Files
da-HomeNetDocumentation/PI5/Konfiguration/docker/traefik.md
T
2026-06-19 23:18:04 +02:00

6.9 KiB
Raw Blame History

Traefik Reverse Proxy

Zusammenfassung: Traefik läuft als zentraler Reverse Proxy mit Let's Encrypt TLS-Terminierung. Alle öffentlichen Dienste hängen am selben Docker-Netzwerk traefik. Die Routing-Konfiguration erfolgt per File Provider (YAML-Dateien in /conf.d/), nicht per Docker-Labels. Quellen: 🖥️ raw/Systemdaten Raspberry PI5.md, 🔌 SSH (/opt/compose/traefik/conf.d/*.yml, 18.06. 20:00) Zuletzt aktualisiert: 2026-06-18 (Update 20:00)


Container

Feld Wert
Image traefik:latest
Container-Name traefik
Restart unless-stopped
Netzwerk traefik (extern)
Ports (Host) 80:80, 443:443

Static Configuration (compose.yml command:)

command:
  - "--api.dashboard=true"
  - "--log.level=INFO"

  # File Provider (statt Docker Labels)
  - "--providers.file.directory=/conf.d"
  - "--providers.file.watch=true"
  - "--providers.file=true"

  # Entrypoints
  - "--entrypoints.web.address=:80"
  - "--entrypoints.websecure.address=:443"
  - "--entrypoints.websecure.http.tls=true"
  - "--entrypoints.web.http.sanitizePath=false"
  - "--entrypoints.websecure.http.sanitizePath=false"
  - "--entrypoints.websecure.http.encodedCharacters.allowEncodedSlash=true"
  - "--entrypoints.websecure.http.encodedCharacters.allowEncodedBackSlash=true"
  - "--entrypoints.websecure.http.encodedCharacters.allowEncodedSemicolon=true"
  - "--entrypoints.websecure.http.encodedCharacters.allowEncodedPercent=true"
  - "--entrypoints.websecure.http.encodedCharacters.allowEncodedQuestionMark=true"
  - "--entrypoints.websecure.http.encodedCharacters.allowEncodedHash=true"

  # Let's Encrypt
  - "--certificatesresolvers.le.acme.email=dial-master@gmx.de"
  - "--certificatesresolvers.le.acme.storage=/acme.json"
  - "--certificatesresolvers.le.acme.httpchallenge.entrypoint=web"

Volumes

Host-Pfad Container-Pfad Zweck
./conf.d /conf.d File-Provider-Konfigurationen (dynamische Routen)
./acme.json /acme.json Let's-Encrypt-Zertifikatspeicher
./auth/.htpasswd /.htpasswd Basis-Auth für das Dashboard
/etc/localtime /etc/localtime:ro Zeitzone

Dynamic Configuration (File Provider)

Die eigentlichen Routen-Regeln liegen als YAML-Dateien in /opt/compose/traefik/conf.d/. Alle Dateien (Stand: 17.06.2026):

Datei Zweck
0000-global.yml HTTP-Catchall-Router (fängt HTTP ab; HTTPS-Redirect auskommentiert)
0010-middlewares.yml Middleware-Chains (auth, security, rate-limit, nextcloud-dav, etc., + chain-authelia)
0015-authelia-service.yml authelia Route (ohne Auth)
0020-authelia-middleware.yml ForwardAuth-Middleware (chain-authelia + authelia-forwardauth)
0020-prometheus.yml Prometheus-Route (mit Basic-Auth)
0030-grafana.yml Grafana-Route (ohne Auth-Middleware)
0100-traefik-dashboard.yml Traefik-Dashboard (mit Basic-Auth)
0105-collabora.yml Collabora (iFrame-freundliche Header, WebSocket-Support)
0110-nextcloud.yml Nextcloud (mit chain-nextcloud-Middleware)
0120-paperless.yml Paperless
0130-immich.yml Immich
0140-wikijs.yml Wiki.js
0150-stirling.yml Stirling PDF (mit chain-authelia)
0160-plex.yml Plex
0170-nginx.yml Nginx Static Webserver
0500-jenkins.yml Jenkins (mit Jenkins-Headern)
0510-gitea.yml Gitea (ohne Middleware OIDC)

Vollständige Routing-Übersicht

Subdomain interner Dienst Middleware Auth
cloud.* http://nextcloud chain-nextcloud
photos.* http://immich_server:2283 chain-immich
paperless.* http://paperless-webserver-1:8000 chain-app-standard
wiki.* http://wikijs:3000 chain-app-standard
pdf.* http://stirling-pdf:8080 chain-authelia ForwardAuth
music.* http://plex:32400 chain-app-standard
web.* http://nginx_pi5:80 chain-app-standard
office.* http://collabora:9980 collabora-headers
jenkins.* http://jenkins:8080 chain-jenkins
git.* http://gitea:3000 🔄 OIDC (in Einrichtung)
auth.* http://authelia:9091 SSO-Portal + OIDC
traefik.* api@internal chain-secure-admin Basic-Auth (→ chain-authelia)
prometheus.* http://monitoring-prometheus:9090 chain-secure-admin Basic-Auth (→ chain-authelia)
grafana.* http://monitoring-grafana:3000

Die Domain-Platzhalter {{ env "HOSTNAME_BASE" }} werden durch da.home-webserver.de ersetzt. Nur office.da.home-webserver.de ist hardcodiert.

Middleware-Chains

Die wichtigsten Middleware-Ketten:

Chain Enthält
chain-secure-admin security-headers + auth-admin (Basic-Auth via .htpasswd)
chain-app-standard security-headers + upload-limit + rate-limit
chain-immich security-headers + rate-limit
chain-nextcloud security-headers + nextcloud-dav (CalDAV/CardDAV-Redirect) + compress + upload-limit
chain-jenkins jenkins-headers (X-Forwarded-Proto/Port) + rate-limit
chain-authelia security-headers + authelia-forwardauth (ForwardAuth)

Hinweise

  • Stirling PDF (pdf.*) ist als erster Dienst auf chain-authelia umgestellt ForwardAuth aktiv.
  • Gitea (git.*) hat keine Middleware Authentifizierung läuft per OIDC direkt zwischen Gitea und Authelia.
  • Prometheus und Traefik-Dashboard sind noch per Basic-Auth geschützt (auth-admin-Middleware mit .htpasswd-Datei). Geplant: Umstellung auf authelia.
  • Grafana hat KEIN Auth in Traefik der Schutz liegt ausschließlich bei Grafana selbst.
  • Die Collabora-Konfiguration erlaubt iFrame-Einbettung für Nextcloud-Integration.
  • Siehe authelia für die vollständige SSO-Dokumentation.

Let's Encrypt

  • E-Mail: dial-master@gmx.de
  • Challenge: HTTP (Port 80)
  • Speicher: /acme.json (gemapptes Host-Volume)
  • Resolver-Name: le

DNS

Traefik nutzt 8.8.8.8 und 1.1.1.1 als upstream DNS.

Wichtige Hinweise

  • Die encodedCharacters-Optionen sind für collabora wichtig (WebSockets, encoded Slashes).
  • Das Dashboard ist per API aktiviert, aber durch .htpasswd geschützt.
  • Der File Provider wird live überwacht (watch=true) Änderungen an YAML-Dateien werden ohne Neustart übernommen.

Verwandte Seiten