Traefik
Traefik
The cluster’s ingress controller — every hostname on *.prod-k3s.homelab.example terminates here before being routed to a Service. Deployed via the official Helm chart into the traefik namespace.
Stack
| Item | Value |
|---|---|
| Image | docker.io/traefik:v3.7.13 |
| Namespace | traefik |
| Replicas | 3 |
| Service type | LoadBalancer, static IP 192.0.2.30 (from the MetalLB pool) |
| Ports | 80 → redirects to websecure; 443 (HTTP/1.1+2); 4443/UDP (HTTP/3) |
| Ingress providers | kubernetesCRD (IngressRoute, cross-namespace allowed) + kubernetesIngress |
Entry points
web(:80) — everything is redirected towebsecure(priority 10).websecure(:443) — TLS terminates here; HTTP/3 is enabled and advertised on UDP4443.- Both entry points trust
X-Forwarded-Forfrom10.42.0.0/16(the k3s pod CIDR), so headers forwarded by in-cluster proxies likecloudflaredare honored.
TLS defaults to the shared local-example-com-tls wildcard certificate via a TLSStore.
External (non-Kubernetes) routes
Traefik also proxies to services that aren’t in the cluster at all, via the providers.file provider pointed at /external-routes. A ConfigMap (external-routes-config) holds the static route/service definitions; an initContainer (sync-external-routes, busybox:1.36) copies it onto a Longhorn-backed PVC (external-routes, 100Mi RWX) at pod start, since the file provider needs a real file, not a mounted ConfigMap directly, to pick up providers.file.watch: true reloads cleanly:
| Route | Target |
|---|---|
epyc.prod-k3s.homelab.example | Proxmox VE UI (192.0.2.194:8006) |
pbs.prod-k3s.homelab.example | Proxmox Backup Server (198.51.100.109:8007) |
cockpit.prod-k3s.homelab.example | Cockpit (192.0.2.194:9090) |
truenas.prod-k3s.homelab.example | TrueNAS (192.0.2.166) |
All four use the default-headers + https-redirectscheme middleware chain. The file also defines (currently unused by the routers above, but available) a secured middleware chain — default-whitelist (RFC1918 source ranges) → default-headers → middlewares-authentik (forward-auth to an Authentik outpost) — for routes that need auth in front of them.
Dashboard
Traefik’s own API/dashboard (api@internal) is exposed as an IngressRoute at traefik.prod-k3s.homelab.example, gated by a basicAuth Middleware (traefik-dashboard-basicauth, credentials in Secret/traefik-dashboard-auth). The chart’s built-in ingressRoute.dashboard is disabled in favor of this explicit one.
Notable Helm values
1
2
3
4
5
6
7
8
9
10
additionalArguments:
- "--serversTransport.insecureSkipVerify=true"
- "--providers.file.directory=/external-routes"
- "--providers.file.watch=true"
deployment:
replicas: 3
initContainers:
- name: sync-external-routes
image: busybox:1.36
insecureSkipVerify is set because several external backends (Proxmox, Cockpit, TrueNAS) present self-signed or internal-CA certificates.
Deploy
1
2
helm upgrade --install traefik traefik/traefik -n traefik -f values.yaml
kubectl apply -f dashboard/ -f external-routes/ -f default-headers.yaml -f tlsstore.yaml