fixing config to just route within network and not expose ports of services
This commit is contained in:
+3
-5
@@ -25,17 +25,15 @@ services:
|
|||||||
image: registry:2
|
image: registry:2
|
||||||
restart: unless-stopped
|
restart: unless-stopped
|
||||||
container_name: registry
|
container_name: registry
|
||||||
ports:
|
|
||||||
- 5001:5001 # using different port simply because nginx container needs the 5000 port
|
|
||||||
volumes:
|
volumes:
|
||||||
- /mnt/registry:/var/lib/registry
|
- /mnt/registry:/var/lib/registry
|
||||||
networks:
|
networks:
|
||||||
- nginx
|
- nginx
|
||||||
|
|
||||||
rancher:
|
rancher:
|
||||||
image: rancher/rancher:latest
|
image: rancher/rancher:latest
|
||||||
restart: unless-stopped
|
restart: unless-stopped
|
||||||
container_name: rancher
|
container_name: rancher
|
||||||
ports:
|
|
||||||
- 2000:80
|
|
||||||
- 2001:443
|
|
||||||
privileged: true
|
privileged: true
|
||||||
|
networks:
|
||||||
|
- nginx
|
||||||
|
|||||||
+33
-1
@@ -12,11 +12,12 @@ http {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
# container registry
|
||||||
server {
|
server {
|
||||||
listen 5000;
|
listen 5000;
|
||||||
|
|
||||||
location / {
|
location / {
|
||||||
proxy_pass http://localhost:5001;
|
proxy_pass http://registry:5000;
|
||||||
proxy_set_header Host $host;
|
proxy_set_header Host $host;
|
||||||
proxy_set_header X-Real-IP $remote_addr;
|
proxy_set_header X-Real-IP $remote_addr;
|
||||||
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
||||||
@@ -24,6 +25,33 @@ http {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
# rancher http
|
||||||
|
server {
|
||||||
|
listen 2000;
|
||||||
|
|
||||||
|
location / {
|
||||||
|
proxy_pass http://rancher:80;
|
||||||
|
proxy_set_header Host $host;
|
||||||
|
proxy_set_header X-Real-IP $remote_addr;
|
||||||
|
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
||||||
|
proxy_set_header X-Forwarded-Proto $scheme;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
# rancher https: the destination container will handle tls
|
||||||
|
server {
|
||||||
|
listen 2001;
|
||||||
|
|
||||||
|
location / {
|
||||||
|
proxy_pass https://rancher:443;
|
||||||
|
proxy_set_header Host $host;
|
||||||
|
proxy_set_header X-Real-IP $remote_addr;
|
||||||
|
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
||||||
|
proxy_set_header X-Forwarded-Proto $scheme;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
# kubernetes cluster hello world
|
||||||
server {
|
server {
|
||||||
listen 80;
|
listen 80;
|
||||||
|
|
||||||
@@ -38,21 +66,25 @@ http {
|
|||||||
}
|
}
|
||||||
|
|
||||||
stream {
|
stream {
|
||||||
|
# kubernetes cluster api
|
||||||
server {
|
server {
|
||||||
listen 3080;
|
listen 3080;
|
||||||
proxy_pass localhost:33360; # TODO: change to NodePort of api within kubernetes
|
proxy_pass localhost:33360; # TODO: change to NodePort of api within kubernetes
|
||||||
}
|
}
|
||||||
|
|
||||||
|
# k8s audio relay
|
||||||
server {
|
server {
|
||||||
listen 6000 udp;
|
listen 6000 udp;
|
||||||
proxy_pass localhost:33600; # TODO: change to NodePort of udp deployment service
|
proxy_pass localhost:33600; # TODO: change to NodePort of udp deployment service
|
||||||
}
|
}
|
||||||
|
|
||||||
|
# k8s video relay
|
||||||
server {
|
server {
|
||||||
listen 6001 udp;
|
listen 6001 udp;
|
||||||
proxy_pass localhost:33600; # TODO: change to NodePort of udp deployment service
|
proxy_pass localhost:33600; # TODO: change to NodePort of udp deployment service
|
||||||
}
|
}
|
||||||
|
|
||||||
|
# k8s presence heartbeat
|
||||||
server {
|
server {
|
||||||
listen 6002;
|
listen 6002;
|
||||||
proxy_pass localhost:33600; # TODO: change to NodePort of tcp presence deployment service
|
proxy_pass localhost:33600; # TODO: change to NodePort of tcp presence deployment service
|
||||||
|
|||||||
Reference in New Issue
Block a user