Toilal
The companion containers ddb relies on have not been refreshed in years, while both the upstream projects and the configuration formats ddb generates for them have moved on. ## Scope ### cfssl - `gficentreouest/alpine-cfssl` is pulled untagged (`latest`) by `docker-compose.yml` at the root of this repository, which backs the certs and traefik integration tests. The image is published under the pre-Inetum org name and is not rebuilt anymore. - Decide between rebuilding/republishing it under a current namespace with a pinned tag, or moving to another PKI. Upstream #245 already proposes mkcert as an alternative to cfssl for certificate generation — the two should be arbitrated together. - Pin an explicit tag once settled: an untagged `latest` makes the test suite silently depend on whatever is cached locally. ### traefik - `ddb/feature/traefik/schema.py` ships the dynamic configuration templates ddb writes for each virtual host (`[http.routers]`, `[http.middlewares]`, `[http.services]`). They target traefik v2; traefik v3 changed the router rule syntax (`PathPrefix` matchers, regexp syntax, `HostRegexp`) and several middleware options. - Check the generated files against traefik v3, and decide whether to support both or require v3. ### portainer - Bump to a current release and check the compose definition still matches (portainer CE 2.x changed its volumes and the admin bootstrap flow). ## Where the work happens The containers themselves live in [inetum-orleans/docker-devbox](https://github.com/inetum-orleans/docker-devbox); this ticket tracks the ddb side: the cfssl image used by the tests, and the traefik configuration templates ddb generates. ## Related - inetum-orleans/docker-devbox-ddb#245 use mkcert as an alternative to cfssl - inetum-orleans/docker-devbox-ddb#235 explore coredns as a replacement for acrylic