job "traefik-ingress" { datacenters = ["hetzner"] type = "service" group "traefik-ingress" { network { mode = "host" port "http" { static = 80 host_network = "public" } port "https" { static = 443 host_network = "public" } port "admin" { static = 9080 host_network = "private" } } vault{ policies=["access-tables"] } task "traefik-ingress" { driver = "docker" service { name = "traefik" tags = ["traefik"] port = "https" } service { name = "traefik-admin" port = "admin" tags = [ "traefik.enable=true", "traefik.http.routers.${NOMAD_JOB_NAME}_insecure.rule=Host(`${NOMAD_JOB_NAME}.ducamps.win`)", "traefik.http.routers.${NOMAD_JOB_NAME}.tls.domains[0].sans=${NOMAD_JOB_NAME}.ducamps.win", ] } config { image = "traefik" ports = [ "http", "https", "admin" ] volumes =[ "local/traefik.toml:/etc/traefik/traefik.toml", "/mnt/diskstation/nomad/traefik/acme.json:/acme.json" ] } # vault{ #} env { } template{ data=<