Skip to content

Repository files navigation

Local Blumilk Traefik environment

This repo contains default Blumilk Traefik configuration for local development environment.

Requirements


Installation


Taskfile setup

Installation

Installation methods: https://taskfile.dev/installation

GitHub: https://github.com/go-task/task
Taskfile releases: https://github.com/go-task/task/releases

Other OS

If you are using other OS, please contribute and create pull request.

Task commands


To list all task commands just run:

task

Task commands completions:


Add this line to .bashrc if you are using bash:

eval "$(task --completion bash)"

For other shells see:
https://taskfile.dev/installation/#option-1-load-the-completions-in-your-shells-startup-config-recommended

Project initialization

Before first use, project has to be initialized.

First, prepare .env file

cp .env.example .env

By default .env file is ready to go, and prepared for Blumilk local environment purposes. So no changes are needed.
But if you need to customize it, just edit .env file.
Project is flexible and all important settings are customizable via .env file.

Docker network

By default, project uses 172.31.0.0/16 network subnet and requires 172.31.100.100 (Traefik) and 172.31.200.200 (Dnsmasq) IPs.
So if you have allocated this network and IPs, you need to remove it before initialization or change network settings in .env file.

Certificates and domain

By default blumilk.local.env domain will be used.
mkcert generate wildcard certificate for *.blumilk.local.env domains.

Project init

This command will prepare all necessary files and configs based on .env file.

task init

This need to be run only once. This command will create .initialized file.
If you want to re-initialize, run task init --force or remove .initialized file.

WARNING, these files will be replaced during initialization:

  • ./traefik/config/static/traefik.yml
  • ./traefik/config/dynamic/certificates.yml
  • ./traefik/config/dynamic/middlewares.yml
  • ./portainer/portainer-admin-password-file - if Portainer has been created, changing password in this file won't change admin password. To change password you need to remove portainer container, volume and recreate it or check Portianer docs
  • ./dns/dnsmasq/dnsmasq.d/blumilk-local-environment.conf
  • ./dns/systemd/resolved.conf.d/blumilk-local-environment.conf
  • .initialized

Usage

To run environment:

task run

Portainer access

By default:
user: admin
password: passwordpassword
dashborad: https://portainer.blumilk.local.env

Traefik access

dashborad: https://traefik.blumilk.local.env

Redirect entry point

Traefik requires one free host port to use redirect entrypoint for localhost hostnames.
By default it is 301 port.
You can customize this host port for this entrypoint in .env file via TRAEFIK_REDIRECT_ENTRYPOINT_HOST_PORT. \

If project has been initialized already, and you changed this value, you need to initialize project again or update regex key in middlewares.yml file manually.

This entrypoint redirect permanent (301 HTTP code) to the part after /.
Example:

http://localhost:301/https://blumilk.pl

will be redirected to https://blumilk.pl.

It is created to handle OAuth2 providers redirects URI (e.g. Google OAuth web app clients). Because you can use only localhost, example.com or real TLD domain.
This allows us to use custom domains (e.g. my-app.blumilk.local.env) and OAuth locally. \

For example, redirect URI will be: http://localhost:301/https://my-app.blumilk.local.env/something

Certificates

We're using mkcert to generate self-signed certificates to support https in local development.
These certificates will cover a local domain *.blumilk.local.env.

Keep in mind that X.509 wildcard certificates only go one level deep.
So a domain a.blumilk.local.env is valid but a.b.blumilk.local.env is not.

Certificates will be valid for 2 years.

Additional certificates for other domains/subdomains

By default, all 1st level subdomains under *.blumilk.local.env will be covered. E.g. foo.blumilk.local.env.

If you need to cover 2nd level subdomains under. *.foo.blumilk.local.env, e.g. bar.foo.blumilk.local.env
you have to generate new certs. Adjust filenames and domain for your needs:

task generate-certs \
CERT_FILENAME=_wildcard.foo.blumilk.local.env.pem \
KEY_FILENAME=_wildcard.foo.blumilk.local.env-key.pem \
DOMAIN=*.foo.blumilk.local.env

Then add certificates to ./traefik/config/dynamic/certificates.yml file:

 - certFile: /certs/_wildcard.foo.blumilk.local.env.pem
keyFile: /certs/_wildcard.foo.blumilk.local.env-key.pem

And restart Traefik (task restart)

HTTPS in containers

If you need to call any *.blumilk.local.env subdomains via https from container, you have to add mkcert CA cert to the docker container.

To do it run container from which you want to send requests via https.
Use container name or ID.

task copy-ca-cert-to-container CONTAINER_NAME=your-container-name

Now you will be able to send requests via https to *.blumilk.local.env domains or others generated via mkcert.

HTTPS in browsers in containers

To use self-signed certs in browsers, we have to add root CA (from mkcert) to the trust store.

To do it, run the container from which you want to add mkcert root CA to the trust store.
Use container name or ID.

task copy-ca-cert-to-trust-store-in-container CONTAINER_NAME=your-container-name

More on mkcert

Reload systemd-resolved configuration

If you changed blumilk-local-environment.conf in ./systemd/resolved.conf.d after project initialization, or want to customize it, run:

task configure-systemd-resolved

It will copy this file to the /etc/systemd/resolved.conf.d and restart systemd-resolved.

Using the environment with your project

Detailed instructions on how to use this environment with your project are available here.

Migration from previous version

  1. Remove old docker stuff:
    • traefik container (traefik-proxy-blumilk-local-container)
    • traefik network (traefik-proxy-blumilk-local)
  2. In projects, you need to update:
    • custom Traefik label from traefik.blumilk.environment to traefik.blumilk.local.environment
    • Traefik network from traefik-proxy-blumilk-local to traefik-proxy-blumilk-local-environment
    • domains from blumilk.localhost to blumilk.local.env

About

Company traefik configuration for development environment.

