Enhance API with OIDC support, including login and callback endpoints. Update environment variables for OIDC configuration in .env.example. Add new features to the catalog service for listing software families, Minecraft versions, and deployment regions. Implement server management actions such as kill, delete, and update in the servers module. Integrate feature flags for maintenance mode in server operations. Update pnpm-lock.yaml with new dependencies and versions.
Some checks failed
CI / Node — lint, typecheck, test, build (push) Failing after 12s
CI / Go — node-agent tests (push) Failing after 9s
CI / Go — edge-gateway build (push) Successful in 17s

This commit is contained in:
TheOnlyMace
2026-07-05 18:39:53 +02:00
parent bf36cb3159
commit 50cd4b3ffd
225 changed files with 17824 additions and 436 deletions

View File

@@ -0,0 +1,95 @@
# HexaHost GameCloud — Traefik dynamic configuration
# Shared middleware and optional file-based routers for the control plane stack.
# Primary routing is defined via Docker labels in deploy/compose/compose.prod.yml.
http:
middlewares:
gamecloud-redirect-https:
redirectScheme:
scheme: https
permanent: true
gamecloud-api-headers:
headers:
stsSeconds: 31536000
stsIncludeSubdomains: true
stsPreload: true
contentTypeNosniff: true
frameDeny: true
referrerPolicy: strict-origin-when-cross-origin
customRequestHeaders:
X-Forwarded-Proto: https
gamecloud-web-headers:
headers:
stsSeconds: 31536000
stsIncludeSubdomains: true
contentTypeNosniff: true
frameDeny: true
referrerPolicy: strict-origin-when-cross-origin
customRequestHeaders:
X-Forwarded-Proto: https
gamecloud-rate-limit:
rateLimit:
average: 100
burst: 200
period: 1s
routers:
# File-provider routers — useful when Traefik runs outside the compose project
# or when you prefer centralised routing. Disable duplicate Docker labels if you
# rely exclusively on these definitions.
gamecloud-api:
rule: Host(`api.example.net`)
entryPoints:
- websecure
service: gamecloud-api
middlewares:
- gamecloud-api-headers
- gamecloud-rate-limit
tls:
certResolver: letsencrypt
gamecloud-web:
rule: Host(`panel.example.net`)
entryPoints:
- websecure
service: gamecloud-web
middlewares:
- gamecloud-web-headers
tls:
certResolver: letsencrypt
services:
gamecloud-api:
loadBalancer:
servers:
- url: http://api:3001
passHostHeader: true
healthCheck:
path: /api/v1/health/live
interval: 15s
timeout: 5s
gamecloud-web:
loadBalancer:
servers:
- url: http://web:3000
passHostHeader: true
healthCheck:
path: /de
interval: 15s
timeout: 5s
tls:
options:
default:
minVersion: VersionTLS12
cipherSuites:
- TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256
- TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256
- TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384
- TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
- TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305
- TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305

View File

@@ -0,0 +1,59 @@
# HexaHost GameCloud — Traefik static configuration
# Mount this file read-only when running the Traefik container on the control plane host.
global:
checkNewVersion: false
sendAnonymousUsage: false
api:
dashboard: true
insecure: false
log:
level: INFO
format: json
accessLog:
format: json
filters:
statusCodes:
- "400-599"
entryPoints:
web:
address: ":80"
http:
redirections:
entryPoint:
to: websecure
scheme: https
permanent: true
websecure:
address: ":443"
http:
tls:
certResolver: letsencrypt
domains:
- main: "${WEB_HOST:-panel.example.net}"
- main: "${API_HOST:-api.example.net}"
providers:
docker:
endpoint: unix:///var/run/docker.sock
exposedByDefault: false
network: traefik-network
watch: true
file:
directory: /etc/traefik/dynamic
watch: true
certificatesResolvers:
letsencrypt:
acme:
email: "${ACME_EMAIL:-ops@example.net}"
storage: /letsencrypt/acme.json
httpChallenge:
entryPoint: web
serversTransport:
insecureSkipVerify: false