基于Docker Compose部署带基础认证的Traefik容器并隐藏仪表盘
Got it, let's get your Traefik setup sorted with dashboard protection and basic auth. Here's the complete, refined configuration you need to implement your requirements:
version: '3' services: traefik: image: traefik:v2.10 # Use a specific stable version to avoid unexpected changes command: - "--api.insecure=false" # Disable direct insecure API access - "--api.dashboard=true" - "--providers.docker=true" - "--providers.docker.domain=domain.com" - "--providers.docker.exposedbydefault=false" - "--entrypoints.web.address=:80" - "--entrypoints.websecure.address=:443" - "--log.level=WARN" networks: - webgateway ports: - "80:80" - "443:443" volumes: - /var/run/docker.sock:/var/run/docker.sock - ./traefik.toml:/traefik.toml - ./htpasswd:/htpasswd # Mount the basic auth credentials file labels: - "traefik.enable=true" - "traefik.http.routers.traefik-dashboard.rule=Host(`traefik.domain.com`)" - "traefik.http.routers.traefik-dashboard.entrypoints=websecure" - "traefik.http.routers.traefik-dashboard.service=api@internal" - "traefik.http.routers.traefik-dashboard.middlewares=traefik-auth" - "traefik.http.middlewares.traefik-auth.basicauth.usersfile=/htpasswd" networks: webgateway: external: true # Remove this line if you want Compose to create the network automatically
Key Setup Steps & Explanations
1. Generate Basic Auth Credentials
You need an htpasswd file to store your username and encrypted password. Use the htpasswd tool (install apache2-utils on Debian/Ubuntu or httpd-tools on RHEL/CentOS if you don't have it):
htpasswd -c ./htpasswd your-preferred-username
You'll be prompted to enter a password, and this will create the htpasswd file in your working directory.
2. Optional: Minimal traefik.toml Config
If you prefer keeping core settings in a TOML file instead of the command section, here's a matching minimal config:
[api] dashboard = true [providers.docker] domain = "domain.com" exposedByDefault = false [entryPoints] [entryPoints.web] address = ":80" [entryPoints.websecure] address = ":443" [log] level = "WARN"
3. Critical Label Breakdown
traefik.enable=true: Ensures Traefik processes this service (required since we setexposedbydefault=false)traefik.http.routers.traefik-dashboard.rule=Host(traefik.domain.com): Routes traffic to the dashboard only when the request matches your domaintraefik.http.routers.traefik-dashboard.middlewares=traefik-auth: Attaches the basic auth middleware to the dashboard routetraefik.http.middlewares.traefik-auth.basicauth.usersfile=/htpasswd: Points to the mounted credentials file for authentication
Final Run Instructions
- Create the
htpasswdfile using the command above - Create the
traefik.tomlfile (or skip it if you're using thecommandsection exclusively) - Start Traefik with:
docker-compose up -d
Now when you visit https://traefik.domain.com, you'll be prompted for your username and password before accessing the secured dashboard. The dashboard is properly hidden behind Traefik's frontend and protected from unauthorized access.
内容的提问来源于stack exchange,提问作者Dakkar

