Docker Swarm Ingress service based on OpenResty with automatic Let's Encrypt SSL provisioning
787
Swarm Ingress OpenResty is a ingress service for Docker in Swarm mode that makes deploying microservices easy. It configures itself automatically and dynamically using services labels.
openresty/openresty:jammyThis OpenResty plugin automatically and transparently issues SSL certificates from Let's Encrypt as requests are received using lua-resty-auto-ssl plugin. It works like:
The Ingress service acts as a reverse proxy in your cluster. It exposes port 80 and 443 to the public an redirects all requests to the correct service in background. It is important that the ingress service can reach other services via the Swarm network (that means they must share a network).
Create network:
docker network create --driver overlay ingress-routing
Deploy swarm stack:
docker stack deploy -c examples/ingress-stack.yml ingress
The ingress service should be scaled to multiple nodes to prevent short outages when the node with the ingress servic becomes unresponsive. By default configured 2 replicas
A service can easily be configured using ingress. You must simply provide a label
ingress.host which determines the hostname under wich the service should be
publicly available.
Additionally to the hostname you can also map another port and path of your service.
By default a request would be redirected to http://service-name:80/.
| Label | Required | Default | Description |
|---|---|---|---|
ingress.host | yes | - | When configured ingress is enabled. The hostname which should be mapped to the service. Multiple domain supported using ingress.host0 .. ingress.hostN |
ingress.port | no | 80 | The port which serves the service in the cluster. |
ingress.path | no | / | A optional path which is prefixed when routing requests to the service. |
ingress.ssl | no | - | Enable SSL provisioning for host |
ingress.ssl_redirect | no | - | Enable automatic redirect from HTTP to HTTPS |
ingress.max_body_size | no | 10m | Max request body size |
ingress.proxy_timeout | no | 600 | Proxy timeout |
It is important to run the service which should be used for ingress that it shares a network.
To start a service with ingress simply pass the required labels on creation.
docker service create --name my-service \
--network ingress-routing \
--label ingress.host=my-service.company.tld \
--label ingress.ssl=yes \
--label ingress.ssl_redirect=yes \
nginx
It is also possible to later add a service to ingress using service update.
docker service update \
--label-add ingress.host=my-service.company.tld \
--label-add ingress.port=8080 \
my-service
We'd love for you to contribute to this container. You can request new features by creating an issue, or submit a pull request with your contribution.
If you encountered a problem running this container, you can file an issue. For us to provide better support, be sure to include the following information in your issue:
Content type
Image
Digest
sha256:c9cdd9d00…
Size
232.7 MB
Last updated
about 3 years ago
docker pull opcycle/swarm-ingress