The previous commit enabled everything that passed the two mechanical
checks. Passing them is necessary, not sufficient: several of those apps
are singletons by role, and an instance of them would validate, clone,
start, and then not make sense.
Eight are now off by design, each saying why:
adguard a resolver is what clients point at
authelia the forward-auth provider every Traefik router points at
gluetun a network provider — apps join it by container name
headscale the control server a tailnet is defined by
libreportal_catalog LibrePortal's own catalog, internal plumbing
ollama one endpoint, and gigabytes of models per copy
trivy the updater resolves the scanner by a FIXED container
name, trivy-service, so a second copy would run and
never be the one CVE scanning uses
wireguard one stable published UDP endpoint; peers are tied to it
And one that should never have been touched: crowdsec ships no
docker-compose.yml, so the audit — which required a compose to read
service names from — skipped it, while the enabling pass only required a
config and did not. It got an unaudited true. There is nothing for
`instance create` to clone, and one decision engine watching the whole
box is the point of it. Now false, with that stated.
23 apps instanceable, 15 not: 6 that cannot be, 9 that should not be.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
110 lines
5.9 KiB
Plaintext
110 lines
5.9 KiB
Plaintext
#
|
|
# =============================================================================
|
|
# GENERAL CONFIGURATION
|
|
# =============================================================================
|
|
# APP_NAME = name of application for use in scripts
|
|
# COMPOSE_FILE = default for no app_name in docker-compose file name, app if there is
|
|
# BACKUP = if true, include this application in backup operations
|
|
# UPDATE_TYPE = auto: new image builds are applied automatically (a recovery snapshot is taken first), manual: only when you press Update
|
|
# HEALTHCHECK = if true, default docker health checks for that container will be enabled
|
|
# AUTHELIA = if true, use Authelia authentication, if false turned off.
|
|
# HEADSCALE = options : false, local, remote (see general config). e.g false or local,remote
|
|
# MONITORING = if true, export this app's metrics to Prometheus + Grafana (needs both apps installed)
|
|
#
|
|
CFG_GLUETUN_APP_NAME=gluetun
|
|
# MULTI_INSTANCE = if true, this app can run as multiple isolated instances
|
|
# (own data/DB/subdomain/backups) via `libreportal instance create`. Only set on
|
|
# apps whose compose identity (container_name, Traefik routers, backup labels)
|
|
# is instance-safe — see scripts/instance/instance_create.sh.
|
|
# Not instanced by design. A network provider, not a destination: other apps join it with network_mode "container:gluetun-service". A second copy leaves that name ambiguous.
