title, description, published, date, tags, editor, dateCreated
title
description
published
date
tags
editor
dateCreated
traefik
true
2026-06-28T14:31:17.139Z
markdown
2026-06-28T14:31:15.285Z
Traefik – Reverse Proxy
Zusammenfassung : Traefik läuft als zentraler Reverse Proxy mit Let's Encrypt TLS-Terminierung. Alle öffentlichen Dienste hängen am selben Docker-Netzwerk traefik. Die Routing-Konfiguration erfolgt per File Provider (YAML-Dateien in /conf.d/), nicht per Docker-Labels.
Quellen : 🖥️ raw/Systemdaten – Raspberry PI5.md, 🔌 SSH (/opt/compose/traefik/conf.d/*.yml, 18.06. 20:00)
Zuletzt aktualisiert : 2026-06-18 (Update 20:00)
Container
Feld
Wert
Image
traefik:latest
Container-Name
traefik
Restart
unless-stopped
Netzwerk
traefik (extern)
Ports (Host)
80:80, 443:443
Static Configuration (compose.yml – command:)
Volumes
Host-Pfad
Container-Pfad
Zweck
./conf.d
/conf.d
File-Provider-Konfigurationen (dynamische Routen)
./acme.json
/acme.json
Let's-Encrypt-Zertifikatspeicher
./auth/.htpasswd
/.htpasswd
Basis-Auth für das Dashboard
/etc/localtime
/etc/localtime:ro
Zeitzone
Dynamic Configuration (File Provider)
Die eigentlichen Routen-Regeln liegen als YAML-Dateien in /opt/compose/traefik/conf.d/. Alle Dateien (Stand: 17.06.2026):
Datei
Zweck
0000-global.yml
HTTP-Catchall-Router (fängt HTTP ab; HTTPS-Redirect auskommentiert )
0010-middlewares.yml
Middleware-Chains (auth, security, rate-limit, nextcloud-dav, etc., + chain-authelia )
0015-authelia-service.yml
✅ authelia Route (ohne Auth)
0020-authelia-middleware.yml
✅ ForwardAuth-Middleware (chain-authelia + authelia-forwardauth)
0020-prometheus.yml
Prometheus-Route (mit Basic-Auth)
0030-grafana.yml
Grafana-Route (ohne Auth-Middleware)
0100-traefik-dashboard.yml
Traefik-Dashboard (mit Basic-Auth)
0105-collabora.yml
Collabora (iFrame-freundliche Header, WebSocket-Support)
0110-nextcloud.yml
Nextcloud (mit chain-nextcloud-Middleware)
0120-paperless.yml
Paperless
0130-immich.yml
Immich
0140-wikijs.yml
Wiki.js
0150-stirling.yml
✅ Stirling PDF (mit chain-authelia)
0160-plex.yml
Plex
0170-nginx.yml
Nginx Static Webserver
0500-jenkins.yml
Jenkins (mit Jenkins-Headern)
0510-gitea.yml
Gitea (ohne Middleware – OIDC)
Vollständige Routing-Übersicht
Subdomain
interner Dienst
Middleware
Auth
cloud.*
http://nextcloud
chain-nextcloud
–
photos.*
http://immich_server:2283
chain-immich
–
paperless.*
http://paperless-webserver-1:8000
chain-app-standard
–
wiki.*
http://wikijs:3000
chain-app-standard
–
pdf.*
http://stirling-pdf:8080
chain-authelia
✅ ForwardAuth
music.*
http://plex:32400
chain-app-standard
–
web.*
http://nginx_pi5:80
chain-app-standard
–
office.*
http://collabora:9980
collabora-headers
–
jenkins.*
http://jenkins:8080
chain-jenkins
–
git.*
http://gitea:3000
–
🔄 OIDC (in Einrichtung)
auth.*
http://authelia:9091
–
✅ SSO-Portal + OIDC
traefik.*
api@internal
chain-secure-admin
Basic-Auth (→ chain-authelia)
prometheus.*
http://monitoring-prometheus:9090
chain-secure-admin
Basic-Auth (→ chain-authelia)
grafana.*
http://monitoring-grafana:3000
–
–
Die Domain-Platzhalter {{ env "HOSTNAME_BASE" }} werden durch da.home-webserver.de ersetzt. Nur office.da.home-webserver.de ist hardcodiert.
Middleware-Chains
Die wichtigsten Middleware-Ketten:
Chain
Enthält
chain-secure-admin
security-headers + auth-admin (Basic-Auth via .htpasswd)
chain-app-standard
security-headers + upload-limit + rate-limit
chain-immich
security-headers + rate-limit
chain-nextcloud
security-headers + nextcloud-dav (CalDAV/CardDAV-Redirect) + compress + upload-limit
chain-jenkins
jenkins-headers (X-Forwarded-Proto/Port) + rate-limit
chain-authelia
security-headers + authelia-forwardauth (ForwardAuth)
Hinweise
Stirling PDF (pdf.*) ist als erster Dienst auf chain-authelia umgestellt – ForwardAuth aktiv.
Gitea (git.*) hat keine Middleware – Authentifizierung läuft per OIDC direkt zwischen Gitea und Authelia.
Prometheus und Traefik-Dashboard sind noch per Basic-Auth geschützt (auth-admin-Middleware mit .htpasswd-Datei). Geplant: Umstellung auf authelia .
Grafana hat KEIN Auth in Traefik – der Schutz liegt ausschließlich bei Grafana selbst.
Die Collabora-Konfiguration erlaubt iFrame-Einbettung für Nextcloud-Integration.
Siehe authelia für die vollständige SSO-Dokumentation.
Let's Encrypt
E-Mail : dial-master@gmx.de
Challenge : HTTP (Port 80)
Speicher : /acme.json (gemapptes Host-Volume)
Resolver-Name : le
DNS
Traefik nutzt 8.8.8.8 und 1.1.1.1 als upstream DNS.
Wichtige Hinweise
Die encodedCharacters-Optionen sind für collabora wichtig (WebSockets, encoded Slashes).
Das Dashboard ist per API aktiviert, aber durch .htpasswd geschützt.
Der File Provider wird live überwacht (watch=true) – Änderungen an YAML-Dateien werden ohne Neustart übernommen.
Verwandte Seiten