Resources

Stars

1 star

Watchers

2 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
GitHub - blumilksoftware/environment: Company traefik configuration for development environment. · GitHub
Skip to content

Repository files navigation

Local Blumilk Traefik environment

This repo contains default Blumilk Traefik configuration for local development environment.

Requirements


Installation


Taskfile setup

Installation

Installation methods: https://taskfile.dev/installation

GitHub: https://github.com/go-task/task
Taskfile releases: https://github.com/go-task/task/releases

Other OS

If you are using other OS, please contribute and create pull request.

Task commands


To list all task commands just run:

task

Task commands completions:


Add this line to .bashrc if you are using bash:

eval "$(task --completion bash)"

For other shells see:
https://taskfile.dev/installation/#option-1-load-the-completions-in-your-shells-startup-config-recommended

Project initialization

Before first use, project has to be initialized.

First, prepare .env file

cp .env.example .env

By default .env file is ready to go, and prepared for Blumilk local environment purposes. So no changes are needed.
But if you need to customize it, just edit .env file.
Project is flexible and all important settings are customizable via .env file.

Docker network

By default, project uses 172.31.0.0/16 network subnet and requires 172.31.100.100 (Traefik) and 172.31.200.200 (Dnsmasq) IPs.
So if you have allocated this network and IPs, you need to remove it before initialization or change network settings in .env file.

Certificates and domain

By default blumilk.local.env domain will be used.
mkcert generate wildcard certificate for *.blumilk.local.env domains.

Project init

This command will prepare all necessary files and configs based on .env file.

task init

This need to be run only once. This command will create .initialized file.
If you want to re-initialize, run task init --force or remove .initialized file.

WARNING, these files will be replaced during initialization:

  • ./traefik/config/static/traefik.yml
  • ./traefik/config/dynamic/certificates.yml
  • ./traefik/config/dynamic/middlewares.yml
  • ./portainer/portainer-admin-password-file - if Portainer has been created, changing password in this file won't change admin password. To change password you need to remove portainer container, volume and recreate it or check Portianer docs
  • ./dns/dnsmasq/dnsmasq.d/blumilk-local-environment.conf
  • ./dns/systemd/resolved.conf.d/blumilk-local-environment.conf
  • .initialized

Usage

To run environment:

task run

Portainer access

By default:
user: admin
password: passwordpassword
dashborad: https://portainer.blumilk.local.env

Traefik access

dashborad: https://traefik.blumilk.local.env

Redirect entry point

Traefik requires one free host port to use redirect entrypoint for localhost hostnames.
By default it is 301 port.
You can customize this host port for this entrypoint in .env file via TRAEFIK_REDIRECT_ENTRYPOINT_HOST_PORT. \

If project has been initialized already, and you changed this value, you need to initialize project again or update regex key in middlewares.yml file manually.

This entrypoint redirect permanent (301 HTTP code) to the part after /.
Example:

http://localhost:301/https://blumilk.pl

will be redirected to https://blumilk.pl.

It is created to handle OAuth2 providers redirects URI (e.g. Google OAuth web app clients). Because you can use only localhost, example.com or real TLD domain.
This allows us to use custom domains (e.g. my-app.blumilk.local.env) and OAuth locally. \

For example, redirect URI will be: http://localhost:301/https://my-app.blumilk.local.env/something

Certificates

We're using mkcert to generate self-signed certificates to support https in local development.
These certificates will cover a local domain *.blumilk.local.env.

Keep in mind that X.509 wildcard certificates only go one level deep.
So a domain a.blumilk.local.env is valid but a.b.blumilk.local.env is not.

Certificates will be valid for 2 years.

Additional certificates for other domains/subdomains

By default, all 1st level subdomains under *.blumilk.local.env will be covered. E.g. foo.blumilk.local.env.

If you need to cover 2nd level subdomains under. *.foo.blumilk.local.env, e.g. bar.foo.blumilk.local.env
you have to generate new certs. Adjust filenames and domain for your needs:

task generate-certs \
CERT_FILENAME=_wildcard.foo.blumilk.local.env.pem \
KEY_FILENAME=_wildcard.foo.blumilk.local.env-key.pem \
DOMAIN=*.foo.blumilk.local.env

Then add certificates to ./traefik/config/dynamic/certificates.yml file:

 - certFile: /certs/_wildcard.foo.blumilk.local.env.pem
keyFile: /certs/_wildcard.foo.blumilk.local.env-key.pem

And restart Traefik (task restart)

HTTPS in containers

If you need to call any *.blumilk.local.env subdomains via https from container, you have to add mkcert CA cert to the docker container.

To do it run container from which you want to send requests via https.
Use container name or ID.

task copy-ca-cert-to-container CONTAINER_NAME=your-container-name

Now you will be able to send requests via https to *.blumilk.local.env domains or others generated via mkcert.

HTTPS in browsers in containers

To use self-signed certs in browsers, we have to add root CA (from mkcert) to the trust store.

To do it, run the container from which you want to add mkcert root CA to the trust store.
Use container name or ID.

task copy-ca-cert-to-trust-store-in-container CONTAINER_NAME=your-container-name

More on mkcert

Reload systemd-resolved configuration

If you changed blumilk-local-environment.conf in ./systemd/resolved.conf.d after project initialization, or want to customize it, run:

task configure-systemd-resolved

It will copy this file to the /etc/systemd/resolved.conf.d and restart systemd-resolved.

Using the environment with your project

Detailed instructions on how to use this environment with your project are available here.

Migration from previous version

  1. Remove old docker stuff:
    • traefik container (traefik-proxy-blumilk-local-container)
    • traefik network (traefik-proxy-blumilk-local)
  2. In projects, you need to update:
    • custom Traefik label from traefik.blumilk.environment to traefik.blumilk.local.environment
    • Traefik network from traefik-proxy-blumilk-local to traefik-proxy-blumilk-local-environment
    • domains from blumilk.localhost to blumilk.local.env

About

Company traefik configuration for development environment.

