchange.using("externalEditor", function ()
StackExchange.using("snippets", function ()
StackExchange.snippets.init();
);
);
, "code-snippets");
StackExchange.ready(function()
var channelOptions =
tags: "".split(" "),
id: "1"
;
initTagRenderer("".split(" "), "".split(" "), channelOptions);
StackExchange.using("externalEditor", function()
// Have to fire editor after snippets, if snippets enabled
if (StackExchange.settings.snippets.snippetsEnabled)
StackExchange.using("snippets", function()
createEditor();
);
else
createEditor();
);
function createEditor()
StackExchange.prepareEditor(
heartbeatType: 'answer',
autoActivateHeartbeat: false,
convertImagesToLinks: true,
noModals: true,
showLowRepImageUploadWarning: true,
reputationToPostImages: 10,
bindNavPrevention: true,
postfix: "",
imageUploader:
brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
allowUrls: true
,
onDemand: true,
discardSelector: ".discard-answer"
,immediatelyShowMarkdownHelp:true
);
);
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f53254195%2ftraefik-internal-only-traffic%23new-answer', 'question_page');
);
Post as a guest
Required, but never shown
1 Answer
1
active
oldest
votes
1 Answer
1
active
oldest
votes
active
oldest
votes
active
oldest
votes
You can use docker's network to isolate your environment, for exemple,
services:
traefik:
networks:
- traefik-net
free-ipa:
networks:
- internal-net
others:
networks:
- traefik-net
- internal-net
Here, others
can access free-ipa
just by using free-ipa
as dns name, and it's accessible by traefik as well. traefik
can't see free-ipa
because they are not in the same network.
Ok that fixes part of the puzle, but the ports 443 still clash on Traefik & freeipa, I need for the public facing sites, and intenal via accessible only names suche as domain/freeipa. Freeipa breaks if you expose/port map on anything else except 443.
– Maurice Manning
Nov 12 '18 at 21:44
add a comment |
You can use docker's network to isolate your environment, for exemple,
services:
traefik:
networks:
- traefik-net
free-ipa:
networks:
- internal-net
others:
networks:
- traefik-net
- internal-net
Here, others
can access free-ipa
just by using free-ipa
as dns name, and it's accessible by traefik as well. traefik
can't see free-ipa
because they are not in the same network.
Ok that fixes part of the puzle, but the ports 443 still clash on Traefik & freeipa, I need for the public facing sites, and intenal via accessible only names suche as domain/freeipa. Freeipa breaks if you expose/port map on anything else except 443.
– Maurice Manning
Nov 12 '18 at 21:44
add a comment |
You can use docker's network to isolate your environment, for exemple,
services:
traefik:
networks:
- traefik-net
free-ipa:
networks:
- internal-net
others:
networks:
- traefik-net
- internal-net
Here, others
can access free-ipa
just by using free-ipa
as dns name, and it's accessible by traefik as well. traefik
can't see free-ipa
because they are not in the same network.
You can use docker's network to isolate your environment, for exemple,
services:
traefik:
networks:
- traefik-net
free-ipa:
networks:
- internal-net
others:
networks:
- traefik-net
- internal-net
Here, others
can access free-ipa
just by using free-ipa
as dns name, and it's accessible by traefik as well. traefik
can't see free-ipa
because they are not in the same network.
answered Nov 12 '18 at 0:55
Siyu
2,2151624
2,2151624
Ok that fixes part of the puzle, but the ports 443 still clash on Traefik & freeipa, I need for the public facing sites, and intenal via accessible only names suche as domain/freeipa. Freeipa breaks if you expose/port map on anything else except 443.
– Maurice Manning
Nov 12 '18 at 21:44
add a comment |
Ok that fixes part of the puzle, but the ports 443 still clash on Traefik & freeipa, I need for the public facing sites, and intenal via accessible only names suche as domain/freeipa. Freeipa breaks if you expose/port map on anything else except 443.
– Maurice Manning
Nov 12 '18 at 21:44
Ok that fixes part of the puzle, but the ports 443 still clash on Traefik & freeipa, I need for the public facing sites, and intenal via accessible only names suche as domain/freeipa. Freeipa breaks if you expose/port map on anything else except 443.
– Maurice Manning
Nov 12 '18 at 21:44
Ok that fixes part of the puzle, but the ports 443 still clash on Traefik & freeipa, I need for the public facing sites, and intenal via accessible only names suche as domain/freeipa. Freeipa breaks if you expose/port map on anything else except 443.
– Maurice Manning
Nov 12 '18 at 21:44
add a comment |
Thanks for contributing an answer to Stack Overflow!
- Please be sure to answer the question. Provide details and share your research!
But avoid …
- Asking for help, clarification, or responding to other answers.
- Making statements based on opinion; back them up with references or personal experience.
To learn more, see our tips on writing great answers.
Some of your past answers have not been well-received, and you're in danger of being blocked from answering.
Please pay close attention to the following guidance:
- Please be sure to answer the question. Provide details and share your research!
But avoid …
- Asking for help, clarification, or responding to other answers.
- Making statements based on opinion; back them up with references or personal experience.
To learn more, see our tips on writing great answers.
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f53254195%2ftraefik-internal-only-traffic%23new-answer', 'question_page');
);
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown