19 ms·
Take a look at Traefik, even if you don't use containers
- iansinnott 2y ago> Traefik is more comparable to HAProxy than to nginx/caddy/apache2 Aren't caddy and traefik fairly comparable? I've only used them both lightly so I may be missing the core point of each, but I thought of them as very similar.
- thinkmassive 2y agoCaddy is primarily a web server like nginx and apache httpd. Traefik and HAproxy are primarily reverse proxies.
- mholt 2y agoCaddy is actually used as a reverse proxy more than a static file server. It's equally excellent and proficient as both! Caddy's functionality is comparable to nginx, apache httpd, and haproxy.
- indigodaddy 2y agoAnd while we’re at it, it can even forward proxy recentlyish I believe?
- mholt 2y agoYeah, Caddy v1 had a forwardproxy plugin that finally got updated for v2: https://github.com/caddyserver/forwardproxy/ https://github.com/caddyserver/forwardproxy/
- justusthane 2y agoThe rest of the sentence you quoted explains that nginx, Caddy, and Apache are all webservers (which can also reverse proxy). Traefik and HAproxy are only reverse proxies and not webservers.
- IggleSniggle 2y agoHAProxy can be a web server though, albeit it is not designed to operate this way and thus requires some goofy configuration to make happen. I only know this because it was useful for me while working on a HAProxy extension.
- mkesper 2y agoCaddy is at the same level as nginx/apache. It is able to do everything a web server is expected to (serving web sites, files and proxying services) plus handling LetsEncrypt automatically. It does not, afaik, do dynamic service discovery like traefik nor load balancing of TCP at the protocol layer, like e.g. haproxy. https://caddyserver.com/features https://caddyserver.com/features
- baobun 2y agoJust to add on, haproxy does service discovery too. https://www.haproxy.com/blog/consul-service-discovery-for-haproxy https://www.haproxy.com/blog/consul-service-discovery-for-ha...
- mholt 2y agoCaddy can absolutely do both of those things. - https://caddyserver.com/docs/modules/http.reverse_proxy.upstreams.srv https://caddyserver.com/docs/modules/http.reverse_proxy.upst... - https://github.com/mholt/caddy-l4 https://github.com/mholt/caddy-l4
- lmeyerov 2y agoWe are long-time fans of Caddy, preferring it over traefik + nginx especially for our docker-compose flows.. though it's fair to distinguish 'can' vs 'easy to do' E.g., we can imagine writing or using a plugin to figure out some upcoming fancy sticky session routing logic based on routes/content vs just the user IP, but there are easier and more 'with the grain' solutions than with what Caddy exposes today, afaict (Agreed tho: The reverse proxy module, for more typical cases, is awesome and we have been enjoying for years!)
- francislavoie 2y agoSticky sessions are supported: https://caddyserver.com/docs/caddyfile/directives/reverse_proxy#load-balancing https://caddyserver.com/docs/caddyfile/directives/reverse_pr..., and yes it's pluggable so you could write your own LB policy. Very easy, just copy the code from Caddy's source to write your own plugin. Let us know if you need help. Also yes, Caddy does service discovery if you use https://github.com/lucaslorentz/caddy-docker-proxy https://github.com/lucaslorentz/caddy-docker-proxy, configuration via Docker labels. Or you can use dynamic upstreams (built-in) https://caddyserver.com/docs/caddyfile/directives/reverse_proxy#dynamic-upstreams https://caddyserver.com/docs/caddyfile/directives/reverse_pr... to use A/AAAA or SRV DNS records to load your list of upstreams.
- candiddevmike 2y agoTraefik can't serve static files, or interact with CGI providers like PHP.
