traefik: second, env-named network so non-RPC services can be routed off chains #80

Merged
claude merged 1 commits from traefik-extra-network into main 2026-09-13 13:23:45 +00:00
2 changed files with 8 additions and 0 deletions

View File

@@ -1,4 +1,11 @@
networks:
# Second network Traefik also listens on, so a service can be routed WITHOUT
# sitting on `chains` next to the RPC nodes, Redis and the Traefik API (a
# public-facing site next to unauthenticated :8545 endpoints is a foothold we
# do not want to hand out). Overridable per host via TRAEFIK_EXTRA_NETWORK;
# the default is an empty bridge, so hosts that do not use it are unaffected.
extra:
name: ${TRAEFIK_EXTRA_NETWORK:-rpc_extra}
chains:
driver: bridge
ipam:

View File

@@ -38,6 +38,7 @@ services:
- "/var/run/docker.sock:/var/run/docker.sock:ro"
networks:
- chains
- extra
labels:
- "traefik.enable=true"
- "traefik.http.middlewares.ipallowlist.ipallowlist.sourcerange=$WHITELIST"