Files
da-HomeNetDocumentation/PI5/Konfiguration/docker/traefik.md
T
2026-06-19 23:18:04 +02:00

152 lines
6.9 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# Traefik Reverse Proxy
**Zusammenfassung**: Traefik läuft als zentraler Reverse Proxy mit Let's Encrypt TLS-Terminierung. Alle öffentlichen Dienste hängen am selben Docker-Netzwerk `traefik`. Die Routing-Konfiguration erfolgt per **File Provider** (YAML-Dateien in `/conf.d/`), nicht per Docker-Labels.
**Quellen**: 🖥️ `raw/Systemdaten Raspberry PI5.md`, 🔌 SSH (`/opt/compose/traefik/conf.d/*.yml`, 18.06. 20:00)
**Zuletzt aktualisiert**: 2026-06-18 (Update 20:00)
---
## Container
| Feld | Wert |
|---|---|
| **Image** | `traefik:latest` |
| **Container-Name** | `traefik` |
| **Restart** | `unless-stopped` |
| **Netzwerk** | `traefik` (extern) |
| **Ports (Host)** | `80:80`, `443:443` |
## Static Configuration (compose.yml `command:`)
```yaml
command:
- "--api.dashboard=true"
- "--log.level=INFO"
# File Provider (statt Docker Labels)
- "--providers.file.directory=/conf.d"
- "--providers.file.watch=true"
- "--providers.file=true"
# Entrypoints
- "--entrypoints.web.address=:80"
- "--entrypoints.websecure.address=:443"
- "--entrypoints.websecure.http.tls=true"
- "--entrypoints.web.http.sanitizePath=false"
- "--entrypoints.websecure.http.sanitizePath=false"
- "--entrypoints.websecure.http.encodedCharacters.allowEncodedSlash=true"
- "--entrypoints.websecure.http.encodedCharacters.allowEncodedBackSlash=true"
- "--entrypoints.websecure.http.encodedCharacters.allowEncodedSemicolon=true"
- "--entrypoints.websecure.http.encodedCharacters.allowEncodedPercent=true"
- "--entrypoints.websecure.http.encodedCharacters.allowEncodedQuestionMark=true"
- "--entrypoints.websecure.http.encodedCharacters.allowEncodedHash=true"
# Let's Encrypt
- "--certificatesresolvers.le.acme.email=dial-master@gmx.de"
- "--certificatesresolvers.le.acme.storage=/acme.json"
- "--certificatesresolvers.le.acme.httpchallenge.entrypoint=web"
```
## Volumes
| Host-Pfad | Container-Pfad | Zweck |
|---|---|---|
| `./conf.d` | `/conf.d` | File-Provider-Konfigurationen (dynamische Routen) |
| `./acme.json` | `/acme.json` | Let's-Encrypt-Zertifikatspeicher |
| `./auth/.htpasswd` | `/.htpasswd` | Basis-Auth für das Dashboard |
| `/etc/localtime` | `/etc/localtime:ro` | Zeitzone |
## Dynamic Configuration (File Provider)
Die eigentlichen Routen-Regeln liegen als YAML-Dateien in `/opt/compose/traefik/conf.d/`. Alle Dateien (Stand: 17.06.2026):
| Datei | Zweck |
|---|---|---|
| `0000-global.yml` | HTTP-Catchall-Router (fängt HTTP ab; HTTPS-Redirect **auskommentiert**) |
| `0010-middlewares.yml` | Middleware-Chains (auth, security, rate-limit, nextcloud-dav, etc., **+ chain-authelia**) |
| `0015-authelia-service.yml` | ✅ [authelia](./authelia.md) Route (ohne Auth) |
| `0020-authelia-middleware.yml` | ✅ ForwardAuth-Middleware (chain-authelia + authelia-forwardauth) |
| `0020-prometheus.yml` | Prometheus-Route (mit Basic-Auth) |
| `0030-grafana.yml` | Grafana-Route (ohne Auth-Middleware) |
| `0100-traefik-dashboard.yml` | Traefik-Dashboard (mit Basic-Auth) |
| `0105-collabora.yml` | Collabora (iFrame-freundliche Header, WebSocket-Support) |
| `0110-nextcloud.yml` | Nextcloud (mit chain-nextcloud-Middleware) |
| `0120-paperless.yml` | Paperless |
| `0130-immich.yml` | Immich |
| `0140-wikijs.yml` | Wiki.js |
| `0150-stirling.yml` | ✅ Stirling PDF (mit `chain-authelia`) |
| `0160-plex.yml` | Plex |
| `0170-nginx.yml` | Nginx Static Webserver |