- psYchotic 2y agoI'm considering moving reverse proxying to Traefik for my self-hosted stuff. Unlike the article's author, I'm running containerized workloads with Docker Compose, and currently using Caddy with the excellent caddy-docker-proxy plugin. What that gets me, currently: - Reverse proxying, with Docker labels for configuration. New workloads are picked up automatically (but I do need to attach workloads to Caddy's network bridge). - TLS certificates - Automatic DNS configuration (using yet another plugin, caddy-dynamicdns), so I don't have to worry too much about losing access to my stuff if my ISP decides to hand me a different IP address (which hasn't happened yet) There are a few things I'm currently not entirely happy about my setup: - Any new/restarting workload makes Caddy restart entirely, resulting in loss of access to my stuff (temporarily). Caddy doesn't hand off existing connections to a new instance, unfortunately. - Using wildcard certs isn't as simple as it could/should be. As I don't want every workload to be advertised to the world through certificate transparency logs, I use wildcard certs, and that means I currently can't use simple Caddy file syntax I otherwise would with a cert per hostname. This is something I know is being worked on in Caddy, but still. Anyway, I've used Traefik in k8s environments before, and it's been fairly pleasant, so I think I'll give it a go for my personal stuff too! PS: Don't let this comment discourage you trying Caddy, it's actually really good!
- mynegation 2y agoI have not used Caddy, I use traefik and it discovers docker properties for configuration and TLS certificates with auto update. Not sure about dynamic DNS - I do not use it from Traefik. Adding and removing containers does not need a restart AFAIR.
- remram 2y agoThose are giant limitations. This is the first I hear of any reverse proxy that has to restart and drop connections to update configuration. That is usually the first, most fundamental part of any such server's design.
- IggleSniggle 2y agoCaddy doesn't have to restart, I think it's related to the specifics of their setup. The simple/easy path that gets a lot of people into caddy has a workflow that's more like, run caddy, job done. The next level is, give caddy super simple configuration file, reload caddy with "caddy reload --config /etc/caddy/Caddyfile". After that, you use the REST API to make changes to the server while it is running, which uses a JSON configuration definition instead of a Caddyfile, so it ends up being a jump for users.
- MrOxiMoron 2y agoI love treafik, we use it with nomad/consul and docker to setup our whole infrastructure. The plugin system is also simple yet powerful and the dynamic configs are great for our customers custom domains, we can quickly see if a domain points to the right IP and put it in to get everything working. And of a domain no longer points to is we get a slack notification and it removes it from traefik so it no longer tries to get SSL certificates for it.
- kopadudl 2y agoWhen my company looked at different proxies for k8s, we ended upon traefik cause we had experience from docker swarm and it has a dashboard.
- silverquiet 2y agoI use Traefik in production (with containers), and my favorite aspect of it is that the configuration is carried via the labels on containers which means I rarely if ever need to make any modifications to the Traefik config itself. I'd say the biggest con is trying to figure out how to pronounce the name - I think it's just regular traffic, but I can't help wanting to call it "trey-feek" or something like that.
- Projectiboga 2y agoae is closest to y, or hi. So Tryfik, is my guess, otherwise is Trayfik. If it's European fik, might be feek. *Just taking a guess here.
- tazjin 2y agoI think its "träfik", i.e. "traffic" with a German accent.
- psYchotic 2y ago> ae is closest to y, or hi. So Tryfik, is my guess, otherwise is Trayfik. If it's European fik, might be feek. *Just taking a guess here. I wondered how to pronounce Traefik myself, so I started googling, and came across this: https://traefik.io/blog/how-to-pronounce-traefik-d06696a3f026/ https://traefik.io/blog/how-to-pronounce-traefik-d06696a3f02... Tldr: just pronounce as you would "traffic".
- fidotron 2y agoHeavy +1 on the labels thing. Reduces the scope of things to keep track of massively, even if writing them the first time is slightly harder because of the escaping and verbosity. I think a combination of traefik and docker compose are in the sweet spot for small scale self hosters that haven't reached the point where k8s will pay off. i.e. if you have less servers than a k8s HA control plane would use.