Resources

Stars

1 star

Watchers

2 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' GitHub - blumilksoftware/environment: Company traefik configuration for development environment. · GitHub
Skip to content

Repository files navigation

Local Blumilk Traefik environment

This repo contains default Blumilk Traefik configuration for local development environment.

Requirements


Installation


Taskfile setup

Installation

Installation methods: https://taskfile.dev/installation

GitHub: https://github.com/go-task/task
Taskfile releases: https://github.com/go-task/task/releases

Other OS

If you are using other OS, please contribute and create pull request.

Task commands


To list all task commands just run:

task

Task commands completions:


Add this line to .bashrc if you are using bash:

eval "$(task --completion bash)"

For other shells see:
https://taskfile.dev/installation/#option-1-load-the-completions-in-your-shells-startup-config-recommended

Project initialization

Before first use, project has to be initialized.

First, prepare .env file

cp .env.example .env

By default .env file is ready to go, and prepared for Blumilk local environment purposes. So no changes are needed.
But if you need to customize it, just edit .env file.
Project is flexible and all important settings are customizable via .env file.

Docker network

By default, project uses 172.31.0.0/16 network subnet and requires 172.31.100.100 (Traefik) and 172.31.200.200 (Dnsmasq) IPs.
So if you have allocated this network and IPs, you need to remove it before initialization or change network settings in .env file.

Certificates and domain

By default blumilk.local.env domain will be used.
mkcert generate wildcard certificate for *.blumilk.local.env domains.

Project init

This command will prepare all necessary files and configs based on .env file.

task init

This need to be run only once. This command will create .initialized file.
If you want to re-initialize, run task init --force or remove .initialized file.

WARNING, these files will be replaced during initialization:

  • ./traefik/config/static/traefik.yml
  • ./traefik/config/dynamic/certificates.yml
  • ./traefik/config/dynamic/middlewares.yml
  • ./portainer/portainer-admin-password-file - if Portainer has been created, changing password in this file won't change admin password. To change password you need to remove portainer container, volume and recreate it or check Portianer docs
  • ./dns/dnsmasq/dnsmasq.d/blumilk-local-environment.conf
  • ./dns/systemd/resolved.conf.d/blumilk-local-environment.conf
  • .initialized

Usage

To run environment:

task run

Portainer access

By default:
user: admin
password: passwordpassword
dashborad: https://portainer.blumilk.local.env

Traefik access

dashborad: https://traefik.blumilk.local.env

Redirect entry point

Traefik requires one free host port to use redirect entrypoint for localhost hostnames.
By default it is 301 port.
You can customize this host port for this entrypoint in .env file via TRAEFIK_REDIRECT_ENTRYPOINT_HOST_PORT. \

If project has been initialized already, and you changed this value, you need to initialize project again or update regex key in middlewares.yml file manually.

This entrypoint redirect permanent (301 HTTP code) to the part after /.
Example:

http://localhost:301/https://blumilk.pl

will be redirected to https://blumilk.pl.

It is created to handle OAuth2 providers redirects URI (e.g. Google OAuth web app clients). Because you can use only localhost, example.com or real TLD domain.
This allows us to use custom domains (e.g. my-app.blumilk.local.env) and OAuth locally. \

For example, redirect URI will be: http://localhost:301/https://my-app.blumilk.local.env/something

Certificates

We're using mkcert to generate self-signed certificates to support https in local development.
These certificates will cover a local domain *.blumilk.local.env.

Keep in mind that X.509 wildcard certificates only go one level deep.
So a domain a.blumilk.local.env is valid but a.b.blumilk.local.env is not.

Certificates will be valid for 2 years.

Additional certificates for other domains/subdomains

By default, all 1st level subdomains under *.blumilk.local.env will be covered. E.g. foo.blumilk.local.env.

If you need to cover 2nd level subdomains under. *.foo.blumilk.local.env, e.g. bar.foo.blumilk.local.env
you have to generate new certs. Adjust filenames and domain for your needs:

task generate-certs \
CERT_FILENAME=_wildcard.foo.blumilk.local.env.pem \
KEY_FILENAME=_wildcard.foo.blumilk.local.env-key.pem \
DOMAIN=*.foo.blumilk.local.env

Then add certificates to ./traefik/config/dynamic/certificates.yml file:

 - certFile: /certs/_wildcard.foo.blumilk.local.env.pem
keyFile: /certs/_wildcard.foo.blumilk.local.env-key.pem

And restart Traefik (task restart)

HTTPS in containers

If you need to call any *.blumilk.local.env subdomains via https from container, you have to add mkcert CA cert to the docker container.

To do it run container from which you want to send requests via https.
Use container name or ID.

task copy-ca-cert-to-container CONTAINER_NAME=your-container-name

Now you will be able to send requests via https to *.blumilk.local.env domains or others generated via mkcert.

HTTPS in browsers in containers

To use self-signed certs in browsers, we have to add root CA (from mkcert) to the trust store.

To do it, run the container from which you want to add mkcert root CA to the trust store.
Use container name or ID.

task copy-ca-cert-to-trust-store-in-container CONTAINER_NAME=your-container-name

More on mkcert

Reload systemd-resolved configuration

If you changed blumilk-local-environment.conf in ./systemd/resolved.conf.d after project initialization, or want to customize it, run:

task configure-systemd-resolved

It will copy this file to the /etc/systemd/resolved.conf.d and restart systemd-resolved.

Using the environment with your project

Detailed instructions on how to use this environment with your project are available here.

Migration from previous version

  1. Remove old docker stuff:
    • traefik container (traefik-proxy-blumilk-local-container)
    • traefik network (traefik-proxy-blumilk-local)
  2. In projects, you need to update:
    • custom Traefik label from traefik.blumilk.environment to traefik.blumilk.local.environment
    • Traefik network from traefik-proxy-blumilk-local to traefik-proxy-blumilk-local-environment
    • domains from blumilk.localhost to blumilk.local.env

About

Company traefik configuration for development environment.

