
In this blog post, we will show you how to set up Traefik as a Reverse Proxy with Automatic SSL on Linux. Traefik is a modern reverse proxy and load balancer that routes incoming web traffic to the correct backend services based on rules such as domain names, paths, or ports. One of its standout features is automatic SSL/TLS certificate management through Let’s Encrypt. Instead of manually generating, installing, and renewing certificates, Traefik requests valid SSL certificates, configures HTTPS, and renews them before they expire. This ensures secure communication between users and applications with minimal administrative effort. Traefik also integrates seamlessly with Docker, automatically detecting new services and updating routing rules. As a result, it simplifies deployment, improves security, reduces maintenance, and provides reliable traffic management for modern cloud-native applications.
To set up Traefik as a reverse proxy with automatic SSL on Linux, the most efficient method is using Docker Compose. This method leverages Traefik’s native Docker provider to automatically detect containers and provision Let’s Encrypt SSL certificates using TLS challenges.
Table of Contents
Prerequisites
- A server running Linux OS
- User privileges: root or non-root user with sudo privileges
- A valid domain with a pointed A record to the server IP address
Step 1. Update the System
In this blog post, we will use Ubuntu 26.04 as the OS. We assume that you have a fresh installation of Ubuntu, and before installing anything on the server, we will upgrade the system packages to the newest versions:
apt update -y && apt upgrade -y
Step 2. Install Docker
Traefik integrates with Docker Compose by automatically discovering services defined in the docker-compose.yml file, routing traffic to them based on labels, and managing HTTPS with automatic SSL certificates.
To begin, install the packages required for the Docker installation by executing the following command:
apt install software-properties-common apt-transport-https ca-certificates -y
Next, download and import Docker’s official GPG key to ensure the integrity and authenticity of the packages:
curl -fsSL https://download.docker.com/linux/ubuntu/gpg | gpg --dearmor -o /usr/share/keyrings/docker-archive-keyring.gpg
Once the key has been added, configure your system to use the official Docker package repository:
echo "deb [arch=amd64 signed-by=/usr/share/keyrings/docker-archive-keyring.gpg] https://download.docker.com/linux/ubuntu $(lsb_release -cs) stable" | sudo tee /etc/apt/sources.list.d/docker.list > /dev/null
After adding the repository, update the package list and install the Docker Engine together with its essential components:
apt update -y apt install docker-ce docker-ce-cli containerd.io docker-buildx-plugin docker-compose-plugin -y
When the installation is complete, start the Docker service and enable it so it starts automatically whenever the system boots:
systemctl start docker && systemctl enable docker
To confirm that Docker is running properly, check the status of the service:
systemctl status docker
If the installation was successful, the output should look similar to the following:
root@host:/opt# systemctl status docker
● docker.service - Docker Application Container Engine
Loaded: loaded (/usr/lib/systemd/system/docker.service; enabled; preset: enabled)
Active: active (running) since Sat 2026-07-18 20:56:17 CDT; 6s ago
Invocation: 9ae8da3bc2b04692b1c3ee1f9fcee1c6
TriggeredBy: ● docker.socket
Docs: https://docs.docker.com
Main PID: 11382 (dockerd)
Tasks: 10
Memory: 23.9M (peak: 24.7M)
CPU: 1.404s
CGroup: /system.slice/docker.service
└─11382 /usr/bin/dockerd -H fd:// --containerd=/run/containerd/containerd.sock
Step 3. Create the Traefik Static Configuration File
First, create a dedicated directory for Traefik and a dedicated Docker network:
mkdir -p /opt/traefik/data
cd /opt/traefik
Create an empty file to store Let’s Encrypt certificates:
touch data/acme.json
Restrict permissions so only the owner can read/write the certificate file:
chmod 600 data/acme.json
Create the shared proxy network:
docker network create traefik-public
The output should look like this:
root@host:/opt/traefik# docker network create traefik-public
b41d8802b45a243131c29ecbb7c43ba661e2207deff0d88a81779d07c5892e6e
Next, create the Traefik static configuration file:
nano data/traefik.yml
And paste the following lines of code:
# data/traefik.yml
entryPoints:
web:
address: :80
http:
redirections:
entryPoint:
to: websecure
scheme: https
websecure:
address: :443
providers:
docker:
endpoint: "unix:///var/run/docker.sock"
exposedByDefault: false
network: traefik-public
certificatesResolvers:
letsencrypt:
acme:
email: admin@yourdomain.com
storage: acme.json
tlsChallenge: {}
Save the file and close it.
Step 4. Create the Docker Compose File for Traefik
To create the Docker Compose file, execute the following command:
nano docker-compose.yml
Paste the following lines of code:
services:
traefik:
image: traefik:v3.3
container_name: traefik
restart: unless-stopped
security_opt:
- no-new-privileges:true
ports:
- "80:80"
- "443:443"
volumes:
- /var/run/docker.sock:/var/run/docker.sock:ro
- ./data/traefik.yml:/traefik.yml:ro
- ./data/acme.json:/acme.json
networks:
- traefik-public
webapp:
image: nginx:alpine
container_name: demo-webapp
networks:
- traefik-public
labels:
- "traefik.enable=true"
- "traefik.http.routers.webapp.rule=Host(`yourdomain.com`)"
- "traefik.http.routers.webapp.entrypoints=websecure"
- "traefik.http.routers.webapp.tls.certresolver=letsencrypt"
- "traefik.http.services.webapp.loadbalancer.server.port=80"
networks:
traefik-public:
external: true
Save the file and close it.
Now, start the Docker container:
docker compose up -d
Once the process is finished, the output should look like this:
root@host:/opt/traefik# docker compose up -d
[+] up 2/2
✔ Container demo-webapp Started 0.9s
✔ Container traefik Started
How does the process work?
When Traefik starts, it reads the Docker labels configured on the container and waits for incoming requests. When you visit https://yourdomain.com, Traefik contacts Let’s Encrypt to request an SSL certificate. Let’s Encrypt then verifies that the domain is correctly pointing to your server, and after successful validation, the certificate is issued and stored by Traefik. If everything is configured correctly, the SSL certificate should be generated and available within approximately 30 seconds to 2 minutes.
In Conclusion
That’s it. You successfully installed Docker and configured Traefik as a Reverse proxy with Automatic SSL on Linux.
Of course, you don’t have to install it yourself if you have difficulty and aren’t familiar with Linux. You can always contact our technical support. You only need to sign up for one of our monthly management plans and submit a support ticket. We are available 24/7 and will address your request immediately.
If you liked this post about setting up Traefik as a Reverse proxy with Automatic SSL, please share it with your friends or leave a comment below.