- silverquiet 2y agoSmall-scale self hoster would certainly describe my situation (though we do have some of the same infrastructure issues as larger companies). We actually use Swarm which I generally like, but if it was my call we might have looked more at a simplified Kubernetes platform like K3s just because of a safety in numbers aspect.
- djhworld 2y agoI've been using traefik for a few years for all my self hosted things. I abandoned the dynamic/discovery/docker labelling functionality though it was just too finicky and annoying to debug. Instead I generate a static config file using a template engine, pretty much all my things are just a combination of host/target/port so very easy to generate the relevant sections - I don't really have any complicated middlewares other than handling TLS. It sounds like the author of the linked post has taken the same route. The config gets generated through an ansible script and then gets copied to the machine where traefik is running - traefik watches the directory where that file is and auto-reloads on changes. It's been working great!
- beestripes 2y agoWhy traefik over nginx for my modest needs, a couple docker hosts and a few dozen containers. I use https://github.com/NginxProxyManager/nginx-proxy-manager https://github.com/NginxProxyManager/nginx-proxy-manager, would traefik provide a benefit on such a small scale?
- simonw 2y agoIf what you've got already works then no, I don't think you would see any benefit from switching. The moment you need a feature which Traefik provides that isn't in Nginx is when I would consider the switch.
- treyd 2y agoBut what features does Traefik have that nginx doesn't?
- johnchristopher 2y agoI like traefik hot reload (among other things). Want to hide a service (the proxied app), a new route (a router in traefik terminology), a middleware (basic auth, https redirection, headers manipulation) ? Just drop the file and it gets automatically picked up, no need to reload traefik or that vhost. Truth is: I don't like nginx syntax and traefik is/was shiny :]. I went in for the LE renewal and containers, I stayed for the configuration style.
- wg0 2y agoSide question - what people use to hide (and make accessible) the internal services such as grafana, prometheus, rabbit mq (the web interface) and such? Should they be public behind such a proxy? (seems odd) Or should they be totally internal and then setup a Wireguard VPN to reach them?
- pyr0hu 2y agoWe use tailscale for this exact use case and has been working flawlessly so far. You can even set up ACL lists as a firewall.
- John23832 2y agoFrom the internet? Drop them at the ingress level (if using kubernetes). You could also do some ip filtering. Then use an internal proxy (or internal ip of some kind) to reach them. For proof of concepts, I use cloudflare tunnels which allows you to add ACLs to particular routes.
- section_me 2y agoAuth forwarding[1] is normally the route. This allows you to basically zero auth your services. You can also use wireguard or tailscale[2] [1] https://doc.traefik.io/traefik/middlewares/http/forwardauth/ https://doc.traefik.io/traefik/middlewares/http/forwardauth/ [2] https://doc.traefik.io/traefik/master/https/tailscale/ https://doc.traefik.io/traefik/master/https/tailscale/
- waldrews 2y agoServe them on a firewalled port, then: 1) VPN if you need to expose them to multiple trusted users, 2) firewall rules to make them accessible to your IP range, or (probably easiest), 3) access them by ssh tunnel.
- Hrun0 2y ago> what people use to hide (and make accessible) the internal services such as grafana, prometheus, rabbit mq (the web interface) and such? Proxies or VPNs like you mentioned. You usually don't expose things if you don't have to.
- 2y ago
- siva7 2y agoIt’s nice if you’re running a bare metal server on hetzner or DO but in the age of cloud platforms like aws or azure there is hardly a need for traefik.
- PennRobotics 2y agoEven on Hetzner, it's not amazing and not a one-click workflow. Load their Photoprism image on a standard server with only IPv6 (as a v4 address costs extra) and certificates will not get generated; logs point to Traefik although the solution is modifying Dockerfiles; thanks Dockerphiles, for insisting your software is the answer to everything server...
