{"id":25521907,"url":"https://github.com/mu373/traefik","last_synced_at":"2026-05-07T07:40:38.772Z","repository":{"id":189312343,"uuid":"680450070","full_name":"mu373/traefik","owner":"mu373","description":"Basic traefik setup. Easily enable HTTPS access to services running in separate Docker containers.","archived":false,"fork":false,"pushed_at":"2023-08-19T09:57:14.000Z","size":7,"stargazers_count":0,"open_issues_count":0,"forks_count":0,"subscribers_count":1,"default_branch":"main","last_synced_at":"2023-08-19T10:48:28.288Z","etag":null,"topics":["cloudflare","dns","https","letsencrypt","reverse-proxy","tailscale","traefik"],"latest_commit_sha":null,"homepage":"","language":null,"has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/mu373.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null}},"created_at":"2023-08-19T09:25:47.000Z","updated_at":"2023-08-19T10:48:35.749Z","dependencies_parsed_at":"2023-08-19T10:58:49.251Z","dependency_job_id":null,"html_url":"https://github.com/mu373/traefik","commit_stats":null,"previous_names":["mu373/traefik"],"tags_count":null,"template":null,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/mu373%2Ftraefik","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/mu373%2Ftraefik/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/mu373%2Ftraefik/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/mu373%2Ftraefik/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/mu373","download_url":"https://codeload.github.com/mu373/traefik/tar.gz/refs/heads/main","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":239708985,"owners_count":19684168,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["cloudflare","dns","https","letsencrypt","reverse-proxy","tailscale","traefik"],"created_at":"2025-02-19T18:17:35.173Z","updated_at":"2026-05-07T07:40:38.724Z","avatar_url":"https://github.com/mu373.png","language":null,"funding_links":[],"categories":[],"sub_categories":[],"readme":"# traefik\n\nBasic [traefik](https://doc.traefik.io/traefik/master/) setup. Easily enable HTTPS access to services running in separate Docker containers.\n- Automatically create SSL certificates using Let's Encrypt with DNS-challenge ([link](https://doc.traefik.io/traefik/master/https/acme/)). Cloudflare is used as the default provider in this repo.\n- Works well with Tailscale.\n\n## Setup\nPreparing configs\n```sh\ncp .env.sample .env\ncp traefik.sample.yml traefik.yml\ncp dynamic.sample.yml dynamic.yml\nvim .env\nvim traefik.yml #Edit email address for Cloudflare account\nvim dynamic.yml #Configure dynamic routes (optional)\n```\n\nPreparing Docker network\n```sh\n# We will use network called \"traefik-nw\" for traefik and other containers to communicate with each other\ndocker network create traefik-nw \n```\n\n## DNS\n- Create Cloudflare API token from the [dashboard](https://dash.cloudflare.com/profile/api-tokens).\n    - The token should have a permission to edit the DNS\n    - Override the value for `CLOUDFLARE_DNS_API_TOKEN` in the `.env` file\n- Add `A` record for your node\n    - e.g. `server001.example.com  A  100.0.0.1`\n    - You can even use Tailscale IP address here. The contents will only be available when you are connected to Tailscale.\n    - Traefik dashboard will be available at this FQDN.\n- Add `CNAME` record(s) for your target service(s)\n    - e.g. `your-service-1.example.com  CNAME  server001.example.com`\n\n## Docker containers\nHere is a sample `docker-compose.yml` configuration for the target container that you would like to connect through reverse proxy. In this example, 8080 port of the container will be available at `your-service-1.example.com`.\n\n```yml\nservices:\n  \u003cyour_service\u003e:\n    ...\n    expose:\n      - 8080 #The target port should be exposed\n    networks:\n      - traefik-nw #The target container should be in same network with the traefik\n    labels:\n      traefik.enable: true\n      traefik.docker.network: traefik-nw\n      traefik.http.routers.foobar.rule: Host(`your-service-1.example.com`) # your_service:8080 will be available at your-service-1.example.com\n      traefik.http.routers.foobar.service: foobar\n      traefik.http.routers.foobar.entrypoints: websecure\n      traefik.http.routers.foobar.tls.certresolver: cloudflare\n      traefik.http.services.foobar.loadbalancer.server.port: 8080\nnetworks:\n  traefik-nw:\n    external: true\n```\n\n## Dynamic Configuration (Host Services)\nIf you need to expose services running on the host machine (outside Docker containers), you can use the `dynamic.yml` file. This is useful for reverse proxying to services that aren't containerized.\n\nExample configuration in `dynamic.yml`:\n```yml\nhttp:\n  routers:\n    my-app:\n      rule: \"Host(`foobar.example.com`)\"\n      service: my-app-service\n      entryPoints:\n        - websecure\n      tls:\n        certResolver: cloudflare\n\n  services:\n    my-app-service:\n      loadBalancer:\n        servers:\n          - url: \"http://host.docker.internal:8031\"\n```\n\nIn this example, requests to `foobar.example.com` will be routed to a service running on the host machine at port 8031. The special DNS name `host.docker.internal` resolves to the host machine from within Docker containers.\n\n**Note:** Make sure to add the appropriate DNS records in Cloudflare for any domains configured in `dynamic.yml`.\n```","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fmu373%2Ftraefik","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fmu373%2Ftraefik","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fmu373%2Ftraefik/lists"}