Resources

Stars

1 star

Watchers

2 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' GitHub - blumilksoftware/environment: Company traefik configuration for development environment. · GitHub
Skip to content

Repository files navigation

Local Blumilk Traefik environment

This repo contains default Blumilk Traefik configuration for local development environment.

Requirements


Installation


Taskfile setup

Installation

Installation methods: https://taskfile.dev/installation

GitHub: https://github.com/go-task/task
Taskfile releases: https://github.com/go-task/task/releases

Other OS

If you are using other OS, please contribute and create pull request.

Task commands


To list all task commands just run:

task

Task commands completions:


Add this line to .bashrc if you are using bash:

eval "$(task --completion bash)"

For other shells see:
https://taskfile.dev/installation/#option-1-load-the-completions-in-your-shells-startup-config-recommended

Project initialization

Before first use, project has to be initialized.

First, prepare .env file

cp .env.example .env

By default .env file is ready to go, and prepared for Blumilk local environment purposes. So no changes are needed.
But if you need to customize it, just edit .env file.
Project is flexible and all important settings are customizable via .env file.

Docker network

By default, project uses 172.31.0.0/16 network subnet and requires 172.31.100.100 (Traefik) and 172.31.200.200 (Dnsmasq) IPs.
So if you have allocated this network and IPs, you need to remove it before initialization or change network settings in .env file.

Certificates and domain

By default blumilk.local.env domain will be used.
mkcert generate wildcard certificate for *.blumilk.local.env domains.

Project init

This command will prepare all necessary files and configs based on .env file.

task init

This need to be run only once. This command will create .initialized file.
If you want to re-initialize, run task init --force or remove .initialized file.

WARNING, these files will be replaced during initialization:

  • ./traefik/config/static/traefik.yml
  • ./traefik/config/dynamic/certificates.yml
  • ./traefik/config/dynamic/middlewares.yml
  • ./portainer/portainer-admin-password-file - if Portainer has been created, changing password in this file won't change admin password. To change password you need to remove portainer container, volume and recreate it or check Portianer docs
  • ./dns/dnsmasq/dnsmasq.d/blumilk-local-environment.conf
  • ./dns/systemd/resolved.conf.d/blumilk-local-environment.conf
  • .initialized

Usage

To run environment:

task run

Portainer access

By default:
user: admin
password: passwordpassword
dashborad: https://portainer.blumilk.local.env

Traefik access

dashborad: https://traefik.blumilk.local.env

Redirect entry point

Traefik requires one free host port to use redirect entrypoint for localhost hostnames.
By default it is 301 port.
You can customize this host port for this entrypoint in .env file via TRAEFIK_REDIRECT_ENTRYPOINT_HOST_PORT. \

If project has been initialized already, and you changed this value, you need to initialize project again or update regex key in middlewares.yml file manually.

This entrypoint redirect permanent (301 HTTP code) to the part after /.
Example:

http://localhost:301/https://blumilk.pl

will be redirected to https://blumilk.pl.

It is created to handle OAuth2 providers redirects URI (e.g. Google OAuth web app clients). Because you can use only localhost, example.com or real TLD domain.
This allows us to use custom domains (e.g. my-app.blumilk.local.env) and OAuth locally. \

For example, redirect URI will be: http://localhost:301/https://my-app.blumilk.local.env/something

Certificates

We're using mkcert to generate self-signed certificates to support https in local development.
These certificates will cover a local domain *.blumilk.local.env.

Keep in mind that X.509 wildcard certificates only go one level deep.
So a domain a.blumilk.local.env is valid but a.b.blumilk.local.env is not.

Certificates will be valid for 2 years.

Additional certificates for other domains/subdomains

By default, all 1st level subdomains under *.blumilk.local.env will be covered. E.g. foo.blumilk.local.env.

If you need to cover 2nd level subdomains under. *.foo.blumilk.local.env, e.g. bar.foo.blumilk.local.env
you have to generate new certs. Adjust filenames and domain for your needs:

task generate-certs \
CERT_FILENAME=_wildcard.foo.blumilk.local.env.pem \
KEY_FILENAME=_wildcard.foo.blumilk.local.env-key.pem \
DOMAIN=*.foo.blumilk.local.env

Then add certificates to ./traefik/config/dynamic/certificates.yml file:

 - certFile: /certs/_wildcard.foo.blumilk.local.env.pem
keyFile: /certs/_wildcard.foo.blumilk.local.env-key.pem

And restart Traefik (task restart)

HTTPS in containers

If you need to call any *.blumilk.local.env subdomains via https from container, you have to add mkcert CA cert to the docker container.

To do it run container from which you want to send requests via https.
Use container name or ID.

task copy-ca-cert-to-container CONTAINER_NAME=your-container-name

Now you will be able to send requests via https to *.blumilk.local.env domains or others generated via mkcert.

HTTPS in browsers in containers

To use self-signed certs in browsers, we have to add root CA (from mkcert) to the trust store.

To do it, run the container from which you want to add mkcert root CA to the trust store.
Use container name or ID.

task copy-ca-cert-to-trust-store-in-container CONTAINER_NAME=your-container-name

More on mkcert

Reload systemd-resolved configuration

If you changed blumilk-local-environment.conf in ./systemd/resolved.conf.d after project initialization, or want to customize it, run:

task configure-systemd-resolved

It will copy this file to the /etc/systemd/resolved.conf.d and restart systemd-resolved.

Using the environment with your project

Detailed instructions on how to use this environment with your project are available here.

Migration from previous version

  1. Remove old docker stuff:
    • traefik container (traefik-proxy-blumilk-local-container)
    • traefik network (traefik-proxy-blumilk-local)
  2. In projects, you need to update:
    • custom Traefik label from traefik.blumilk.environment to traefik.blumilk.local.environment
    • Traefik network from traefik-proxy-blumilk-local to traefik-proxy-blumilk-local-environment
    • domains from blumilk.localhost to blumilk.local.env

About

Company traefik configuration for development environment.

