You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Docker环境中全局配置Traefik的安全设置?

How to Set Global Security Headers in Traefik (Docker Environment)

Great question! While Traefik 1.5+ lets you set security headers per service via Docker labels, applying them globally eliminates repetitive config across all your services. Here are two reliable methods to do this in a Docker environment:

Method 1: Configure Global Headers via EntryPoints

You can define security headers directly on your Traefik entry points (like websecure for HTTPS traffic). All services routed through this entry point will automatically inherit these headers—no per-service labels needed.

Example in Docker Compose (Command Arguments)

Add these parameters to your Traefik service's command section:

services:
  traefik:
    image: traefik:v1.7
    command:
      # Basic Traefik config
      --api.insecure=true
      --providers.docker=true
      # EntryPoint with global security headers
      --entrypoints.websecure.address=:443
      --entrypoints.websecure.http.headers.stsseconds=31536000
      --entrypoints.websecure.http.headers.stsincludesubdomains=true
      --entrypoints.websecure.http.headers.stspreload=true
      --entrypoints.websecure.http.headers.framedeny=true
      --entrypoints.websecure.http.headers.contenttypenosniff=true
      --entrypoints.websecure.http.headers.customrequestheaders.X-Forwarded-Proto=https
    ports:
      - "443:443"
    volumes:
      - /var/run/docker.sock:/var/run/docker.sock

Example with a Mounted TOML Config File

If you prefer using a config file instead of command args, create a traefik.toml file and mount it to Traefik:

[entryPoints]
  [entryPoints.websecure]
  address = ":443"
    [entryPoints.websecure.http.headers]
      STSSeconds = 31536000
      STSIncludeSubdomains = true
      STSPreload = true
      FrameDeny = true
      ContentTypeNosniff = true
      CustomRequestHeaders = { X-Forwarded-Proto = "https" }

[api]
insecure = true

[providers.docker]

Then update your Docker Compose to mount this file:

services:
  traefik:
    image: traefik:v1.7
    volumes:
      - /var/run/docker.sock:/var/run/docker.sock
      - ./traefik.toml:/etc/traefik/traefik.toml
    ports:
      - "443:443"

Method 2: Use Default Middlewares with the File Provider

For more flexibility (like easily overriding headers for specific services), define a global security middleware in a separate config file, then set it as the default for all Docker services.

Step 1: Create a Middleware Config File

Create a traefik_middlewares.yml file with your security header rules:

http:
  middlewares:
    global-security-headers:
      headers:
        stsSeconds: 31536000
        stsIncludeSubdomains: true
        stsPreload: true
        frameDeny: true
        contentTypeNosniff: true

Step 2: Update Traefik's Docker Compose Config

Mount the middleware file and set it as the default middleware for Docker services:

services:
  traefik:
    image: traefik:v1.7
    command:
      --api.insecure=true
      --providers.docker=true
      # Load the middleware config file
      --providers.file.filename=/etc/traefik/traefik_middlewares.yml
      # Set the global middleware as default for all Docker services
      --providers.docker.middlewares=global-security-headers@file
    volumes:
      - /var/run/docker.sock:/var/run/docker.sock
      - ./traefik_middlewares.yml:/etc/traefik/traefik_middlewares.yml
    ports:
      - "443:443"

Notes

  • If you need custom headers for a specific service, define a unique middleware for it and override the global setting by adding a label like traefik.http.routers.your-service.middlewares=custom-security-headers@file to that service.
  • Ensure you're running Traefik 1.5 or later, as these features aren't available in older versions.

内容的提问来源于stack exchange,提问作者Waldo

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.15 04:56:47