- btbuilder 2y agoWhen looking for a reverse proxy that is performant on Windows and Linux around 5 or 6 years ago the options were very limited. Traefik is what we ended up using. I haven’t checked recently but at the time nginx on Windows used select() and envoy was either beta or needed a recent version of the Windows kernel that not all customers were running. We still use it today.
- riedel 2y agoFunnily I spend my weekend making a traefik config file to gitlab pages on a self hosted instance without pages enabled but using the artifact API. No code involved. Had to configure quite some rewriting logic and use three different plug-ins, which are mostly unmaintained. In the end probably something like nginx, Apache or caddy or a bit of code probably would have worked better, because of all the layering of different middleware. But it worked somehow. I guess it shines through still for easy SSL termination of docker and great observability. That is why at least I have been using it for the past years.
- cagenut 2y agoIn a mirror/reverse of the OPs premise - I always wondered why so many of these open source http reverse proxies sprung up in the container era, like what did they offer that varnish or a vmod to varnish wasn't already doing or capable of? somehow varnish almost completely missed the container era, despite seemingly being the exact type of tool a bunch of teams would go on to create.
- Starlevel004 2y agoDevops guys are mostly incapable of using any service that isn't a) written in Go and b) configured using a YAML-based DSL.
- TNorthover 2y agoTraefik's YAML does a particularly bad job at keeping syntax (such as it is) separate from user-defined labels, I feel. Very difficult to just look at a file and see which bits are labels for the sake of it, and which bits are direct instructions to builtin features.
- demi56 2y ago> and b) configured using a YAML-based DSL. Go devops HATE YAML-based DSL we just put it there cause there’s not alternatives, json ?, don’t wanna go there fortunately there’s CUE lang but moving all these project to accept cue isn’t that easy either. > Devops guys are mostly incapable of using any service that isn't a) written in Go Lol we basically rewrite it in Go if we’re using it frequently. Most Go projects are just things the founder really wanted for himself
- lmeyerov 2y agoFor Caddy, LetsEncrypt: Free TLS in one line without talking to anyone For Traefik, afaict, something about k8s
- methou 2y agoThe only problem I'm having with it is that it doesn't support unix domain socket[0], in a "cloud native" environment you rarely need it but if you are using single node this can be sweet. -- [0]: https://github.com/traefik/traefik/issues/4881 https://github.com/traefik/traefik/issues/4881
- meonkeys 2y agoCould you say more about how a non-network socket would be beneficial? I'm guessing simpler code and lower resource usage, but I'm curious what you're interested in. And by "single node", do you mean one server / one user (even if the user is, say, a single API consumer or whatever), or something else?
- kubanczyk 2y agoAny euid can connect to a localhost tcp socket. But a unix socket is protected with filesystem permissions (rwxrwxrwx, etc.).
- znpy 2y ago> you mount the docker socket into the traefik container and gain the ability to auto-detect other containers that you might want to expose using traefik. Totally not a security issue. Source: trust me bro.
- xorax 2y agohttps://github.com/traefik/traefik/issues/4174 https://github.com/traefik/traefik/issues/4174
- meonkeys 2y agoRelated: https://doc.traefik.io/traefik/providers/docker/#docker-api-access https://doc.traefik.io/traefik/providers/docker/#docker-api-... https://www.reddit.com/r/Traefik/comments/g46lhh/does_binding_the_docker_socket_in_readonly_mode/ https://www.reddit.com/r/Traefik/comments/g46lhh/does_bindin... https://github.com/wollomatic/traefik-hardened https://github.com/wollomatic/traefik-hardened
- dizhn 2y agoI use caddy wherever I can. That it can already handle automatic certificates is a big plus. Plus it's very easy to congiure.
- jspdown 2y agoIf you like Caddy for it's ACME capabilities, then you might enjoy Traefik as well. It supports HTTP, TLS ALPN and DNS challenges and can be configured in one line as well.
- dizhn 2y agoI already use it as a web server and reverse proxy so it's a better match. I've tried traefik in the past and it wasn't as simple as caddy to configure. Caddy has some well thought out magic (like creating a sane modern php config with just one line).
