Ansible Role for a simple Traefik reverse proxy
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Simon Cornet 1e2f033b84
All checks were successful
ci/woodpecker/push/linting Pipeline was successful
docs: improve readme
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
2026-10-05 17:29:31 +02:00
.woodpecker chore(package): update cr.simoncor.net/dockerhub/davidanson/markdownlint-cli2 docker tag to v0.23.3 2026-09-20 05:51:36 +00:00
defaults feat: add coraza as optional waf 2026-04-14 17:30:30 +02:00
handlers feat: initial commit 2025-10-10 22:07:00 +02:00
meta feat: initial commit 2025-10-10 22:07:00 +02:00
roles fix: role url 2026-05-26 16:15:20 +02:00
tasks chore(package): update cr.simoncor.net/dockerhub/library/traefik docker tag to v3.7.13 2026-09-05 05:50:08 +00:00
templates/traefik feat: various small fixes to the traefik config 2026-04-15 16:59:21 +02:00
.ansible-lint fix: exclude only sops yml files from lint 2026-07-14 16:24:00 +02:00
.editorconfig chore: add .editorconfig and .gitattributes 2026-05-27 14:24:06 +02:00
.gitattributes chore: add .editorconfig and .gitattributes 2026-05-27 14:24:06 +02:00
.gitignore feat: initial commit 2025-10-10 22:07:00 +02:00
.markdownlint-cli2.jsonc ci: migrate from gitlab ci to woodpecker 2026-05-15 14:13:50 +02:00
.sops.yaml fix: correct sops regex to ya?ml 2026-07-14 16:02:07 +02:00
.yamllint chore: exclude .yml files from lint configs 2026-07-14 16:17:43 +02:00
AGENTS.md chore: add AGENTS.md for opencode agents 2026-02-16 10:27:05 +01:00
ansible.cfg chore: sync linting and config files from common 2026-07-14 11:33:16 +02:00
playbook.yaml chore(playbook): run galaxy install only on first host 2026-08-13 08:49:33 +02:00
readme.md docs: improve readme 2026-10-05 17:29:31 +02:00
renovate.json feat: initial commit 2025-10-10 22:07:00 +02:00

Ansible Role: Traefik

Installs and runs Traefik as a Docker container on the host network. Traefik terminates TLS on port 443 with Let's Encrypt certificates (DNS-01 challenge through TransIP) and proxies each configured route to a backend. Routes are written to a Traefik file provider config.

Requirements

  • A Docker host. The role uses the community.docker collection.
  • Access to the registry mirror cr.simoncor.net (the image is pulled from cr.simoncor.net/dockerhub).
  • A TransIP account with an API key, used for the ACME DNS challenge.

Dependencies

None in meta/main.yaml. The role does not install Docker itself; run the docker role first (as the s3 playbook does). roles/requirements.yaml (note the .yaml extension) only lists this role (https://git.simoncor.net/ansible/traefik.git).

Variables

Variable Required Default Description
traefik_letsencrypt_email Yes email@example.com E-mail address for Let's Encrypt registration
traefik_routes Yes one example route (service.example.com) List of routes, see below
transip_user Yes TransIP account name (not set in defaults)
transip_key Yes TransIP private key (not set in defaults)
timezone Yes Container timezone (TZ, not set in defaults)

transip_user, transip_key and timezone are used by the tasks but have no default. Keep transip_key in sops-encrypted inventory variables. The key may contain literal \n sequences, which are converted to newlines.

traefik_routes

Every item creates one router and one service in /mnt/traefik/http.yml.

Key Required Default Description
name Yes Public host name, matched with Host(...)
service Yes Name of the router; the service is called <service>-svc
host Yes Backend host or IP address
proto Yes Backend protocol, http or https
port Yes Backend port

The default route also has a waf: false key, which no template uses.

Each router listens on the websecure entrypoint only and uses the transip certificate resolver. The backend URL is <proto>://<host>:<port>. If at least one route uses https, Traefik sets insecureSkipVerify: true for all backends, so backend certificates are not verified.

Example

traefik_letsencrypt_email: "admin@example.com"
timezone: "Europe/Amsterdam"

# transip credentials: keep real values in sops-encrypted inventory vars
transip_user: "example-user"
transip_key: "CHANGE-ME"

traefik_routes:
  - name: "app.example.com"
    service: "webapp"
    host: "192.168.1.10"
    proto: "http"
    port: "8080"
  - name: "api.example.com"
    service: "api"
    host: "192.168.1.11"
    proto: "https"
    port: "443"

Usage

Run playbook.yaml through Semaphore. The playbook first runs ansible-galaxy install -f -r roles/requirements.yaml on localhost, then includes the traefik role.

Operational notes

  • The container is called traefik, uses image cr.simoncor.net/dockerhub/library/traefik:v3.7.13, host networking, restart policy unless-stopped and is pulled on every run.
  • Entrypoints: web on port 80 (redirects to websecure) and websecure on port 443 (timeouts disabled, encoded slashes allowed).
  • Files in /mnt/traefik: traefik.yml, http.yml (both mode 0640), transip.key and acme.json (mode 0600). They are mounted into the container; changes to the config, routes or key restart the container.
  • acme.json holds the issued certificates and is only touched (never overwritten) by the role.
  • After starting the container, the role runs a Docker cleanup (tasks/cleanup.yaml): it prunes containers, images, networks, volumes and the builder cache and then runs docker system prune --all --force --volumes. This removes everything unused on the host.
  • There are no tags.