# Traefik's provider model: routes from Docker, Kubernetes, ECS, or a file

> Traefik is a Go reverse proxy whose routes are derived from an orchestrator or registry API instead of a hand written route table. That removes route maintenance and adds a privileged client to your control plane. Two things to settle before you adopt it: the API published on port 8080, and a support window that closes on every minor release.

**traefik/traefik** — Traefik is a modern HTTP reverse proxy and load balancer that configures itself automatically by watching orchestrators such as Docker, Kubernetes or Consul.

- Repository: https://github.com/traefik/traefik
- Website: https://traefik.io
- Stars: 64,982 · Forks: 6,206
- Language: Go
- License: MIT
- Published: 2026-08-08 · Updated: 2026-08-18 · Language: en
- Canonical page: https://hysenlabs.com/projects/traefik-traefik

## Traefik's provider model: routes come from Docker, Kubernetes, ECS, or a file

Traefik is a Go reverse proxy and load balancer for teams whose services already sit in an orchestrator. Pointing it at that orchestrator is the only configuration step the project asks for: it listens to the service registry or orchestrator API and generates the routes itself. The overview frames the problem plainly, noting that traditional reverse proxies require you to configure each route that connects paths and subdomains to each microservice, and that in an environment where you add, remove, kill, upgrade or scale services many times a day, keeping that table current becomes tedious.

The design bet is that a route table is derived state rather than authored state. The feature list promises configuration updates with no restarts, and the intro names Docker, Swarm mode, Kubernetes, Consul, Etcd, Rancher v2 and Amazon ECS as components Traefik configures itself against. A file provider exists for the cases where none of those is true, and manual routes are supported next to discovered ones. That split is the thing to understand before choosing it. Routes can arrive from a daemon socket and from a file at the same time, and the README does not document which source wins when the two disagree. Circuit breakers, retry and the load balancing algorithms in the feature list all sit on top of whatever the provider produced, which is why a wrong provider decision shows up as routing behaviour rather than as a startup error.

## Four backends have documentation links, Consul and Nomad sit in go.mod

The Supported backends list links four providers: Docker and Swarm mode, Kubernetes, ECS, and File. The Kubernetes entry points at the CRD provider page rather than an ingress controller page, so the Kubernetes path is expressed as custom resources. Consul and Etcd appear in the intro sentence about existing infrastructure, and the module graph backs that up: go.mod requires github.com/hashicorp/consul/api v1.26.1, github.com/hashicorp/nomad/api, and github.com/coreos/go-systemd/v22 v22.7.0. Provider clients are compiled into the same binary, which is why one artifact covers all of these.

The consequence is uneven. If you run one of the four linked providers, the trail through the documentation is obvious. If you run Consul, Nomad, systemd or plain Docker Compose without Swarm mode, you are reading provider pages that the backend list does not link from here, and a module dependency is your only evidence the code path exists. go.mod also pins the toolchain at go 1.26.0, so building from source fixes your Go version before it fixes anything else. The tree splits into cmd/, internal/, pkg/, integration/, contrib/, docs/, script/ and webui/, which tells you where a provider misbehaviour lives and says nothing about which provider the project considers settled.

## A first run is one sample file and one port mapping

The download section offers three routes: a release binary run against the sample configuration, the official Docker image run against the same sample file, or the source tree. The binary route expects a file named traefik.toml in the working directory, and the sample it points at is traefik.sample.toml in the repository root, with a traefik.sample.yml sitting beside it. Start the proxy and it reads that file:

```bash
./traefik --configFile=traefik.toml
```

The container route publishes two host ports, 80 for traffic and 8080 for the dashboard and API, and mounts the same file at /etc/traefik/traefik.toml:

```bash
docker run -d -p 8080:8080 -p 80:80 -v $PWD/traefik.toml:/etc/traefik/traefik.toml traefik
```

Neither line asks Docker or Kubernetes for anything. The proxy is up with no provider configured, so routes come from the file alone. What you watch for first is a rule appearing for a backend you already ran, then the Web UI on 8080 showing the same routes from the other side. The project's own starting point for a real deployment is the 5-Minute Quickstart under doc.traefik.io/traefik/getting-started/quick-start/, and that page requires Docker, so a bare metal install begins with a config file and not with a service discovery step.

## The Dockerfile exposes 80 and the run command publishes 8080 anyway

The image definition fits on one screen: alpine:3.24, ca-certificates and tzdata from apk, ARG TARGETPLATFORM, a copy of the built binary for that platform, EXPOSE 80, VOLUME ["/tmp"], and ENTRYPOINT ["/traefik"]. Two things follow. The image declares no volume for certificates or ACME account state, so once you switch on the Let's Encrypt support listed in the features, the path where that state persists is your choice of mount, and a path that does not survive container replacement is your renewal problem. And 8080 appears nowhere in the image even though the run command publishes it, which means the dashboard and the REST API reach the host through an ordinary published port with no image level hint about who should be reaching them.

The Web UI section is one sentence long: you can access the simple HTML frontend of Traefik. It does not cover authentication, network restriction, or a way to confirm from outside the host whether the API is reachable. The REST API is listed only as a feature. Decide what is allowed to talk to 8080 before the container lands on a machine with a route to the internet, because the same Traefik that discovered your services will happily publish whichever of them a label marks as routable.