Resources

Stars

1 star

Watchers

2 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' GitHub - blumilksoftware/environment: Company traefik configuration for development environment. · GitHub
Skip to content

Repository files navigation

Local Blumilk Traefik environment

This repo contains default Blumilk Traefik configuration for local development environment.

Requirements


Installation


Taskfile setup

Installation

Installation methods: https://taskfile.dev/installation

GitHub: https://github.com/go-task/task
Taskfile releases: https://github.com/go-task/task/releases

Other OS

If you are using other OS, please contribute and create pull request.

Task commands


To list all task commands just run:

task

Task commands completions:


Add this line to .bashrc if you are using bash:

eval "$(task --completion bash)"

For other shells see:
https://taskfile.dev/installation/#option-1-load-the-completions-in-your-shells-startup-config-recommended

Project initialization

Before first use, project has to be initialized.

First, prepare .env file

cp .env.example .env

By default .env file is ready to go, and prepared for Blumilk local environment purposes. So no changes are needed.
But if you need to customize it, just edit .env file.
Project is flexible and all important settings are customizable via .env file.

Docker network

By default, project uses 172.31.0.0/16 network subnet and requires 172.31.100.100 (Traefik) and 172.31.200.200 (Dnsmasq) IPs.
So if you have allocated this network and IPs, you need to remove it before initialization or change network settings in .env file.

Certificates and domain

By default blumilk.local.env domain will be used.
mkcert generate wildcard certificate for *.blumilk.local.env domains.

Project init

This command will prepare all necessary files and configs based on .env file.

task init

This need to be run only once. This command will create .initialized file.
If you want to re-initialize, run task init --force or remove .initialized file.

WARNING, these files will be replaced during initialization:

  • ./traefik/config/static/traefik.yml
  • ./traefik/config/dynamic/certificates.yml
  • ./traefik/config/dynamic/middlewares.yml
  • ./portainer/portainer-admin-password-file - if Portainer has been created, changing password in this file won't change admin password. To change password you need to remove portainer container, volume and recreate it or check Portianer docs
  • ./dns/dnsmasq/dnsmasq.d/blumilk-local-environment.conf
  • ./dns/systemd/resolved.conf.d/blumilk-local-environment.conf
  • .initialized

Usage

To run environment:

task run

Portainer access

By default:
user: admin
password: passwordpassword
dashborad: https://portainer.blumilk.local.env

Traefik access

dashborad: https://traefik.blumilk.local.env

Redirect entry point

Traefik requires one free host port to use redirect entrypoint for localhost hostnames.
By default it is 301 port.
You can customize this host port for this entrypoint in .env file via TRAEFIK_REDIRECT_ENTRYPOINT_HOST_PORT. \

If project has been initialized already, and you changed this value, you need to initialize project again or update regex key in middlewares.yml file manually.

This entrypoint redirect permanent (301 HTTP code) to the part after /.
Example:

http://localhost:301/https://blumilk.pl

will be redirected to https://blumilk.pl.

It is created to handle OAuth2 providers redirects URI (e.g. Google OAuth web app clients). Because you can use only localhost, example.com or real TLD domain.
This allows us to use custom domains (e.g. my-app.blumilk.local.env) and OAuth locally. \

For example, redirect URI will be: http://localhost:301/https://my-app.blumilk.local.env/something

Certificates

We're using mkcert to generate self-signed certificates to support https in local development.
These certificates will cover a local domain *.blumilk.local.env.

Keep in mind that X.509 wildcard certificates only go one level deep.
So a domain a.blumilk.local.env is valid but a.b.blumilk.local.env is not.

Certificates will be valid for 2 years.

Additional certificates for other domains/subdomains

By default, all 1st level subdomains under *.blumilk.local.env will be covered. E.g. foo.blumilk.local.env.

If you need to cover 2nd level subdomains under. *.foo.blumilk.local.env, e.g. bar.foo.blumilk.local.env
you have to generate new certs. Adjust filenames and domain for your needs:

task generate-certs \
CERT_FILENAME=_wildcard.foo.blumilk.local.env.pem \
KEY_FILENAME=_wildcard.foo.blumilk.local.env-key.pem \
DOMAIN=*.foo.blumilk.local.env

Then add certificates to ./traefik/config/dynamic/certificates.yml file:

 - certFile: /certs/_wildcard.foo.blumilk.local.env.pem
keyFile: /certs/_wildcard.foo.blumilk.local.env-key.pem

And restart Traefik (task restart)

HTTPS in containers

If you need to call any *.blumilk.local.env subdomains via https from container, you have to add mkcert CA cert to the docker container.

To do it run container from which you want to send requests via https.
Use container name or ID.

task copy-ca-cert-to-container CONTAINER_NAME=your-container-name

Now you will be able to send requests via https to *.blumilk.local.env domains or others generated via mkcert.

HTTPS in browsers in containers

To use self-signed certs in browsers, we have to add root CA (from mkcert) to the trust store.

To do it, run the container from which you want to add mkcert root CA to the trust store.
Use container name or ID.

task copy-ca-cert-to-trust-store-in-container CONTAINER_NAME=your-container-name

More on mkcert

Reload systemd-resolved configuration

If you changed blumilk-local-environment.conf in ./systemd/resolved.conf.d after project initialization, or want to customize it, run:

task configure-systemd-resolved

It will copy this file to the /etc/systemd/resolved.conf.d and restart systemd-resolved.

Using the environment with your project

Detailed instructions on how to use this environment with your project are available here.

Migration from previous version

  1. Remove old docker stuff:
    • traefik container (traefik-proxy-blumilk-local-container)
    • traefik network (traefik-proxy-blumilk-local)
  2. In projects, you need to update:
    • custom Traefik label from traefik.blumilk.environment to traefik.blumilk.local.environment
    • Traefik network from traefik-proxy-blumilk-local to traefik-proxy-blumilk-local-environment
    • domains from blumilk.localhost to blumilk.local.env

About

Company traefik configuration for development environment.