|
|
CFG_GLUETUN_MULTI_INSTANCE=false
|
|
CFG_GLUETUN_BACKUP=true
|
|
CFG_GLUETUN_BACKUP_STRATEGY=auto
|
|
CFG_GLUETUN_UPDATE_TYPE=auto
|
|
CFG_GLUETUN_COMPOSE_FILE=default
|
|
CFG_GLUETUN_HEALTHCHECK=true
|
|
CFG_GLUETUN_AUTHELIA=false
|
|
CFG_GLUETUN_HEADSCALE=false
|
|
CFG_GLUETUN_MONITORING=false
|
|
#
|
|
# =============================================================================
|
|
# APPLICATION CONFIGURATION
|
|
# =============================================================================
|
|
# VPN_SERVICE_PROVIDER = VPN provider name (mullvad, nordvpn, protonvpn, surfshark, expressvpn, etc.)
|
|
# VPN_TYPE = wireguard or openvpn
|
|
# VPN_COUNTRIES = comma-separated country list (e.g. "Switzerland,Sweden") or empty for any
|
|
# OPENVPN_USER = OpenVPN account username (only when VPN_TYPE=openvpn)
|
|
# OPENVPN_PASSWORD = OpenVPN account password (only when VPN_TYPE=openvpn)
|
|
# WIREGUARD_PRIVATE_KEY = WireGuard private key (only when VPN_TYPE=wireguard)
|
|
# WIREGUARD_ADDRESSES = WireGuard interface address (e.g. "10.64.0.2/32")
|
|
# CONTROL_SERVER_API_KEY = API key for the gluetun HTTP control server, blank to disable auth
|
|
#
|
|
CFG_GLUETUN_VPN_SERVICE_PROVIDER=mullvad
|
|
CFG_GLUETUN_VPN_TYPE=wireguard
|
|
CFG_GLUETUN_VPN_COUNTRIES=
|
|
CFG_GLUETUN_OPENVPN_USER=
|
|
CFG_GLUETUN_OPENVPN_PASSWORD=
|
|
CFG_GLUETUN_WIREGUARD_PRIVATE_KEY=
|
|
CFG_GLUETUN_WIREGUARD_ADDRESSES=
|
|
# HEALTH_TARGETS = comma-separated host:port list pinged over HTTPS to
|
|
# confirm the VPN tunnel is healthy. Defaults are privacy-respecting
|
|
# (Mullvad — your VPN provider; EFF — privacy non-profit). Override
|
|
# with your own targets if you want to check different sites.
|
|
# HEALTH_ICMP_IPS = comma-separated IPv4 list pinged over ICMP for the
|
|
# small recurring health check. Default Quad9 (Swiss non-profit DNS,
|
|
# no logging).
|
|
#
|
|
CFG_GLUETUN_HEALTH_TARGETS="mullvad.net:443,eff.org:443"
|
|
CFG_GLUETUN_HEALTH_ICMP_IPS="9.9.9.9"
|
|
# PROVIDERS_REFRESH_HOURS = how often (hours) to re-fetch gluetun's upstream
|
|
# server list, which powers the provider/country pickers. It's a few MB and
|
|
# rarely changes, so we don't pull it on every WebUI update. Lower it for a
|
|
# fresher list, raise it on a slow/metered link, or set 0 to never auto-fetch
|
|
# (refresh on demand from the Tools tab instead). Default 24.
|
|
#
|
|
CFG_GLUETUN_PROVIDERS_REFRESH_HOURS=24
|
|
#
|
|
# =============================================================================
|
|
# METADATA
|
|
# =============================================================================
|
|
# CATEGORY = application category for grouping
|
|
# TITLE = display name for the application
|
|
# DESCRIPTION = short description of the application
|
|
# LONG_DESCRIPTION = detailed description of the application
|
|
# URL = source repository or documentation URL
|
|
# ACTIONS = available actions for this application
|
|
#
|
|
CFG_GLUETUN_CATEGORY="networking,recommended"
|
|
CFG_GLUETUN_TITLE="Gluetun"
|
|
CFG_GLUETUN_DESCRIPTION="VPN Container Router"
|
|
CFG_GLUETUN_LONG_DESCRIPTION="Run all of your containers through a VPN provider. 30+ providers over WireGuard and OpenVPN, with a built-in kill-switch and port forwarding"
|
|
CFG_GLUETUN_URL="https://github.com/qdm12/gluetun"
|
|
CFG_GLUETUN_ACTIONS="configure|install|restart|shutdown|uninstall"
|
|
#
|
|
# =============================================================================
|
|
# NETWORK CONFIGURATION
|
|
# =============================================================================
|
|
# DOMAIN = number of domain from the general config, useful when using multiple domains
|
|
# WHITELIST = if true only allow whitelisted ips on traefik, if false allow all
|
|
#
|
|
CFG_GLUETUN_DOMAIN=1
|
|
CFG_GLUETUN_WHITELIST=false
|
|
CFG_GLUETUN_NETWORK=default
|
|
#
|
|
# =============================================================================
|
|
# PORT CONFIGURATION
|
|
# =============================================================================
|
|
# PORT_ = port configuration: app|name|external:internal|access|protocol|login|traefik|webui|description
|
|
# - app: application name
|
|
# - name: service identifier (webui, api, ssh, etc.)
|
|
# - external:internal: port mapping (external can be 'random' for auto-allocation)
|
|
# - access: 'public' (internet accessible), 'private' (local network only), 'disabled' (not running)
|
|
# - protocol: 'tcp' or 'udp'
|
|
# - login: if true, this port requires basic-auth via Traefik (only meaningful when traefik=true)
|
|
# - traefik: if true, Traefik handles this port (reverse proxy)
|
|
# - webui: if true, this port serves the main web interface
|
|
# - description: human-readable description of the service
|
|
#
|
|
CFG_GLUETUN_PORT_1="gluetun-service|control|random:8000|private|tcp|false|false|false|HTTP Server|"
|
|
CFG_GLUETUN_PORT_2="gluetun-exporter|metrics|8090:8090|disabled|tcp|false|false|false|Metrics Exporter (sidecar, docker-network only)|"
|