diff --git a/.gitlab-ci.yml b/.gitlab-ci.yml index 78615f4..0a924e5 100644 --- a/.gitlab-ci.yml +++ b/.gitlab-ci.yml @@ -74,21 +74,21 @@ vault_wrap_deploy: refs: - main -traefik_deploy: - <<: *dedicated-runner - stage: deploy - script: - - mkdir -p /home/gitlab-runner/traefik - - docker volume create vault-wrap_traefik-ssl - - docker volume create vault-wrap_traefik-dynamic-conf - - docker run --rm -v vault-wrap_traefik-ssl:/temporary -v /etc/ssl/certs/:/files alpine cp files/runner1-prod.corp.samsonopt.ru.crt /temporary - - docker run --rm -v vault-wrap_traefik-ssl:/temporary -v /etc/ssl/private/:/files alpine cp files/runner1-prod.corp.samsonopt.ru.key /temporary - - docker run --rm -v vault-wrap_traefik-dynamic-conf:/temporary -v ./traefik-files:/files alpine cp files/certificates.yml /temporary - - cp traefik-files/traefik.yml /home/gitlab-runner/traefik/traefik.yml - - export TLS_CERT_FILE=runner1-prod.corp.samsonopt.ru.crt - - export TLS_KEY_FILE=runner1-prod.corp.samsonopt.ru.key - - if [ -e .ci_status/vault_wrap_release ]; then docker-compose -f docker-compose.yml up -d traefik; fi - only: - refs: - - main +# traefik_deploy: + # <<: *dedicated-runner + # stage: deploy + # script: + # - mkdir -p /home/gitlab-runner/traefik + # - docker volume create vault-wrap_traefik-ssl + # - docker volume create vault-wrap_traefik-dynamic-conf + # - docker run --rm -v vault-wrap_traefik-ssl:/temporary -v /etc/ssl/certs/:/files alpine cp files/runner1-prod.corp.samsonopt.ru.crt /temporary + # - docker run --rm -v vault-wrap_traefik-ssl:/temporary -v /etc/ssl/private/:/files alpine cp files/runner1-prod.corp.samsonopt.ru.key /temporary + # - docker run --rm -v vault-wrap_traefik-dynamic-conf:/temporary -v ./traefik-files:/files alpine cp files/certificates.yml /temporary + # - cp traefik-files/traefik.yml /home/gitlab-runner/traefik/traefik.yml + # - export TLS_CERT_FILE=runner1-prod.corp.samsonopt.ru.crt + # - export TLS_KEY_FILE=runner1-prod.corp.samsonopt.ru.key + # - if [ -e .ci_status/vault_wrap_release ]; then docker-compose -f docker-compose.yml up -d traefik; fi + # only: + # refs: + # - main diff --git a/docker-compose.yml b/docker-compose.yml index 05337c7..dd74c46 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -29,6 +29,7 @@ services: - "traefik.http.services.secret.loadbalancer.server.port=443" - "traefik.docker.network=reverse-proxy" - "traefik.http.routers.secret.tls=true" + - "traefik.http.services.secret.loadbalancer.server.scheme=https" networks: - default - vault-wrap