# Dynamic configuration (file provider, hot-reloaded). Middlewares that
# several routers share; referenced from labels as `<name>@file`.
http:
  middlewares:
    # No search engine indexing for anything behind this proxy.
    robots-tag-header:
      headers:
        customResponseHeaders:
          X-Robots-Tag: "noindex, nofollow, noarchive"

    redirect-to-https:
      redirectScheme:
        scheme: https
        permanent: true

    # Single sign-on for the services that want it (not LiteLLM/Open WebUI:
    # one is API-key auth, the other has no login by design).
    authentik-forwardauth:
      forwardAuth:
        address: "https://authentik.${DOMAIN}/outpost.goauthentik.io/auth/traefik"
        trustForwardHeader: true
        authResponseHeaders:
          - X-authentik-username
          - X-authentik-groups
          - X-authentik-email
          - X-authentik-name
          - X-authentik-uid

    # Occasionally needed for backends that expect these on the request.
    protocol-header:
      headers:
        customRequestHeaders:
          X-Forwarded-Proto: "https"
    upgrade-header:
      headers:
        customRequestHeaders:
          Connection: Upgrade
          Upgrade: websocket

    # Dashboard login against FreeIPA over LDAPS (wiltonsr/ldapAuth plugin).
    # Bind credentials, the CA and the exact search filter are left out here;
    # the plugin README documents them.
    ldap-auth:
      plugin:
        ldapAuth:
          baseDN: "cn=users,cn=accounts,dc=example,dc=lan"
          attribute: "uid"
          bindDN: "uid=traefik,cn=users,cn=accounts,dc=example,dc=lan"
          bindPassword: "<REDACTED>"
          forwardUsername: true
          forwardAuthorization: true
          forwardUsernameHeader: X-Remote-User
          serverList:
            - url: "ldaps://ipa.example.lan"
              port: 636
              certificateAuthority: |-
                -----BEGIN CERTIFICATE-----
                <your internal CA, PEM>
                -----END CERTIFICATE-----