## make binary needs Docker, because the Web UI assets are built in a container

Building from source is not simply invoking the Go compiler. The Makefile's binary target depends on generate-webui, which depends on webui/static/index.html, which calls build-webui-image, which runs a container build against webui/buildx.Dockerfile and then a yarn build:prod inside that image. On a machine with Go 1.26.0 and no Docker, the asset step fails before compilation starts. The commands involved are:

```bash
make generate
make binary
docker build -t traefik-webui -f webui/buildx.Dockerfile webui
```

The generate target runs go generate, which the Makefile describes as producing dynamic and static configuration documentation reference files, so a build also regenerates reference output from the source tree. Two variables catch people out. DOCKER_BUILD_PLATFORMS defaults to linux/amd64,linux/arm64, so any other target needs that variable changed rather than guessed. LINT_EXECUTABLES is misspell shellcheck, and both have to be on PATH before the lint path works. The default target is generate plus binary, and the visible part of the Makefile does not run the integration suite that lives under integration/.

## Support ends when the next minor version ships, and v2 is still receiving patches

Support in Traefik runs one minor version deep. The release cycle says each version is supported until the next one is released, gives 1.1.x supported until 1.2.0 is out as the example, and states that bug fix releases deliver no new features. The release list shows why that matters on a running deployment: v3.7.13 and v2.11.57 were both published on 2026-09-04, and v3.7.12 followed on 2026-08-26. Two major lines took patches on the same day, so a v2 install you inherited is not abandoned, and no release date tells you when it will be.

The upgrade cost lands in two separate places. Anyone crossing from v2 to v3 is pointed at a migration guide for breaking changes, and nothing in the repository states how long v2 keeps taking patches. For everything else, a new provider option or another load balancing algorithm arrives in a minor release that simultaneously ends support for the line you were pinned to. The last push landed on 2026-09-25, so commits are still arriving. The licence identifier is MIT with LICENSE.md at the repository root, and the README does not restate the terms, so what you redistribute inside your container or your binary is governed by that file rather than by the README.

## Where a hand written NGINX route table is the better answer

The alternative worth naming is NGINX, and the difference is architectural rather than a ranking. A file driven proxy parses a route table somebody wrote, validates it and reloads. An orchestrator driven proxy holds a client to a control plane and rebuilds routes whenever that plane changes. Traefik picks the second model: the module requires github.com/docker/cli v29.8.1+incompatible and github.com/docker/go-connections v0.8.1, so the Docker provider speaks to the Docker API rather than reading compose files, and the Kubernetes entry links to a CRD provider. The bill for that choice is permission. The proxy needs credentials and network reach into the control plane, and a component that can enumerate every service can also route to one that was never meant to be public. Traefik's own argument for the trade is that hand maintained routes become tedious when services change many times a day, and that argument holds when they do.

The speed question does not resolve from this repository. Fast appears in the feature list as a bare word, and there is no benchmark table comparing Traefik with NGINX or Caddy anywhere in the tree. Metrics support for Prometheus, Datadog, Statsd and InfluxDB tells you the project expects you to watch a running instance yourself. Measure on your own traffic before treating any ranking as settled.

## Conclusion

Adopt Traefik when your services already sit in Docker, Swarm, Kubernetes or ECS and the route table is the part that keeps rotting, since the file provider, the metrics sinks and the access log formats all assume an orchestrator or a person who keeps a file current. Skip it when you have a handful of static routes, or when you cannot grant API access to your control plane. Check first that your orchestrator is one of the four backends with linked documentation, then read the v2 to v3 migration guide, because v2.11.57 shipped on the same day as v3.7.13 and the old line is still taking patches.

## FAQ

### What is Traefik used for?

Traefik is an HTTP reverse proxy and load balancer that listens to a service registry or orchestrator API and generates the routes to your services. Around that core it adds Let's Encrypt certificates with wildcard support, circuit breakers and retry, metrics output, and access logs in JSON or CLF.

### Why use Traefik instead of NGINX?

The stated reason is that traditional reverse proxies need each route from a path or subdomain to a microservice configured by hand, which becomes tedious when services are added, killed or scaled many times a day. The repository makes no NGINX specific comparison beyond that framing.

### Which is faster, Traefik or NGINX?

That cannot be answered from the project's own documentation. Fast is listed as a feature in one word, and the repository holds no benchmark against NGINX or Caddy, so any ranking comes from your own measurement.

### Is Traefik only for Docker?

No. The Supported backends list names Docker and Swarm mode, Kubernetes, ECS, and File. Consul, Etcd, Rancher v2 and Nomad also appear as integration targets, and go.mod carries their client libraries.

### How do you use the Traefik dashboard?

The dashboard is the HTML frontend of the proxy, and the container run command publishes port 8080 alongside port 80 to reach it. The README does not document how to restrict access to that API, so decide what may talk to 8080 yourself.

### How do you use Traefik in Kubernetes?

The Kubernetes entry in the backends list links to the provider documentation for the CRD based provider, so configuration there is expressed as custom resources rather than as a file. The project's quickstart is Docker only, so no first run command for Kubernetes appears in the README.

## Sources

- [Official documentation](https://traefik.io)
- [Official README](https://github.com/traefik/traefik#readme)
- [Project repository](https://github.com/traefik/traefik)
- [Release notes](https://github.com/traefik/traefik/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/traefik-traefik
