Repository navigation
Ferrum Foundry v0.1.0
Ferrum Foundry v0.1.0
Docker
docker pull ferrumedge/ferrum-foundry:v0.1.0
docker pull ghcr.io/ferrum-edge/ferrum-foundry:v0.1.0Production quick start
Run Foundry only behind an identity-aware reverse proxy that removes
client-supplied identity headers and injects the trusted proxy proof:
export FERRUM_JWT_SECRET=$(openssl rand -hex 32)
export FERRUM_TRUSTED_PROXY_SECRET=$(openssl rand -hex 32)
docker run \
-e FERRUM_ADMIN_URL=https://your-gateway:9443 \
-e FERRUM_JWT_SECRET \
-e FERRUM_AUTH_MODE=trusted-proxy \
-e FERRUM_TRUSTED_PROXY_SECRET \
-p 127.0.0.1:8080:8080 \
ferrumedge/ferrum-foundry:v0.1.0Configure the proxy to send X-Ferrum-Auth-Secret,
X-Forwarded-User, X-Ferrum-Role, and exact
X-Ferrum-Namespaces grants. See
Production authentication.