Skip to content

proxy

This page is generated from the same Go declarations the loader enforces, so it cannot drift from what ob validate accepts.

config · dnsChallenge · entrypoints · image · kind · managed · network · port · provider · resolvers

FieldTypeDefaultWhat it does
configstring—Repository-relative proxy configuration directory. Dynamic YAML or TOML files extend Onebox’s managed configuration. A managed DNS challenge may use a directory containing only .env for provider credentials. Including traefik.yml or traefik.yaml instead takes ownership of the static configuration, which must use the watched file-provider directory /etc/traefik/dynamic, must not enable the Docker provider, must define certificatesResolvers.letsencrypt for exact terminating routes, and must define the DNS-01 certificatesResolvers.onebox-wildcard for wildcard terminating routes. Dynamic files may not reuse Onebox-generated router or service names or redefine the managed onebox-compress middleware. Expects a path inside the repository, with no control character or shell metacharacter.
dnsChallengeobject—Managed ACME DNS-01 challenge used to issue wildcard certificates. Provider credentials belong in proxy.config/.env; Onebox continues to own the static proxy configuration.
dnsChallenge.provider *string—Traefik DNS challenge provider name. Its credential variables must be supplied through proxy.config/.env. Expects a lower-case Traefik DNS provider name such as cloudflare or route53.
dnsChallenge.resolverslist—DNS resolvers used to verify challenge propagation, written as host:port.
entrypointsmap—Additional named TCP listeners published by the managed proxy. Onebox adds them to its generated static configuration; a proxy.config containing custom traefik.yml or traefik.yaml must define matching Traefik entrypoints.
entrypoints.<name>.portinteger—Host and proxy-container TCP port used by this listener.
imagestring—Container image used for the managed proxy. Expects a registry reference such as nginx:1.27 or ghcr.io/acme/app@sha256:….
kindTraefikDocker · NoneTraefikDockerProxy implementation, or none to disable routing.
managedboolean—Let Onebox converge the host-scoped proxy when routes are declared.
networkstringonebox-ingressExternal container network shared with routed workloads; default and Onebox’s derived application and service network names are reserved.

* marks a field that is required within its own object.