Resources

Stars

1 star

Watchers

2 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' GitHub - blumilksoftware/environment: Company traefik configuration for development environment. · GitHub
Skip to content

Repository files navigation

Local Blumilk Traefik environment

This repo contains default Blumilk Traefik configuration for local development environment.

Requirements


Installation


Taskfile setup

Installation

Installation methods: https://taskfile.dev/installation

GitHub: https://github.com/go-task/task
Taskfile releases: https://github.com/go-task/task/releases

Other OS

If you are using other OS, please contribute and create pull request.

Task commands


To list all task commands just run:

task

Task commands completions:


Add this line to .bashrc if you are using bash:

eval "$(task --completion bash)"

For other shells see:
https://taskfile.dev/installation/#option-1-load-the-completions-in-your-shells-startup-config-recommended

Project initialization

Before first use, project has to be initialized.

First, prepare .env file

cp .env.example .env

By default .env file is ready to go, and prepared for Blumilk local environment purposes. So no changes are needed.
But if you need to customize it, just edit .env file.
Project is flexible and all important settings are customizable via .env file.

Docker network

By default, project uses 172.31.0.0/16 network subnet and requires 172.31.100.100 (Traefik) and 172.31.200.200 (Dnsmasq) IPs.
So if you have allocated this network and IPs, you need to remove it before initialization or change network settings in .env file.

Certificates and domain

By default blumilk.local.env domain will be used.
mkcert generate wildcard certificate for *.blumilk.local.env domains.

Project init

This command will prepare all necessary files and configs based on .env file.

task init

This need to be run only once. This command will create .initialized file.
If you want to re-initialize, run task init --force or remove .initialized file.

WARNING, these files will be replaced during initialization:

  • ./traefik/config/static/traefik.yml
  • ./traefik/config/dynamic/certificates.yml
  • ./traefik/config/dynamic/middlewares.yml
  • ./portainer/portainer-admin-password-file - if Portainer has been created, changing password in this file won't change admin password. To change password you need to remove portainer container, volume and recreate it or check Portianer docs
  • ./dns/dnsmasq/dnsmasq.d/blumilk-local-environment.conf
  • ./dns/systemd/resolved.conf.d/blumilk-local-environment.conf
  • .initialized

Usage

To run environment:

task run

Portainer access

By default:
user: admin
password: passwordpassword
dashborad: https://portainer.blumilk.local.env

Traefik access

dashborad: https://traefik.blumilk.local.env

Redirect entry point

Traefik requires one free host port to use redirect entrypoint for localhost hostnames.
By default it is 301 port.
You can customize this host port for this entrypoint in .env file via TRAEFIK_REDIRECT_ENTRYPOINT_HOST_PORT. \

If project has been initialized already, and you changed this value, you need to initialize project again or update regex key in middlewares.yml file manually.

This entrypoint redirect permanent (301 HTTP code) to the part after /.
Example:

http://localhost:301/https://blumilk.pl

will be redirected to https://blumilk.pl.

It is created to handle OAuth2 providers redirects URI (e.g. Google OAuth web app clients). Because you can use only localhost, example.com or real TLD domain.
This allows us to use custom domains (e.g. my-app.blumilk.local.env) and OAuth locally. \

For example, redirect URI will be: http://localhost:301/https://my-app.blumilk.local.env/something

Certificates

We're using mkcert to generate self-signed certificates to support https in local development.
These certificates will cover a local domain *.blumilk.local.env.

Keep in mind that X.509 wildcard certificates only go one level deep.
So a domain a.blumilk.local.env is valid but a.b.blumilk.local.env is not.

Certificates will be valid for 2 years.

Additional certificates for other domains/subdomains

By default, all 1st level subdomains under *.blumilk.local.env will be covered. E.g. foo.blumilk.local.env.

If you need to cover 2nd level subdomains under. *.foo.blumilk.local.env, e.g. bar.foo.blumilk.local.env
you have to generate new certs. Adjust filenames and domain for your needs:

task generate-certs \
CERT_FILENAME=_wildcard.foo.blumilk.local.env.pem \
KEY_FILENAME=_wildcard.foo.blumilk.local.env-key.pem \
DOMAIN=*.foo.blumilk.local.env

Then add certificates to ./traefik/config/dynamic/certificates.yml file:

 - certFile: /certs/_wildcard.foo.blumilk.local.env.pem
keyFile: /certs/_wildcard.foo.blumilk.local.env-key.pem

And restart Traefik (task restart)

HTTPS in containers

If you need to call any *.blumilk.local.env subdomains via https from container, you have to add mkcert CA cert to the docker container.

To do it run container from which you want to send requests via https.
Use container name or ID.

task copy-ca-cert-to-container CONTAINER_NAME=your-container-name

Now you will be able to send requests via https to *.blumilk.local.env domains or others generated via mkcert.

HTTPS in browsers in containers

To use self-signed certs in browsers, we have to add root CA (from mkcert) to the trust store.

To do it, run the container from which you want to add mkcert root CA to the trust store.
Use container name or ID.

task copy-ca-cert-to-trust-store-in-container CONTAINER_NAME=your-container-name

More on mkcert

Reload systemd-resolved configuration

If you changed blumilk-local-environment.conf in ./systemd/resolved.conf.d after project initialization, or want to customize it, run:

task configure-systemd-resolved

It will copy this file to the /etc/systemd/resolved.conf.d and restart systemd-resolved.

Using the environment with your project

Detailed instructions on how to use this environment with your project are available here.

Migration from previous version

  1. Remove old docker stuff:
    • traefik container (traefik-proxy-blumilk-local-container)
    • traefik network (traefik-proxy-blumilk-local)
  2. In projects, you need to update:
    • custom Traefik label from traefik.blumilk.environment to traefik.blumilk.local.environment
    • Traefik network from traefik-proxy-blumilk-local to traefik-proxy-blumilk-local-environment
    • domains from blumilk.localhost to blumilk.local.env

About

Company traefik configuration for development environment.

