proxy
This page is generated from the same Go declarations the loader enforces, so it
cannot drift from what ob validate accepts.
Fields on this page
Section titled “Fields on this page”config · dnsChallenge · entrypoints · image · kind · managed · network · port · provider · resolvers
Reference
Section titled “Reference”| Field | Type | Default | What it does |
|---|---|---|---|
config | string | — | Repository-relative proxy configuration directory. Dynamic YAML or TOML files extend Onebox’s managed configuration. A managed DNS challenge may use a directory containing only .env for provider credentials. Including traefik.yml or traefik.yaml instead takes ownership of the static configuration, which must use the watched file-provider directory /etc/traefik/dynamic, must not enable the Docker provider, must define certificatesResolvers.letsencrypt for exact terminating routes, and must define the DNS-01 certificatesResolvers.onebox-wildcard for wildcard terminating routes. Dynamic files may not reuse Onebox-generated router or service names or redefine the managed onebox-compress middleware. Expects a path inside the repository, with no control character or shell metacharacter. |
dnsChallenge | object | — | Managed ACME DNS-01 challenge used to issue wildcard certificates. Provider credentials belong in proxy.config/.env; Onebox continues to own the static proxy configuration. |
dnsChallenge.provider * | string | — | Traefik DNS challenge provider name. Its credential variables must be supplied through proxy.config/.env. Expects a lower-case Traefik DNS provider name such as cloudflare or route53. |
dnsChallenge.resolvers | list | — | DNS resolvers used to verify challenge propagation, written as host:port. |
entrypoints | map | — | Additional named TCP listeners published by the managed proxy. Onebox adds them to its generated static configuration; a proxy.config containing custom traefik.yml or traefik.yaml must define matching Traefik entrypoints. |
entrypoints.<name>.port | integer | — | Host and proxy-container TCP port used by this listener. |
image | string | — | Container image used for the managed proxy. Expects a registry reference such as nginx:1.27 or ghcr.io/acme/app@sha256:…. |
kind | TraefikDocker · None | TraefikDocker | Proxy implementation, or none to disable routing. |
managed | boolean | — | Let Onebox converge the host-scoped proxy when routes are declared. |
network | string | onebox-ingress | External container network shared with routed workloads; default and Onebox’s derived application and service network names are reserved. |
* marks a field that is required within its own object.