- amne 2y agoI tried to get caddy to listen to both ports 80 and 443 in a cluster. I failed miserably. The documentation simply dismisses this as a possible scenario.
- mholt 2y agoHow do you mean? Many of our users do this with no issues.
- amne 2y agoI didn't realize the lack of context so my bad. I was trying to do some tests to compare kubernetes resource usage of nginx+php-fpm, nginx unit with php module and frankenphp (based on caddy). For reasons that are not relevant I need the service to be exposed on both ports 80 and 443 and do both plain HTTP and HTTPS. The host is not fixed because there is a public DNS but also the cluster-internal service name. With nginx+php-fpm and nginx unit it was dead easy: here's port 80, here's a self-signed cert for TLS so listen also on 443. That's it. it works. With Caddy it was so frustrating to see so many assumptions and "automatic redirects, trust me, this is what you want" and no obvious manual override that I just gave up. What I got working before I gave up was either only port 80 which is not good enough, either only port 443 which is also not good enough or both but 80 redirects to 443.
- chadsix 2y agoYou can also use Cloud Seeder [1] which might be easier since it gives each container a dedicated IP. </shamelessplug> [1] https://github.com/ipv6rslimited/cloudseeder https://github.com/ipv6rslimited/cloudseeder
- jasoneckert 2y agoAnother thing worthy of note is that Traefik is configured by default in K3s. This has allowed K3s to be the quickest way to spin up a K8s cluster for testing, essentially allowing you to treat your cluster like cattle too. Simply add your deployment and associated service using NodePort, and you can access your app without worrying about the ingress controller. I use a shell script to spin up K3s clusters and test apps I specify as a positional parameter on demand (leveraging the ttl.sh ephemeral container registry). The same script tears down the cluster when finished.
- deleted 2y ago[deleted]
- sph 2y agoTraefik is pretty cool, but suffers from the same, terrible problem of Ansible: there is a lot of documentation, and a lot of words written, yet you can never find anything you need. I have used it since v1 and I routinely get lost in their docs, and get immensely frustrated. I have been using Caddy for smaller projects simply because its documentation is not as terrible (though not great by any stretch) Technical writers: documentation by example is good only for newbies skimming through. People familiar with your product need a reference and exhaustive lists, not explanation for different fields spread over 10 tutorial pages. Focus on those that use the product day in and day out, not solely on the "onboarding" procedure. This is my pet peeve and the reason why I hate using Ansible so damn much, and Traefik to a lesser extent.
- mholt 2y agoFunny you say that because we don’t have nearly any examples in the Caddy docs. We’re working on improving them later this year.
- sph 2y agoExamples are good in docs. But documentation that's only made of examples and tutorials... not so much. Thanks for Caddy btw. Neat little tool.
- linsomniac 2y agoDo not agree WRT ansible, been using it for well over 5 years and usually a google search points me right at the correct part of the documentation to answer my question. Ansible, the tool itself, can be a bit obtuse, largely IMHO because of the YAML source language, so some concepts are hard to translate into the tool, but the documentation has never bothered me. As far as "a lot of words written, can't find what you need", Fortinet is my poster child there (based on trying to use it a decade ago). Everything I looked up there had 10,20,30 pages of introductory material with the Fortinet stuff spread throughout it.
