How to Set Up Traefik as a Reverse Proxy with Automatic SSL

How to Set Up Traefik as a Reverse Proxy with Automatic SSL

In this blog post, we will show you how to set up Traefik as a Reverse Proxy with Automatic SSL on Linux. Traefik is a modern reverse proxy and load balancer that routes incoming web traffic to the correct backend services based on rules such as domain names, paths, or ports. One of its standout features is automatic SSL/TLS certificate management through Let’s Encrypt. Instead of manually generating, installing, and renewing certificates, Traefik requests valid SSL certificates, configures HTTPS, and renews them before they expire. This ensures secure communication between users and applications with minimal administrative effort. Traefik also integrates seamlessly with Docker, automatically detecting new services and updating routing rules. As a result, it simplifies deployment, improves security, reduces maintenance, and provides reliable traffic management for modern cloud-native applications.

To set up Traefik as a reverse proxy with automatic SSL on Linux, the most efficient method is using Docker Compose. This method leverages Traefik’s native Docker provider to automatically detect containers and provision Let’s Encrypt SSL certificates using TLS challenges.

Prerequisites

  • A server running Linux OS
  • User privileges: root or non-root user with sudo privileges
  • A valid domain with a pointed A record to the server IP address

Step 1. Update the System

In this blog post, we will use Ubuntu 26.04 as the OS. We assume that you have a fresh installation of Ubuntu, and before installing anything on the server, we will upgrade the system packages to the newest versions:

apt update -y && apt upgrade -y

Step 2. Install Docker

Traefik integrates with Docker Compose by automatically discovering services defined in the docker-compose.yml file, routing traffic to them based on labels, and managing HTTPS with automatic SSL certificates.

To begin, install the packages required for the Docker installation by executing the following command:

apt install software-properties-common apt-transport-https ca-certificates -y

Next, download and import Docker’s official GPG key to ensure the integrity and authenticity of the packages:

curl -fsSL https://download.docker.com/linux/ubuntu/gpg | gpg --dearmor -o /usr/share/keyrings/docker-archive-keyring.gpg

Once the key has been added, configure your system to use the official Docker package repository:

echo "deb [arch=amd64 signed-by=/usr/share/keyrings/docker-archive-keyring.gpg] https://download.docker.com/linux/ubuntu $(lsb_release -cs) stable" | sudo tee /etc/apt/sources.list.d/docker.list > /dev/null

After adding the repository, update the package list and install the Docker Engine together with its essential components:

apt update -y

apt install docker-ce docker-ce-cli containerd.io docker-buildx-plugin docker-compose-plugin -y

When the installation is complete, start the Docker service and enable it so it starts automatically whenever the system boots:

systemctl start docker && systemctl enable docker

To confirm that Docker is running properly, check the status of the service:

systemctl status docker

If the installation was successful, the output should look similar to the following:

root@host:/opt# systemctl status docker
● docker.service - Docker Application Container Engine
Loaded: loaded (/usr/lib/systemd/system/docker.service; enabled; preset: enabled)
Active: active (running) since Sat 2026-07-18 20:56:17 CDT; 6s ago
Invocation: 9ae8da3bc2b04692b1c3ee1f9fcee1c6
TriggeredBy: ● docker.socket
Docs: https://docs.docker.com
Main PID: 11382 (dockerd)
Tasks: 10
Memory: 23.9M (peak: 24.7M)
CPU: 1.404s
CGroup: /system.slice/docker.service
└─11382 /usr/bin/dockerd -H fd:// --containerd=/run/containerd/containerd.sock

Step 3. Create the Traefik Static Configuration File

First, create a dedicated directory for Traefik and a dedicated Docker network:

mkdir -p /opt/traefik/data

cd /opt/traefik

Create an empty file to store Let’s Encrypt certificates:

touch data/acme.json

Restrict permissions so only the owner can read/write the certificate file:

chmod 600 data/acme.json

Create the shared proxy network:

docker network create traefik-public

The output should look like this:

root@host:/opt/traefik# docker network create traefik-public
b41d8802b45a243131c29ecbb7c43ba661e2207deff0d88a81779d07c5892e6e

Next, create the Traefik static configuration file:

nano data/traefik.yml

And paste the following lines of code:

# data/traefik.yml
entryPoints:
web:
address: :80
http:
redirections:
entryPoint:
to: websecure
scheme: https
websecure:
address: :443

providers:
docker:
endpoint: "unix:///var/run/docker.sock"
exposedByDefault: false
network: traefik-public

certificatesResolvers:
letsencrypt:
acme:
email: admin@yourdomain.com
storage: acme.json
tlsChallenge: {}

Save the file and close it.

Step 4. Create the Docker Compose File for Traefik

To create the Docker Compose file, execute the following command:

nano docker-compose.yml

Paste the following lines of code:

Need a fast and easy fix?
✔ Unlimited Managed Support
✔ Supports Your Software
✔ 2 CPU Cores
✔ 2 GB RAM
✔ 50 GB PCIe4 NVMe Disk
✔ 1854 GeekBench Score
✔ Unmetered Data Transfer
NVME 2 VPS

Now just $43 .99
/mo

GET YOUR VPS
services:
traefik:
image: traefik:v3.3
container_name: traefik
restart: unless-stopped
security_opt:
- no-new-privileges:true
ports:
- "80:80"
- "443:443"
volumes:
- /var/run/docker.sock:/var/run/docker.sock:ro
- ./data/traefik.yml:/traefik.yml:ro
- ./data/acme.json:/acme.json
networks:
- traefik-public

webapp:
image: nginx:alpine
container_name: demo-webapp
networks:
- traefik-public
labels:
- "traefik.enable=true"
- "traefik.http.routers.webapp.rule=Host(`yourdomain.com`)"
- "traefik.http.routers.webapp.entrypoints=websecure"
- "traefik.http.routers.webapp.tls.certresolver=letsencrypt"
- "traefik.http.services.webapp.loadbalancer.server.port=80"

networks:
traefik-public:
external: true

Save the file and close it.

Now, start the Docker container:

docker compose up -d

Once the process is finished, the output should look like this:

root@host:/opt/traefik# docker compose up -d
[+] up 2/2
✔ Container demo-webapp Started 0.9s
✔ Container traefik Started

How does the process work?

When Traefik starts, it reads the Docker labels configured on the container and waits for incoming requests. When you visit https://yourdomain.com, Traefik contacts Let’s Encrypt to request an SSL certificate. Let’s Encrypt then verifies that the domain is correctly pointing to your server, and after successful validation, the certificate is issued and stored by Traefik. If everything is configured correctly, the SSL certificate should be generated and available within approximately 30 seconds to 2 minutes.

In Conclusion

That’s it. You successfully installed Docker and configured Traefik as a Reverse proxy with Automatic SSL on Linux.

Of course, you don’t have to install it yourself if you have difficulty and aren’t familiar with Linux. You can always contact our technical support. You only need to sign up for one of our monthly management plans and submit a support ticket. We are available 24/7 and will address your request immediately.

If you liked this post about setting up Traefik as a Reverse proxy with Automatic SSL, please share it with your friends or leave a comment below.

Leave a Comment