| `0500-jenkins.yml` | Jenkins (mit Jenkins-Headern) |
| `0510-gitea.yml` | Gitea (ohne Middleware OIDC) |
### Vollständige Routing-Übersicht
| Subdomain | interner Dienst | Middleware | Auth |
|---|---|---|---|---|
| `cloud.*` | `http://nextcloud` | `chain-nextcloud` | |
| `photos.*` | `http://immich_server:2283` | `chain-immich` | |
| `paperless.*` | `http://paperless-webserver-1:8000` | `chain-app-standard` | |
| `wiki.*` | `http://wikijs:3000` | `chain-app-standard` | |
| **`pdf.*`** | **`http://stirling-pdf:8080`** | **`chain-authelia`** | **✅ ForwardAuth** |
| `music.*` | `http://plex:32400` | `chain-app-standard` | |
| `web.*` | `http://nginx_pi5:80` | `chain-app-standard` | |
| `office.*` | `http://collabora:9980` | `collabora-headers` | |
| `jenkins.*` | `http://jenkins:8080` | `chain-jenkins` | |
| `git.*` | `http://gitea:3000` | | **🔄 OIDC (in Einrichtung)** |
| `auth.*` | `http://authelia:9091` | | ✅ SSO-Portal + OIDC |
| `traefik.*` | `api@internal` | `chain-secure-admin` | **Basic-Auth** *(→ chain-authelia)* |
| `prometheus.*` | `http://monitoring-prometheus:9090` | `chain-secure-admin` | **Basic-Auth** *(→ chain-authelia)* |
| `grafana.*` | `http://monitoring-grafana:3000` | | |
Die Domain-Platzhalter `{{ env "HOSTNAME_BASE" }}` werden durch `da.home-webserver.de` ersetzt. Nur `office.da.home-webserver.de` ist hardcodiert.
### Middleware-Chains
Die wichtigsten Middleware-Ketten:
| Chain | Enthält |
|---|---|---|
| `chain-secure-admin` | `security-headers` + `auth-admin` (Basic-Auth via `.htpasswd`) |
| `chain-app-standard` | `security-headers` + `upload-limit` + `rate-limit` |
| `chain-immich` | `security-headers` + `rate-limit` |
| `chain-nextcloud` | `security-headers` + `nextcloud-dav` (CalDAV/CardDAV-Redirect) + `compress` + `upload-limit` |
| `chain-jenkins` | `jenkins-headers` (X-Forwarded-Proto/Port) + `rate-limit` |
| **`chain-authelia`** | **`security-headers` + `authelia-forwardauth`** (ForwardAuth) |
### Hinweise
- **Stirling PDF** (`pdf.*`) ist als erster Dienst auf `chain-authelia` umgestellt ForwardAuth aktiv.
- **Gitea** (`git.*`) hat **keine Middleware** Authentifizierung läuft per OIDC direkt zwischen Gitea und Authelia.
- **Prometheus** und **Traefik-Dashboard** sind noch per Basic-Auth geschützt (`auth-admin`-Middleware mit `.htpasswd`-Datei). Geplant: Umstellung auf [authelia](./authelia.md).
- **Grafana hat KEIN Auth in Traefik** der Schutz liegt ausschließlich bei Grafana selbst.
- Die Collabora-Konfiguration erlaubt **iFrame-Einbettung** für Nextcloud-Integration.
- Siehe [authelia](./authelia.md) für die vollständige SSO-Dokumentation.
## Let's Encrypt
- **E-Mail**: `dial-master@gmx.de`
- **Challenge**: HTTP (Port 80)
- **Speicher**: `/acme.json` (gemapptes Host-Volume)
- **Resolver-Name**: `le`
## DNS
Traefik nutzt `8.8.8.8` und `1.1.1.1` als upstream DNS.
## Wichtige Hinweise
- Die **encodedCharacters-Optionen** sind für [collabora](./collabora.md) wichtig (WebSockets, encoded Slashes).
- Das **Dashboard** ist per API aktiviert, aber durch `.htpasswd` geschützt.
- Der File Provider wird **live überwacht** (`watch=true`) Änderungen an YAML-Dateien werden ohne Neustart übernommen.
## Verwandte Seiten
- [docker-services](../docker-services.md) Alle Dienste, die Traefik nutzen
- [authelia](./authelia.md) SSO mit ForwardAuth und Passkey
- [nextcloud](./nextcloud.md)
- [collabora](./collabora.md)
- [gitea](./gitea.md)
- [jenkins](./jenkins.md)
- [domain-und-ssl](../domain-und-ssl.md)