- sph 2y agoAlright, please link me to an exhaustive list of Jinja filters supported by Ansible out of the box. I'll wait. What you are given is https://docs.ansible.com/ansible/latest/playbook_guide/playbooks_filters.html https://docs.ansible.com/ansible/latest/playbook_guide/playb... and you need basically to read/scan each example until you find what you need [1]. Do you call that good, especially when these are basically the only way of doing anything a little complex? That's a sure way of killing my flow and productivity in its tracks. I have been through this page in anger a dozen times, and I still have no idea what Ansible filters can or cannot do. Also, using Google to find stuff is "cheating". The goal of documentation is to be able to use it as reference; if you need an external tool to find anything in it, that defeats its purpose a bit. When people wrote documentation books, they had to make sure it's usable, legible and efficient. These days apparently that's become lost art. 1: these examples are not even exhaustive, because they don't list all the builtin Jinja filters; chances are that what you need isn't listed on that page, but you should instead refer to https://tedboy.github.io/jinja2/templ14.html https://tedboy.github.io/jinja2/templ14.html
- arush15june 2y agoI use caddy rather traefik. It's much easier to manage the Caddyfile compared to the traefik YAML config IMO, and we just keep three separate Caddyfiles for local, production and on-prem deployments. There are a plethora of great plugins, we use the coraza WAF plugin for caddy and it works well.
- pricci 2y agoI moved from Traefik to Caddy with caddy-docker-proxy for my self-hosting setup. All the features I need but *much* simpler. https://github.com/lucaslorentz/caddy-docker-proxy https://github.com/lucaslorentz/caddy-docker-proxy
- sureglymop 2y agoLooks interesting but I don't see the benefits really. Still looks like a lot of labels exactly like with traefik. Why should one switch?
- BrandoElFollito 2y agoHaving had used traefik, caddy and now caddy proxy, I like the latter because labels are simple pointers to actual caddy features (reasonably documented). I used to have all my docker compose files in elaborate structures but moved to portainer for simplicity. Together with caddy proxy it rocks (well, there are several things missing but I have hope)
- preya2k 2y agoSame here. I enjoyed Traefik for being able to use docker tags for my reverse proxy configuration. The mechanism is great, however I did not like Traefiks internal config structure. Caddy is much easier for me to understand and matches my (small scale) use cases much better. Using Caddy via Docker labels through caddy-docker-proxy is about as perfect as it gets (for me).
- renk 2y agoYes. If you don't need all of the service discovery and auto-scaling shenanigans (or are willing to script it yourself), you can gleefully skip Traefik, Docker Swarm, Kubernetes etc. and just use Caddy! It can really do most things and it does them well.
- muhehe 2y agoIn the future our company will migrate to k8s. It looks like it will be openshift, specifically. Do we need this in openshift or is there some "native" mechanism baked in?
- verdverm 2y agoYou'll likely have an ingress controller provided with openshift, which tends to be more batteries included. There are quite a few options: https://kubernetes.io/docs/concepts/services-networking/ingress-controllers/ https://kubernetes.io/docs/concepts/services-networking/ingr...
- lakomen 2y agoTraefik is considerably slower and more resource hungry than nginx. There is nothing more to say.
- engine_y 2y agoWe've been using Traefik in prod for 2 years. While I used NGINX in the past, I decided to migrate to Traefik mainly because of the automatic let's encrypt integration. I am sorry for that decision. Traefik's documentation does not make sense to me or my team. It is finicky and misbehaves without proper logging. As an example - when I want to recreate the certificates - it fails sporadically leaving prod down for an indefinite amount of time. We're moving back to NGINX.
- spyspy 2y agoI’ve always just used go’s built in reverse proxy if I need an API gateway. You can adapt it to meet any specific need, easily find libraries to do common tasks (CORS, rate limiting, retries, etc), and the best part: no configuration language. You just write go.
- jimmyl02 2y agocurious what are the performance characteristics here? I would assume something like Nginx that has been optimized over a longer period of time / a more specific use case would have non-negligible performance benefits at scale?
- spyspy 2y agoNot everything needs to be at “scale”. I’ve deployed this pattern over 10k req/sec but it’s all about your SLOs. I’ve (thankfully) never needed to lose sleep over a millisecond or 2 in my line of work.
- hellcow 2y agoI did the same thing. After some bad downtime from Traefik introducing breaking changes in a point release, I decided to write my own. My reverse proxy offered a service mesh, live config reloads, managed TLS certs, and automatically rerouted traffic around down services. The whole thing was a few hundred LOC anyone could understand in its entirety. It ran in production for years unchanged and never caused an outage.
