# Install Traefik with Docker: Reverse Proxy with Automatic Routing

> Run Traefik v3 with Docker Compose, route several containers by hostname with labels, add the dashboard, middlewares and automatic Let's Encrypt certificates.

- Source: https://www.itwonderlab.com/install-traefik-docker/
- Published: 2026-08-30
- Updated: 2026-08-30
- Author: Javier Ruiz Jiménez (https://www.javierruizjimenez.com/)
- Site: IT Wonder Lab (https://www.itwonderlab.com/)

---

## What is Traefik

[Traefik](https://www.itwonderlab.com/traefik/) is a reverse proxy that **configures itself**. It watches Docker (or [Kubernetes](https://www.itwonderlab.com/kubernetes/)) and, when a container starts with the right labels, it creates the route for it. There is no configuration file to edit and reload for each new service. It is also the ingress controller bundled with [K3s](https://www.itwonderlab.com/k3s/) and [Rancher Desktop](https://www.itwonderlab.com/rancher-desktop/).

## Traefik and two services

```yaml title="compose.yaml"
services:
  traefik:
    image: traefik:v3.1
    command:
      - --providers.docker=true
      - --providers.docker.exposedbydefault=false
      - --entrypoints.web.address=:80
      - --api.dashboard=true
      - --api.insecure=true
    ports:
      - "80:80"
      - "8080:8080"
    volumes:
      - /var/run/docker.sock:/var/run/docker.sock:ro

  whoami:
    image: traefik/whoami
    labels:
      - traefik.enable=true
      - traefik.http.routers.whoami.rule=Host(`whoami.localhost`)
      - traefik.http.routers.whoami.entrypoints=web

  site:
    image: nginx:stable
    labels:
      - traefik.enable=true
      - traefik.http.routers.site.rule=Host(`site.localhost`)
      - traefik.http.routers.site.entrypoints=web
      - traefik.http.services.site.loadbalancer.server.port=80
```

```bash
docker compose up -d
curl http://whoami.localhost
curl http://site.localhost
```

The `.localhost` names resolve to your machine in most systems, so no `/etc/hosts` change is needed. Traefik reads the Docker socket to find containers: `exposedbydefault=false` makes a container public only when it has `traefik.enable=true`.

## The dashboard

Open `http://localhost:8080`. It shows the **routers** (rule to service), **services** and **middlewares** that Traefik discovered. `--api.insecure=true` is only for local use: in production protect the dashboard with a router and an authentication middleware.

## Middlewares

A middleware changes the request before it reaches the service. Add labels to the `whoami` container:

```yaml
    labels:
      - traefik.http.routers.whoami.middlewares=auth,strip
      - traefik.http.middlewares.auth.basicauth.users=admin:$$apr1$$H6uskkkW$$IgXLP6ewTrSuBkTrqE8wj/
      - traefik.http.middlewares.strip.stripprefix.prefixes=/api
```

The password is an `htpasswd` hash (`htpasswd -nb admin secret`), with each `$` doubled in Compose. Other useful middlewares are `redirectscheme` (HTTP to HTTPS), `ratelimit` and `headers`.

## HTTPS with Let's Encrypt

Add a certificate resolver and an HTTPS entrypoint to the Traefik command:

```yaml
      - --entrypoints.websecure.address=:443
      - --certificatesresolvers.le.acme.email=you@example.com
      - --certificatesresolvers.le.acme.storage=/letsencrypt/acme.json
      - --certificatesresolvers.le.acme.httpchallenge.entrypoint=web
```

Then mark each router:

```yaml
      - traefik.http.routers.site.entrypoints=websecure
      - traefik.http.routers.site.tls.certresolver=le
```

Mount a volume on `/letsencrypt` to keep the certificates. The server must be reachable on port 80 from the internet, with a public DNS name pointing to it.

## Traefik in Kubernetes

K3s installs Traefik for you, and you configure it with `Ingress` or `IngressRoute` resources instead of labels. See [Kubernetes in Rancher Desktop](https://www.itwonderlab.com/rancher-desktop-kubernetes/) and [Install K3s](https://www.itwonderlab.com/install-kubernetes-k3s/).
