Post

Traefik

Traefik

Traefik

The cluster’s ingress controller — every hostname on *.prod-k3s.homelab.example terminates here before being routed to a Service. Deployed via the official Helm chart into the traefik namespace.

Stack

ItemValue
Imagedocker.io/traefik:v3.7.13
Namespacetraefik
Replicas3
Service typeLoadBalancer, static IP 192.0.2.30 (from the MetalLB pool)
Ports80 → redirects to websecure; 443 (HTTP/1.1+2); 4443/UDP (HTTP/3)
Ingress providerskubernetesCRD (IngressRoute, cross-namespace allowed) + kubernetesIngress

Entry points

  • web (:80) — everything is redirected to websecure (priority 10).
  • websecure (:443) — TLS terminates here; HTTP/3 is enabled and advertised on UDP 4443.
  • Both entry points trust X-Forwarded-For from 10.42.0.0/16 (the k3s pod CIDR), so headers forwarded by in-cluster proxies like cloudflared are honored.

TLS defaults to the shared local-example-com-tls wildcard certificate via a TLSStore.

External (non-Kubernetes) routes

Traefik also proxies to services that aren’t in the cluster at all, via the providers.file provider pointed at /external-routes. A ConfigMap (external-routes-config) holds the static route/service definitions; an initContainer (sync-external-routes, busybox:1.36) copies it onto a Longhorn-backed PVC (external-routes, 100Mi RWX) at pod start, since the file provider needs a real file, not a mounted ConfigMap directly, to pick up providers.file.watch: true reloads cleanly:

RouteTarget
epyc.prod-k3s.homelab.exampleProxmox VE UI (192.0.2.194:8006)
pbs.prod-k3s.homelab.exampleProxmox Backup Server (198.51.100.109:8007)
cockpit.prod-k3s.homelab.exampleCockpit (192.0.2.194:9090)
truenas.prod-k3s.homelab.exampleTrueNAS (192.0.2.166)

All four use the default-headers + https-redirectscheme middleware chain. The file also defines (currently unused by the routers above, but available) a secured middleware chain — default-whitelist (RFC1918 source ranges) → default-headers → middlewares-authentik (forward-auth to an Authentik outpost) — for routes that need auth in front of them.

Dashboard

Traefik’s own API/dashboard (api@internal) is exposed as an IngressRoute at traefik.prod-k3s.homelab.example, gated by a basicAuth Middleware (traefik-dashboard-basicauth, credentials in Secret/traefik-dashboard-auth). The chart’s built-in ingressRoute.dashboard is disabled in favor of this explicit one.

Notable Helm values

1
2
3
4
5
6
7
8
9
10
additionalArguments:
  - "--serversTransport.insecureSkipVerify=true"
  - "--providers.file.directory=/external-routes"
  - "--providers.file.watch=true"

deployment:
  replicas: 3
  initContainers:
    - name: sync-external-routes
      image: busybox:1.36

insecureSkipVerify is set because several external backends (Proxmox, Cockpit, TrueNAS) present self-signed or internal-CA certificates.

Deploy

1
2
helm upgrade --install traefik traefik/traefik -n traefik -f values.yaml
kubectl apply -f dashboard/ -f external-routes/ -f default-headers.yaml -f tlsstore.yaml
This post is licensed under CC BY 4.0 by the author.