- 2y ago
- Sincere6066 2y agoI'll stick with caddy. It's worked for me for years.
- rglullis 2y agoFor authentication, I had good luck with authentik as forward proxy. The one thing that bothers me with traefik is that their implementation of ACME does not work if you have some sort of DNS load balancing. I had one setup with three servers responding to the same domain. It seems the first request )to start the ACME dance) would go to one server, and if the second one (with the .well-known address) is sent to a different one, it will just return a 404 and fail the whole thing. Now I either have * to delegate the certificate management to the service itself or add Caddy as a secondary proxy just to get certificate from it. * Of course, someone smarter than me will point me to a better solution and I will be forever grateful.
- jackweirdy 2y agoIf I am not misunderstanding (sorry if I am) it sounds like you use the http challenge where your cert provider tries to GET your challenge file — if so, could the DNS challenge be better suited? There, you put the challenge in a TXT record value
- rglullis 2y agoYou got it, but your solution won't work because of one detail: I can not use the DNS challenge because I am running a managed service provider, and my customers are the ones who own the domain. All I can do is ask them "please add a CNAME to my gateway", and I need to figure out everything else on my side.
- jspdown 2y agoIt might not be suitable for your use case but, have you tried ACME DNS challenge delegation to a different one hosted by yourself?
- francislavoie 2y agoSounds like you're looking for Caddy's On-Demand TLS, then. No other server or ACME client does this. https://caddyserver.com/docs/automatic-https#on-demand-tls https://caddyserver.com/docs/automatic-https#on-demand-tls
- barbazoo 2y agoI’d stay away from it. The magical way to set it up via docker compose tags is nice but doesn’t allow for zero downtime deployment at least until recently. Getting true zero downtime deployments only worked with their file provider but that’s a bit archaic these days.
- ofrzeta 2y agoIs it any better than HAProxy? HAProxy has served me well for at least a decade and has also been modernized for the cloud age with the runtime API that allows dynamic configuration.
- ljhtlajdfqasd 2y agoAll of these proxies seemed to have achieved feature parity within the last couple years. Where they seem differ is the licensing, enterprise model, source language, and data plane model (sidecar vs no sidecar).
- juangacovas 2y agoSame here, we've been using HAProxy for years now and only gets to improve
- teekert 2y agoI have used traefik a lot. But I mostly got frustrated with all the docker-compose labels and layers and so many lines just to have a rev proxy. Then I found Caddy. Never looked back. I guess I was never the audience for Traefik. I just need an https enabled rev proxy. Or a basic-auth layer. In Caddy both are just 1 line, very concise, no layers (which I still don’t understand…)
- cab404 2y agoSomehow, I find myself using Caddy everywhere I would use Træfik in the past.
- vedmed 2y agoI needed a reverse proxy the other week. OPNSense is my firewall. I tried traefik, but it was too complicated. So I installed caddy, and it was easy as pie. My .02
- firesteelrain 2y agoWe just started running Traefik in production since looking at self managed K8s was just too hard and complicated for what we were trying to do. We have an Ansible Docker compose service (that’s what we call it), that starts up the containers and auto registers the containers with Traefik. It works really well. We are airgapped so can’t use Let’s Encrypt. We inject the certs into our containers via Ansible or Docker Compose.
- brainzap 2y agoIt would be nice if proxies are opinionated about typical URL usecases and offer an easy way to redirect www to non-www or handle path with missing slash.
- notoall 2y agoFor simple deployments, consider whether you need a reverse proxy at all. I have IPv6 everywhere, with each service getting its own IPv6 address. Each service is managed in inetd-style (via systemd-socket-proxyd ), and so essentially listens directly. For services that need to serve IPv4, I have a reverse proxy on my network edge that demuxes on TLS SNI to the corresponding IPv6 address. The advantage here is never having to deal with complex applications, with their complex and changing configuration.
