fixing config to just route within network and not expose ports of services

This commit is contained in:
talksik
2023-08-14 13:53:24 -07:00
parent b41a9cc3c9
commit 904be49ac9
2 changed files with 36 additions and 6 deletions
+3 -5
View File
@@ -25,17 +25,15 @@ services:
image: registry:2 image: registry:2
restart: unless-stopped restart: unless-stopped
container_name: registry container_name: registry
ports:
- 5001:5001 # using different port simply because nginx container needs the 5000 port
volumes: volumes:
- /mnt/registry:/var/lib/registry - /mnt/registry:/var/lib/registry
networks: networks:
- nginx - nginx
rancher: rancher:
image: rancher/rancher:latest image: rancher/rancher:latest
restart: unless-stopped restart: unless-stopped
container_name: rancher container_name: rancher
ports:
- 2000:80
- 2001:443
privileged: true privileged: true
networks:
- nginx
+33 -1
View File
@@ -12,11 +12,12 @@ http {
} }
} }
# container registry
server { server {
listen 5000; listen 5000;
location / { location / {
proxy_pass http://localhost:5001; proxy_pass http://registry:5000;
proxy_set_header Host $host; proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
@@ -24,6 +25,33 @@ http {
} }
} }
# rancher http
server {
listen 2000;
location / {
proxy_pass http://rancher:80;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
}
}
# rancher https: the destination container will handle tls
server {
listen 2001;
location / {
proxy_pass https://rancher:443;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
}
}
# kubernetes cluster hello world
server { server {
listen 80; listen 80;
@@ -38,21 +66,25 @@ http {
} }
stream { stream {
# kubernetes cluster api
server { server {
listen 3080; listen 3080;
proxy_pass localhost:33360; # TODO: change to NodePort of api within kubernetes proxy_pass localhost:33360; # TODO: change to NodePort of api within kubernetes
} }
# k8s audio relay
server { server {
listen 6000 udp; listen 6000 udp;
proxy_pass localhost:33600; # TODO: change to NodePort of udp deployment service proxy_pass localhost:33600; # TODO: change to NodePort of udp deployment service
} }
# k8s video relay
server { server {
listen 6001 udp; listen 6001 udp;
proxy_pass localhost:33600; # TODO: change to NodePort of udp deployment service proxy_pass localhost:33600; # TODO: change to NodePort of udp deployment service
} }
# k8s presence heartbeat
server { server {
listen 6002; listen 6002;
proxy_pass localhost:33600; # TODO: change to NodePort of tcp presence deployment service proxy_pass localhost:33600; # TODO: change to NodePort of tcp presence deployment service