159 lines
5.2 KiB
YAML
159 lines
5.2 KiB
YAML
---
|
|
sunet_frontend:
|
|
|
|
load_balancer:
|
|
api_imagetag: 'stable'
|
|
exabgp_imagetag: 'stable'
|
|
port80_acme_c_backend: 'letsencrypt_acme-c.sunet.se'
|
|
static_backends:
|
|
letsencrypt_acme-c.sunet.se.se:
|
|
- '89.45.232.90' # note: port 80
|
|
|
|
peers:
|
|
loke.sunet.se:
|
|
as: '65434'
|
|
remote_ip: '130.242.124.130'
|
|
loke.sunet.se_v6:
|
|
as: '65434'
|
|
remote_ip: '2001:6b0:7:127::2'
|
|
se-tug-rs-1.sunet.se:
|
|
as: '65434'
|
|
remote_ip: '130.242.125.111'
|
|
se-tug-rs-1.sunet.se_v6:
|
|
as: '65434'
|
|
remote_ip: '2001:6b0:8:4::111'
|
|
|
|
|
|
websites2:
|
|
|
|
'connector':
|
|
site_name: 'connector.eidas.swedenconnect.se'
|
|
frontends:
|
|
'fe-fre-3.komreg.net':
|
|
ips: ['94.176.226.10', '2001:6b0:65:1::10']
|
|
'fe-tug-3.komreg.net':
|
|
ips: ['94.176.226.11', '2001:6b0:65:1::11']
|
|
backends:
|
|
default:
|
|
'eidas-connector-1.sveidas.se':
|
|
ips: ['94.176.224.133']
|
|
server_args: 'ssl check verify none cookie ec1'
|
|
'eidas-connector-2.sveidas.se':
|
|
ips: ['94.176.224.5']
|
|
server_args: 'ssl check verify none cookie ec2'
|
|
'eidas-connector-3.sveidas.se':
|
|
ips: ['94.176.224.134']
|
|
server_args: 'ssl check verify none cookie ec3'
|
|
'eidas-connector-4.sveidas.se':
|
|
ips: ['94.176.224.6']
|
|
server_args: 'ssl check verify none cookie ec4'
|
|
allow_ports:
|
|
- 443
|
|
letsencrypt_server: 'acme-c.sunet.se'
|
|
haproxy_imagetag: 'stable'
|
|
|
|
'mdeidas':
|
|
site_name: 'md.eidas.swedenconnect.se'
|
|
frontends:
|
|
'fe-fre-3.komreg.net':
|
|
ips: ['94.176.226.12', '2001:6b0:65:1::12']
|
|
'fe-tug-3.komreg.net':
|
|
ips: ['94.176.226.13', '2001:6b0:65:1::13']
|
|
backends:
|
|
default:
|
|
'eupub-1.komreg.net':
|
|
ips: ['94.176.224.200']
|
|
server_args: 'ssl check verify none'
|
|
'eupub-2.komreg.net':
|
|
ips: ['94.176.224.72']
|
|
server_args: 'ssl check verify none'
|
|
allow_ports:
|
|
- 443
|
|
letsencrypt_server: 'acme-c.sunet.se'
|
|
haproxy_imagetag: 'stable'
|
|
|
|
'test':
|
|
site_name: 'test.swedenconnect.se'
|
|
frontends:
|
|
'fe-fre-3.komreg.net':
|
|
ips: ['94.176.226.16', '2001:6b0:65:1::16']
|
|
'fe-tug-3.komreg.net':
|
|
ips: ['94.176.226.17', '2001:6b0:65:1::17']
|
|
backends:
|
|
default:
|
|
'eidas-test-1.sveidas.se':
|
|
ips: ['94.176.224.139']
|
|
server_args: 'ssl check verify none cookie t1'
|
|
'eidas-test-2.sveidas.se':
|
|
ips: ['94.176.224.11']
|
|
server_args: 'ssl check verify none cookie t2'
|
|
allow_ports:
|
|
- 443
|
|
letsencrypt_server: 'acme-c.sunet.se'
|
|
haproxy_imagetag: 'stable'
|
|
|
|
'proxy':
|
|
site_name: 'proxy.eidas.swedenconnect.se'
|
|
frontends:
|
|
'fe-fre-3.komreg.net':
|
|
ips: ['94.176.226.18', '2001:6b0:65:1::18']
|
|
'fe-tug-3.komreg.net':
|
|
ips: ['94.176.226.19', '2001:6b0:65:1::19']
|
|
backends:
|
|
default:
|
|
'eidas-proxy-1.sveidas.se':
|
|
ips: ['94.176.224.140']
|
|
server_args: 'ssl check verify none cookie p1'
|
|
'eidas-proxy-2.sveidas.se':
|
|
ips: ['94.176.224.12']
|
|
server_args: 'ssl check verify none cookie p2'
|
|
'eidas-proxy-3.sveidas.se':
|
|
ips: ['94.176.224.141']
|
|
server_args: 'ssl check verify none cookie p3'
|
|
'eidas-proxy-4.sveidas.se':
|
|
ips: ['94.176.224.13']
|
|
server_args: 'ssl check verify none cookie p4'
|
|
allow_ports:
|
|
- 443
|
|
letsencrypt_server: 'acme-c.sunet.se'
|
|
haproxy_imagetag: 'stable'
|
|
|
|
'md':
|
|
site_name: 'md.swedenconnect.se'
|
|
frontends:
|
|
'fe-fre-3.komreg.net':
|
|
ips: ['94.176.226.14', '2001:6b0:65:1::14']
|
|
'fe-tug-3.komreg.net':
|
|
ips: ['94.176.226.15', '2001:6b0:65:1::15']
|
|
backends:
|
|
default:
|
|
'natpub-1.komreg.net':
|
|
ips: ['94.176.224.199']
|
|
server_args: 'ssl check verify none'
|
|
'natpub-2.komreg.net':
|
|
ips: ['94.176.224.71']
|
|
server_args: 'ssl check verify none'
|
|
allow_ports:
|
|
- 443
|
|
letsencrypt_server: 'acme-c.sunet.se'
|
|
haproxy_imagetag: 'stable'
|
|
|
|
'demweidas':
|
|
site_name: 'demw.eidas.swedenconnect.se'
|
|
frontends:
|
|
'fe-fre-3.komreg.net':
|
|
ips: ['94.176.226.14', '2001:6b0:65:1::14']
|
|
'fe-tug-3.komreg.net':
|
|
ips: ['94.176.226.15', '2001:6b0:65:1::15']
|
|
backends:
|
|
default:
|
|
'demw-1.komreg.net':
|
|
ips: ['94.176.224.252']
|
|
server_args: 'ssl check verify none'
|
|
'demw-2.komreg.net':
|
|
ips: ['94.176.224.253']
|
|
server_args: 'ssl check verify none'
|
|
allow_ports:
|
|
- 443
|
|
tls_certificate_bundle: /etc/ssl/certs/demw_eidas_swedenconnect_se.pem
|
|
haproxy_imagetag: 'stable'
|