Resources

Stars

1 star

Watchers

2 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' GitHub - blumilksoftware/environment: Company traefik configuration for development environment. · GitHub
Skip to content

Repository files navigation

Local Blumilk Traefik environment

This repo contains default Blumilk Traefik configuration for local development environment.

Requirements


Installation


Taskfile setup

Installation

Installation methods: https://taskfile.dev/installation

GitHub: https://github.com/go-task/task
Taskfile releases: https://github.com/go-task/task/releases

Other OS

If you are using other OS, please contribute and create pull request.

Task commands


To list all task commands just run:

task

Task commands completions:


Add this line to .bashrc if you are using bash:

eval "$(task --completion bash)"

For other shells see:
https://taskfile.dev/installation/#option-1-load-the-completions-in-your-shells-startup-config-recommended

Project initialization

Before first use, project has to be initialized.

First, prepare .env file

cp .env.example .env

By default .env file is ready to go, and prepared for Blumilk local environment purposes. So no changes are needed.
But if you need to customize it, just edit .env file.
Project is flexible and all important settings are customizable via .env file.

Docker network

By default, project uses 172.31.0.0/16 network subnet and requires 172.31.100.100 (Traefik) and 172.31.200.200 (Dnsmasq) IPs.
So if you have allocated this network and IPs, you need to remove it before initialization or change network settings in .env file.

Certificates and domain

By default blumilk.local.env domain will be used.
mkcert generate wildcard certificate for *.blumilk.local.env domains.

Project init

This command will prepare all necessary files and configs based on .env file.

task init

This need to be run only once. This command will create .initialized file.
If you want to re-initialize, run task init --force or remove .initialized file.

WARNING, these files will be replaced during initialization:

  • ./traefik/config/static/traefik.yml
  • ./traefik/config/dynamic/certificates.yml
  • ./traefik/config/dynamic/middlewares.yml
  • ./portainer/portainer-admin-password-file - if Portainer has been created, changing password in this file won't change admin password. To change password you need to remove portainer container, volume and recreate it or check Portianer docs
  • ./dns/dnsmasq/dnsmasq.d/blumilk-local-environment.conf
  • ./dns/systemd/resolved.conf.d/blumilk-local-environment.conf
  • .initialized

Usage

To run environment:

task run

Portainer access

By default:
user: admin
password: passwordpassword
dashborad: https://portainer.blumilk.local.env

Traefik access

dashborad: https://traefik.blumilk.local.env

Redirect entry point

Traefik requires one free host port to use redirect entrypoint for localhost hostnames.
By default it is 301 port.
You can customize this host port for this entrypoint in .env file via TRAEFIK_REDIRECT_ENTRYPOINT_HOST_PORT. \

If project has been initialized already, and you changed this value, you need to initialize project again or update regex key in middlewares.yml file manually.

This entrypoint redirect permanent (301 HTTP code) to the part after /.
Example:

http://localhost:301/https://blumilk.pl

will be redirected to https://blumilk.pl.

It is created to handle OAuth2 providers redirects URI (e.g. Google OAuth web app clients). Because you can use only localhost, example.com or real TLD domain.
This allows us to use custom domains (e.g. my-app.blumilk.local.env) and OAuth locally. \

For example, redirect URI will be: http://localhost:301/https://my-app.blumilk.local.env/something

Certificates

We're using mkcert to generate self-signed certificates to support https in local development.
These certificates will cover a local domain *.blumilk.local.env.

Keep in mind that X.509 wildcard certificates only go one level deep.
So a domain a.blumilk.local.env is valid but a.b.blumilk.local.env is not.

Certificates will be valid for 2 years.

Additional certificates for other domains/subdomains

By default, all 1st level subdomains under *.blumilk.local.env will be covered. E.g. foo.blumilk.local.env.

If you need to cover 2nd level subdomains under. *.foo.blumilk.local.env, e.g. bar.foo.blumilk.local.env
you have to generate new certs. Adjust filenames and domain for your needs:

task generate-certs \
CERT_FILENAME=_wildcard.foo.blumilk.local.env.pem \
KEY_FILENAME=_wildcard.foo.blumilk.local.env-key.pem \
DOMAIN=*.foo.blumilk.local.env

Then add certificates to ./traefik/config/dynamic/certificates.yml file:

 - certFile: /certs/_wildcard.foo.blumilk.local.env.pem
keyFile: /certs/_wildcard.foo.blumilk.local.env-key.pem

And restart Traefik (task restart)

HTTPS in containers

If you need to call any *.blumilk.local.env subdomains via https from container, you have to add mkcert CA cert to the docker container.

To do it run container from which you want to send requests via https.
Use container name or ID.

task copy-ca-cert-to-container CONTAINER_NAME=your-container-name

Now you will be able to send requests via https to *.blumilk.local.env domains or others generated via mkcert.

HTTPS in browsers in containers

To use self-signed certs in browsers, we have to add root CA (from mkcert) to the trust store.

To do it, run the container from which you want to add mkcert root CA to the trust store.
Use container name or ID.

task copy-ca-cert-to-trust-store-in-container CONTAINER_NAME=your-container-name

More on mkcert

Reload systemd-resolved configuration

If you changed blumilk-local-environment.conf in ./systemd/resolved.conf.d after project initialization, or want to customize it, run:

task configure-systemd-resolved

It will copy this file to the /etc/systemd/resolved.conf.d and restart systemd-resolved.

Using the environment with your project

Detailed instructions on how to use this environment with your project are available here.

Migration from previous version

  1. Remove old docker stuff:
    • traefik container (traefik-proxy-blumilk-local-container)
    • traefik network (traefik-proxy-blumilk-local)
  2. In projects, you need to update:
    • custom Traefik label from traefik.blumilk.environment to traefik.blumilk.local.environment
    • Traefik network from traefik-proxy-blumilk-local to traefik-proxy-blumilk-local-environment
    • domains from blumilk.localhost to blumilk.local.env

About

Company traefik configuration for development environment.

