Traefik: Dynamic Reverse Proxy for Containers
Last updated on

Traefik: Dynamic Reverse Proxy for Containers

Traefik is a reverse proxy that discovers its own configuration. Instead of maintaining a file listing every backend, it watches Docker, Kubernetes, or another provider and builds routes from labels attached to your services.

The dynamic model

Add labels to a container declaring its hostname and port, start it, and the route exists. Stop the container and the route disappears. For environments where services come and go frequently, that eliminates the edit-reload cycle that traditional proxies require, and it keeps routing configuration next to the service it belongs to rather than in a separate file.

Automatic HTTPS through Let’s Encrypt is built in, including DNS challenges for wildcard certificates.

The honest tradeoff

Traefik’s learning curve is the steepest of the common reverse proxies. Its terminology (entrypoints, routers, services, middlewares) takes time, its v1 to v2 migration invalidated most tutorials online, and debugging means reading labels scattered across many Compose files rather than one config. People who love it genuinely love it; people who wanted a proxy working in ten minutes often end up on Caddy.

Middlewares

Authentication, rate limiting, header manipulation, path rewriting, and IP allowlists attach as middlewares to routers. Combined with a forward-auth provider like Authelia or Authentik, this is how single sign-on gets placed in front of applications that have no authentication of their own.

Alternatives

Caddy gives automatic HTTPS with a much simpler config file. Nginx Proxy Manager offers a web UI for people who prefer clicking. Our reverse proxy guide compares the three in practice.

License

Traefik is released under the MIT License.