Install Traefik with Docker: Reverse Proxy with Automatic Routing
What is Traefik #
Traefik is a reverse proxy that configures itself. It watches Docker (or Kubernetes) and, when a container starts with the right labels, it creates the route for it. There is no configuration file to edit and reload for each new service. It is also the ingress controller bundled with K3s and Rancher Desktop.
Traefik and two services #
services:
traefik:
image: traefik:v3.1
command:
- --providers.docker=true
- --providers.docker.exposedbydefault=false
- --entrypoints.web.address=:80
- --api.dashboard=true
- --api.insecure=true
ports:
- "80:80"
- "8080:8080"
volumes:
- /var/run/docker.sock:/var/run/docker.sock:ro
whoami:
image: traefik/whoami
labels:
- traefik.enable=true
- traefik.http.routers.whoami.rule=Host(`whoami.localhost`)
- traefik.http.routers.whoami.entrypoints=web
site:
image: nginx:stable
labels:
- traefik.enable=true
- traefik.http.routers.site.rule=Host(`site.localhost`)
- traefik.http.routers.site.entrypoints=web
- traefik.http.services.site.loadbalancer.server.port=80docker compose up -d
curl http://whoami.localhost
curl http://site.localhost
The .localhost names resolve to your machine in most systems, so no /etc/hosts change is needed. Traefik reads the Docker socket to find containers: exposedbydefault=false makes a container public only when it has traefik.enable=true.
The dashboard #
Open http://localhost:8080. It shows the routers (rule to service), services and middlewares that Traefik discovered. --api.insecure=true is only for local use: in production protect the dashboard with a router and an authentication middleware.
Middlewares #
A middleware changes the request before it reaches the service. Add labels to the whoami container:
labels:
- traefik.http.routers.whoami.middlewares=auth,strip
- traefik.http.middlewares.auth.basicauth.users=admin:$$apr1$$H6uskkkW$$IgXLP6ewTrSuBkTrqE8wj/
- traefik.http.middlewares.strip.stripprefix.prefixes=/api
The password is an htpasswd hash (htpasswd -nb admin secret), with each $ doubled in Compose. Other useful middlewares are redirectscheme (HTTP to HTTPS), ratelimit and headers.
HTTPS with Let's Encrypt #
Add a certificate resolver and an HTTPS entrypoint to the Traefik command:
- --entrypoints.websecure.address=:443
- --certificatesresolvers.le.acme.email=you@example.com
- --certificatesresolvers.le.acme.storage=/letsencrypt/acme.json
- --certificatesresolvers.le.acme.httpchallenge.entrypoint=web
Then mark each router:
- traefik.http.routers.site.entrypoints=websecure
- traefik.http.routers.site.tls.certresolver=le
Mount a volume on /letsencrypt to keep the certificates. The server must be reachable on port 80 from the internet, with a public DNS name pointing to it.
Traefik in Kubernetes #
K3s installs Traefik for you, and you configure it with Ingress or IngressRoute resources instead of labels. See Kubernetes in Rancher Desktop and Install K3s.