如何在Traefik中实现用户级访问控制?附Nginx迁移与K8s部署需求
Absolutely! Traefik fully supports HTTP Basic Authentication just like your old Nginx setup, and it’s easy to configure in Kubernetes—ideal for your scenario where your app doesn’t handle access control itself. Plus, you can keep using that fancy Traefik GUI you love (and even secure it with auth too, if you want!).
Here’s a step-by-step breakdown to get you set up:
1. Generate Your htpasswd File
First, create an encrypted htpasswd file just like you did with Nginx. If you don’t have the htpasswd tool installed, you can use the official Apache HTTP Server image to generate it:
# Generate a new htpasswd file with user "larry" (replace with your username) htpasswd -Bc htpasswd larry # You’ll be prompted to enter and confirm a password
This creates a file named htpasswd with your username and bcrypt-hashed password.
2. Create a Kubernetes Secret for the htpasswd File
Next, store this file as a Kubernetes Secret so Traefik can access it:
kubectl create secret generic traefik-basic-auth --from-file=htpasswd=./htpasswd
This creates a secret named traefik-basic-auth in your default namespace (adjust the namespace flag if needed).
3. Define a Traefik Middleware for Basic Auth
Traefik uses middlewares to add functionality like authentication. Create a Middleware resource that references your secret:
apiVersion: traefik.containo.us/v1alpha1 kind: Middleware metadata: name: basic-auth namespace: default # Match the namespace of your secret spec: basicAuth: secret: traefik-basic-auth
Save this as basic-auth-middleware.yaml and apply it with:
kubectl apply -f basic-auth-middleware.yaml
4. Apply the Middleware to Your Route
Now you can attach this middleware to your app’s ingress route. You have two options here:
Option A: Use Traefik’s Custom IngressRoute (Recommended)
Traefik’s IngressRoute CRD gives you more control over routing. Here’s an example that protects your app with basic auth:
apiVersion: traefik.containo.us/v1alpha1 kind: IngressRoute metadata: name: my-app-ingress namespace: default spec: entryPoints: - websecure # Use your configured entry point (e.g., web for HTTP) routes: - match: Host(`myapp.example.com`) kind: Rule services: - name: my-app-service # Replace with your app's service name port: 80 middlewares: - name: basic-auth # Attach the basic auth middleware tls: certResolver: default # Optional: If using Let's Encrypt for SSL
Option B: Use Standard Kubernetes Ingress
If you prefer using the standard Ingress resource, add a Traefik-specific annotation to reference the middleware:
apiVersion: networking.k8s.io/v1 kind: Ingress metadata: name: my-app-ingress namespace: default annotations: # Format: <namespace>-<middleware-name>@kubernetescrd traefik.ingress.kubernetes.io/router.middlewares: default-basic-auth@kubernetescrd spec: rules: - host: myapp.example.com http: paths: - path: / pathType: Prefix backend: service: name: my-app-service port: number: 80
Bonus: Secure the Traefik GUI
Since you love the Traefik Dashboard, you can protect it with the same basic auth middleware! Just add the middlewares: - name: basic-auth line to your Dashboard’s IngressRoute definition, same as we did for your app.
Final Notes
- The basic auth middleware is reusable—you can attach it to as many routes as you need.
- Make sure your Traefik deployment has permissions to read Kubernetes Secrets and Middleware resources (most official Traefik Helm charts include these permissions by default).
内容的提问来源于stack exchange,提问作者Larry Cai