- notpushkin 2y agoI'm using a reverse proxy just to terminate TLS. Pretty sure it is possible to do that at a service level, but don't think it's worth the trouble.
- dmeijboom 2y agoI don’t get the appeal of Traefik. If you want an easy to use reverse proxy that works well, pick nginx. Want something simple for self-hosting? Take a look as caddy. For Kubernetes, try out Envoy Gateway.
- 1oooqooq 2y ago> “Server Name Indication” (SNI) into the trash it goes. anyone who support https everywhere and ever slightly tolerates SNI is a fool.
- d-z-m 2y agocan you elaborate?
- 1oooqooq 2y agoSNI = nsa backdoor into https everywhere. basically it moves private info in the plain text header "for edge performance"
- d-z-m 2y ago> SNI = nsa backdoor into https everywhere. No. Not even remotely true. If you can write a coherent argument that substantiates this claim then I will address it.
- ajnin 2y agoI don't see why you're opposing HTTPS everywhere and SNI, HTTP already had the Host header so it is not a new information leak. It's pretty much mandatory if you intend to serve multiple domains with different certificates from the same host/proxy, which seems like a very very common use case, and there is no alternative to this right now.
- 1oooqooq 2y agoI don't see how you think NSI doesn't nullify https everywhere. "we need MitM for performance". listen to yourself. if some optimization breaks security, you do not optimize.
- d-z-m 2y ago> I don't see how you think NSI doesn't nullify https everywhere. It doesn't. SNI doesn't leak the URL being accessed, or anything that isn't encoded in the hostame.
- woopwoop24 2y agoi had such a hard time learning traefik and transitioning to V2. I do not fall into the standard case, wanting to use traefik for containers, not running on the same host (you cannot have labels annoted as the docs suggest, if the container is on another host) Docs were sparse and also not wanted to use the env vars for the traefik config as well, so took a bit of fumbling and reading and eventually i figured it out, but was almost on the verge of going back to haproxy
- jakubsuchy 2y agoArticle spends a lot of time comparing Traefik to HAProxy. Might just as well use HAProxy then :-)
- mubu 2y agoA couple weeks ago I was deciding between reverse proxies and eventually settled with Caddy because of its simplicity. However, Traefik's auto discovery of containers and referencing by labels is quite nice, but Caddy has a plugin to do the same. I read the article but I'm still not convinced Traefik has anything over Caddy for me. Maybe someone else does and can chime in.
- nderjung 2y agoIf you're looking for an alternative way to run traefik, we support this out-of-the-box on https://kraft.cloud https://kraft.cloud -- A platform dedicated to running ultra-lightweight VMs based on Dockerfiles, with millisecond cold start times (96ms for Traefik), scale-to-zero, autoscale. Check it out in our docs: https://docs.kraft.cloud/guides/traefik/ https://docs.kraft.cloud/guides/traefik/ It's also possible to start traefik and other services together using Compose files: https://docs.kraft.cloud/guides/features/compose/ https://docs.kraft.cloud/guides/features/compose/
- evtothedev 2y agoThe 37Signals/Basecamp team has been working on a small, opinionated replacement for Traefik called Thruster: https://github.com/basecamp/thruster https://github.com/basecamp/thruster Would be worth checking out, if you're currently considering options.
- renk 2y agoSimilar: https://git.deuxfleurs.fr/Deuxfleurs/tricot https://git.deuxfleurs.fr/Deuxfleurs/tricot
- cvalka 2y agoThe holly three: Caddy, Envoy, Traefik. Do not use nginx and haproxy.
- xorcist 2y agoAfter running into traefik a couple of times I have yet to see a deployment where it does not consume more cpu cycles than the microservices it is fronting. From a casual glance it does nothing haproxy doesn't already do, at a fraction of the cpu cost.