Files
homelab/traefik/README.md
T

1.5 KiB

Traefik

Ingress for HTTP, gRPC, TCP, and UDP services, with public and internal TLS.

Kubernetes uses the Helm settings in k8s/traefik-values.yaml. The deploy library applies supporting resources in this directory but does not install or upgrade the Traefik chart. Bootstrap the chart and CRDs separately.

The LoadBalancer address is set to 192.168.80.2. Change it for another network. Entrypoints include web traffic, Gitea SSH, NetBird STUN, and other lab protocols. Public certificates come from cert-manager; internal certificates use the lab CA. The file provider reads traefik-dynamic through an additional volume and flags.

API access

The committed chart values enable api.insecure and expose TCP 8080 through the LoadBalancer for Homarr integration. That listener has no Traefik authentication. Its reachability depends on external network controls. Review those controls before deploying these values outside the trusted network.

The normal dashboard IngressRoute is a separate path; protecting that route does not protect the direct port 8080 listener.

Compose alternative

Compose mounts static and dynamic config, certificates, ACME state, and the Docker socket. It needs the external proxy network. Local file-server routing and TLS files have .example templates; copy only the ones needed for the host.

Keep ACME state and private keys with backups. Changing ingress values can affect every service at once, so inspect routes and entrypoints after an upgrade.

See the repository README for deployment selection.