Files
homelab/traefik/README.md
T

34 lines
1.5 KiB
Markdown

# Traefik
Ingress for HTTP, gRPC, TCP, and UDP services, with public and internal TLS.
Kubernetes uses the Helm settings in `k8s/traefik-values.yaml`. The deploy
library applies supporting resources in this directory but does not install or
upgrade the Traefik chart. Bootstrap the chart and CRDs separately.
The LoadBalancer address is set to `192.168.80.2`. Change it for another network.
Entrypoints include web traffic, Gitea SSH, NetBird STUN, and other lab protocols.
Public certificates come from cert-manager; internal certificates use the lab CA.
The file provider reads `traefik-dynamic` through an additional volume and flags.
## API access
The committed chart values enable `api.insecure` and expose TCP 8080 through the
LoadBalancer for Homarr integration. That listener has no Traefik authentication.
Its reachability depends on external network controls. Review those controls
before deploying these values outside the trusted network.
The normal dashboard IngressRoute is a separate path; protecting that route does
not protect the direct port 8080 listener.
## Compose alternative
Compose mounts static and dynamic config, certificates, ACME state, and the
Docker socket. It needs the external `proxy` network. Local file-server routing
and TLS files have `.example` templates; copy only the ones needed for the host.
Keep ACME state and private keys with backups. Changing ingress values can affect
every service at once, so inspect routes and entrypoints after an upgrade.
See the [repository README](../README.md) for deployment selection.