Install Traefik with Docker: Reverse Proxy with Automatic Routing

· 1 min read · Docker & Rancher Desktop Tutorials

What is Traefik #

Traefik is a reverse proxy that configures itself. It watches Docker (or Kubernetes) and, when a container starts with the right labels, it creates the route for it. There is no configuration file to edit and reload for each new service. It is also the ingress controller bundled with K3s and Rancher Desktop.

Traefik and two services #

compose.yaml
services:
  traefik:
    image: traefik:v3.1
    command:
      - --providers.docker=true
      - --providers.docker.exposedbydefault=false
      - --entrypoints.web.address=:80
      - --api.dashboard=true
      - --api.insecure=true
    ports:
      - "80:80"
      - "8080:8080"
    volumes:
      - /var/run/docker.sock:/var/run/docker.sock:ro

  whoami:
    image: traefik/whoami
    labels:
      - traefik.enable=true
      - traefik.http.routers.whoami.rule=Host(`whoami.localhost`)
      - traefik.http.routers.whoami.entrypoints=web

  site:
    image: nginx:stable
    labels:
      - traefik.enable=true
      - traefik.http.routers.site.rule=Host(`site.localhost`)
      - traefik.http.routers.site.entrypoints=web
      - traefik.http.services.site.loadbalancer.server.port=80
docker compose up -d
curl http://whoami.localhost
curl http://site.localhost

The .localhost names resolve to your machine in most systems, so no /etc/hosts change is needed. Traefik reads the Docker socket to find containers: exposedbydefault=false makes a container public only when it has traefik.enable=true.

The dashboard #

Open http://localhost:8080. It shows the routers (rule to service), services and middlewares that Traefik discovered. --api.insecure=true is only for local use: in production protect the dashboard with a router and an authentication middleware.

Middlewares #

A middleware changes the request before it reaches the service. Add labels to the whoami container:

    labels:
      - traefik.http.routers.whoami.middlewares=auth,strip
      - traefik.http.middlewares.auth.basicauth.users=admin:$$apr1$$H6uskkkW$$IgXLP6ewTrSuBkTrqE8wj/
      - traefik.http.middlewares.strip.stripprefix.prefixes=/api

The password is an htpasswd hash (htpasswd -nb admin secret), with each $ doubled in Compose. Other useful middlewares are redirectscheme (HTTP to HTTPS), ratelimit and headers.

HTTPS with Let's Encrypt #

Add a certificate resolver and an HTTPS entrypoint to the Traefik command:

      - --entrypoints.websecure.address=:443
      - --certificatesresolvers.le.acme.email=you@example.com
      - --certificatesresolvers.le.acme.storage=/letsencrypt/acme.json
      - --certificatesresolvers.le.acme.httpchallenge.entrypoint=web

Then mark each router:

      - traefik.http.routers.site.entrypoints=websecure
      - traefik.http.routers.site.tls.certresolver=le

Mount a volume on /letsencrypt to keep the certificates. The server must be reachable on port 80 from the internet, with a public DNS name pointing to it.

Traefik in Kubernetes #

K3s installs Traefik for you, and you configure it with Ingress or IngressRoute resources instead of labels. See Kubernetes in Rancher Desktop and Install K3s.

#Docker #Traefik #Kubernetes