Sign inSign up

benzine/bouncer

By benzine

•Updated over 2 years ago

Automatic Swarm Nginx Loadbalancer

Image
Networking
0

752

benzine/bouncer repository overview

⁠Automatic Swarm Nginx Loadbalancer

⁠Environment variables

This container has its own environment variables, AS WELL AS scanning for some environment variables associated with your services. These should not be confused.

⁠Load balancer Configuration
⁠Main configuration
KeyDefaultOptionsBehaviour
DOCKER_HOSTfalseDefine a http endpoint representing your docker socket. If this is null, it connects to /var/lib/docker.sock
GLOBAL_CERTfalseContents of an ssl certificateIf you want to provide a single cert for all endpoints, perhaps with a catch-all that may be later overriden, you can provide the whole contents of a certificates file here.
GLOBAL_CERT_KEYfalseContents of an ssl certificates private keyThe private key related to GLOBAL CERT. These must be provided in tandem.
BOUNCER_FORCED_UPDATE_INTERVAL_SECONDSfalsepositive numbersTo force the bouncer to update on a schedule even if no changes are detected, measured in seconds
⁠For using with lets encrypt
KeyDefaultOptionsBehaviour
BOUNCER_LETSENCRYPT_MODE'staging''staging' or 'production'Determine if this is going to connect to a production or staging Lets Encrypt server
BOUNCER_LETSENCRYPT_EMAIL'[email protected]⁠'Email address to associate with lets encrypt
⁠For using S3 for generated cert synchronisation with Lets Encrypt
KeyDefaultOptionsBehaviour
BOUNCER_S3_BUCKETfalseenable S3 behaviour to store lets-encrypt generated certs
BOUNCER_S3_ENDPOINTfalsedefine s3 endpoint to override default AWS s3 implementation, for example, with minio
BOUNCER_S3_KEY_IDfalseS3 API Key ID
BOUNCER_s3_KEY_SECRETfalseS3 API Key Secret
BOUNCER_S3_REGIONfalseS3 API Region
BOUNCER_S3_USE_PATH_STYLE_ENDPOINTfalsetrue or falseNeeded for minio
BOUNCER_S3_PREFIXfalsePrefix file path in s3 bucket
⁠Served Instance Configuration

These environment variables need to be applied to the CONSUMING SERVICE and not the loadbalancer container itself.

KeyExampleBehaviour
BOUNCER_DOMAIN"a.example.com"The domain that should be directed to this container
BOUNCER_LETSENCRYPTValues are "yes" or "true", anything else is falseTo enable, or disable Lets Encrypt service for this hostname
BOUNCER_TARGET_PORT9000Explicitly define the port you want to hit the service on, in case of ambiguity
BOUNCER_ALLOW_NON_SSLDefaults to enabled. Values are "yes" or "true", anything else is falseShould HTTP only traffic be allowed to hit this service? If disabled, http traffic is forwarded towards https
BOUNCER_ALLOW_WEBSOCKETSDefaults to enabled. Values are "yes" or "true", anything else is falseEnable websocket behaviour
BOUNCER_ALLOW_LARGE_PAYLOADSDefaults to disabled.Allows overriding the default nginx payload size. Related to BOUNCER_MAX_PAYLOADS_MEGABYTES
BOUNCER_MAX_PAYLOADS_MEGABYTESnumbersSize of max payload to allow, in megabytes. Requires BOUNCER_ALLOW_LARGE_PAYLOADS to be enabled

⁠Security considerations

If you're putting this behind access control to the docker socket, it will need access to the /swarm /services and /containers endpoints of the docker api.

Tag summary

Content type

Image

Digest

sha256:26d551979…

Size

151.3 MB

Last updated

over 2 years ago

docker pull benzine/bouncer