如何在Docker环境中全局配置Traefik的安全设置?
Great question! While Traefik 1.5+ lets you set security headers per service via Docker labels, applying them globally eliminates repetitive config across all your services. Here are two reliable methods to do this in a Docker environment:
Method 1: Configure Global Headers via EntryPoints
You can define security headers directly on your Traefik entry points (like websecure for HTTPS traffic). All services routed through this entry point will automatically inherit these headers—no per-service labels needed.
Example in Docker Compose (Command Arguments)
Add these parameters to your Traefik service's command section:
services: traefik: image: traefik:v1.7 command: # Basic Traefik config --api.insecure=true --providers.docker=true # EntryPoint with global security headers --entrypoints.websecure.address=:443 --entrypoints.websecure.http.headers.stsseconds=31536000 --entrypoints.websecure.http.headers.stsincludesubdomains=true --entrypoints.websecure.http.headers.stspreload=true --entrypoints.websecure.http.headers.framedeny=true --entrypoints.websecure.http.headers.contenttypenosniff=true --entrypoints.websecure.http.headers.customrequestheaders.X-Forwarded-Proto=https ports: - "443:443" volumes: - /var/run/docker.sock:/var/run/docker.sock
Example with a Mounted TOML Config File
If you prefer using a config file instead of command args, create a traefik.toml file and mount it to Traefik:
[entryPoints] [entryPoints.websecure] address = ":443" [entryPoints.websecure.http.headers] STSSeconds = 31536000 STSIncludeSubdomains = true STSPreload = true FrameDeny = true ContentTypeNosniff = true CustomRequestHeaders = { X-Forwarded-Proto = "https" } [api] insecure = true [providers.docker]
Then update your Docker Compose to mount this file:
services: traefik: image: traefik:v1.7 volumes: - /var/run/docker.sock:/var/run/docker.sock - ./traefik.toml:/etc/traefik/traefik.toml ports: - "443:443"
Method 2: Use Default Middlewares with the File Provider
For more flexibility (like easily overriding headers for specific services), define a global security middleware in a separate config file, then set it as the default for all Docker services.
Step 1: Create a Middleware Config File
Create a traefik_middlewares.yml file with your security header rules:
http: middlewares: global-security-headers: headers: stsSeconds: 31536000 stsIncludeSubdomains: true stsPreload: true frameDeny: true contentTypeNosniff: true
Step 2: Update Traefik's Docker Compose Config
Mount the middleware file and set it as the default middleware for Docker services:
services: traefik: image: traefik:v1.7 command: --api.insecure=true --providers.docker=true # Load the middleware config file --providers.file.filename=/etc/traefik/traefik_middlewares.yml # Set the global middleware as default for all Docker services --providers.docker.middlewares=global-security-headers@file volumes: - /var/run/docker.sock:/var/run/docker.sock - ./traefik_middlewares.yml:/etc/traefik/traefik_middlewares.yml ports: - "443:443"
Notes
- If you need custom headers for a specific service, define a unique middleware for it and override the global setting by adding a label like
traefik.http.routers.your-service.middlewares=custom-security-headers@fileto that service. - Ensure you're running Traefik 1.5 or later, as these features aren't available in older versions.
内容的提问来源于stack exchange,提问作者Waldo