Resources

Stars

1 star

Watchers

2 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); GitHub - blumilksoftware/environment: Company traefik configuration for development environment. · GitHub
Skip to content

Repository files navigation

Local Blumilk Traefik environment

This repo contains default Blumilk Traefik configuration for local development environment.

Requirements


Installation


Taskfile setup

Installation

Installation methods: https://taskfile.dev/installation

GitHub: https://github.com/go-task/task
Taskfile releases: https://github.com/go-task/task/releases

Other OS

If you are using other OS, please contribute and create pull request.

Task commands


To list all task commands just run:

task

Task commands completions:


Add this line to .bashrc if you are using bash:

eval "$(task --completion bash)"

For other shells see:
https://taskfile.dev/installation/#option-1-load-the-completions-in-your-shells-startup-config-recommended

Project initialization

Before first use, project has to be initialized.

First, prepare .env file

cp .env.example .env

By default .env file is ready to go, and prepared for Blumilk local environment purposes. So no changes are needed.
But if you need to customize it, just edit .env file.
Project is flexible and all important settings are customizable via .env file.

Docker network

By default, project uses 172.31.0.0/16 network subnet and requires 172.31.100.100 (Traefik) and 172.31.200.200 (Dnsmasq) IPs.
So if you have allocated this network and IPs, you need to remove it before initialization or change network settings in .env file.

Certificates and domain

By default blumilk.local.env domain will be used.
mkcert generate wildcard certificate for *.blumilk.local.env domains.

Project init

This command will prepare all necessary files and configs based on .env file.

task init

This need to be run only once. This command will create .initialized file.
If you want to re-initialize, run task init --force or remove .initialized file.

WARNING, these files will be replaced during initialization:

  • ./traefik/config/static/traefik.yml
  • ./traefik/config/dynamic/certificates.yml
  • ./traefik/config/dynamic/middlewares.yml
  • ./portainer/portainer-admin-password-file - if Portainer has been created, changing password in this file won't change admin password. To change password you need to remove portainer container, volume and recreate it or check Portianer docs
  • ./dns/dnsmasq/dnsmasq.d/blumilk-local-environment.conf
  • ./dns/systemd/resolved.conf.d/blumilk-local-environment.conf
  • .initialized

Usage

To run environment:

task run

Portainer access

By default:
user: admin
password: passwordpassword
dashborad: https://portainer.blumilk.local.env

Traefik access

dashborad: https://traefik.blumilk.local.env

Redirect entry point

Traefik requires one free host port to use redirect entrypoint for localhost hostnames.
By default it is 301 port.
You can customize this host port for this entrypoint in .env file via TRAEFIK_REDIRECT_ENTRYPOINT_HOST_PORT. \

If project has been initialized already, and you changed this value, you need to initialize project again or update regex key in middlewares.yml file manually.

This entrypoint redirect permanent (301 HTTP code) to the part after /.
Example:

http://localhost:301/https://blumilk.pl

will be redirected to https://blumilk.pl.

It is created to handle OAuth2 providers redirects URI (e.g. Google OAuth web app clients). Because you can use only localhost, example.com or real TLD domain.
This allows us to use custom domains (e.g. my-app.blumilk.local.env) and OAuth locally. \

For example, redirect URI will be: http://localhost:301/https://my-app.blumilk.local.env/something

Certificates

We're using mkcert to generate self-signed certificates to support https in local development.
These certificates will cover a local domain *.blumilk.local.env.

Keep in mind that X.509 wildcard certificates only go one level deep.
So a domain a.blumilk.local.env is valid but a.b.blumilk.local.env is not.

Certificates will be valid for 2 years.

Additional certificates for other domains/subdomains

By default, all 1st level subdomains under *.blumilk.local.env will be covered. E.g. foo.blumilk.local.env.

If you need to cover 2nd level subdomains under. *.foo.blumilk.local.env, e.g. bar.foo.blumilk.local.env
you have to generate new certs. Adjust filenames and domain for your needs:

task generate-certs \
CERT_FILENAME=_wildcard.foo.blumilk.local.env.pem \
KEY_FILENAME=_wildcard.foo.blumilk.local.env-key.pem \
DOMAIN=*.foo.blumilk.local.env

Then add certificates to ./traefik/config/dynamic/certificates.yml file:

 - certFile: /certs/_wildcard.foo.blumilk.local.env.pem
keyFile: /certs/_wildcard.foo.blumilk.local.env-key.pem

And restart Traefik (task restart)

HTTPS in containers

If you need to call any *.blumilk.local.env subdomains via https from container, you have to add mkcert CA cert to the docker container.

To do it run container from which you want to send requests via https.
Use container name or ID.

task copy-ca-cert-to-container CONTAINER_NAME=your-container-name

Now you will be able to send requests via https to *.blumilk.local.env domains or others generated via mkcert.

HTTPS in browsers in containers

To use self-signed certs in browsers, we have to add root CA (from mkcert) to the trust store.

To do it, run the container from which you want to add mkcert root CA to the trust store.
Use container name or ID.

task copy-ca-cert-to-trust-store-in-container CONTAINER_NAME=your-container-name

More on mkcert

Reload systemd-resolved configuration

If you changed blumilk-local-environment.conf in ./systemd/resolved.conf.d after project initialization, or want to customize it, run:

task configure-systemd-resolved

It will copy this file to the /etc/systemd/resolved.conf.d and restart systemd-resolved.

Using the environment with your project

Detailed instructions on how to use this environment with your project are available here.

Migration from previous version

  1. Remove old docker stuff:
    • traefik container (traefik-proxy-blumilk-local-container)
    • traefik network (traefik-proxy-blumilk-local)
  2. In projects, you need to update:
    • custom Traefik label from traefik.blumilk.environment to traefik.blumilk.local.environment
    • Traefik network from traefik-proxy-blumilk-local to traefik-proxy-blumilk-local-environment
    • domains from blumilk.localhost to blumilk.local.env

About

Company traefik configuration for development environment.

Resources

Stars

1 star

Watchers

2 watching

Forks

Releases

Packages

Contributors

Languages