furtka-gateway/traefik/dynamic/default-cert.yml.example
Robert Syrnicki 3a9d18fcd5 Scaffold gateway stack and single-tenant control plane
wg-easy + Traefik docker-compose stack (Phase 1) plus a stdlib-only
control-plane API for box registration, WireGuard peer provisioning via
wg-easy, and per-box route publish/unpublish backed by Traefik's file
provider (Phase 2, single-tenant mode). SQLite holds accounts/boxes/routes
so a later multi-tenant shared instance is the same schema with more rows,
not a reshape.

wg-easy's actual REST API was verified against its source rather than
assumed: it has no bearer-token auth (session-cookie login via
POST /api/auth/password) and no way to accept an externally-generated
public key (it always mints the keypair itself, private key included) —
both corrected from the original plan during implementation.
2026-08-24 11:50:25 +02:00

12 lines
409 B
Text

# GATEWAY_MODE=shared only. Copy to traefik/dynamic/default-cert.yml with
# GATEWAY_BASE_DOMAIN substituted (ops/deploy.sh does this) to request the
# one wildcard cert used as the default for every published subdomain.
tls:
stores:
default:
defaultGeneratedCert:
resolver: le-dns
domain:
main: "GATEWAY_BASE_DOMAIN"
sans:
- "*.GATEWAY_BASE_DOMAIN"