Sign inSign up

djpic/traefik

By djpic

•Updated 5 days ago

Traefik preconfigured to only support TLSv1.2 and 1.3 with only secure ciphers.

Image
Networking
Web servers
1

5.5K

djpic/traefik repository overview

This version of Traefik has TLS1.2+ configured by default with only the secure ciphers. Additionally, there is another option to allow only TLSv1.3.

The ciphers that are enabled with this image by default are:

- TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384
- TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
- TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256
- TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256
- TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305
- TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305

To use the TLSv1.3 option only:

- "traefik.http.routers.router0.tls.options=tlsv13only"

Also, includes predefined middlewares: https-redirect, secure-headers, semi-secure-headers, and compress-content.

https-redirect
This is a simple scheme redirect that can be applied docker containers individually.

secure-headers
Applies the secure recommended response headers.

semi-secure-headers
Applies most secure recommended response headers. Allows manually setting the contentSecurityPolicy header.

compress-content
Allows gzip and compressing return traffic.

Apply these middleware by using @file. For example: https-redirect@file

This image is based on my article posted at Traefik v2 Secure TLS and Header Configuration with Docker Provider⁠.

For the source files used to build this image, visit DjPic, LLC - Docker Traefik Image⁠.

Get notified when my docker images are updated and when new articles are posted to my website by following my twitter @djpic_llc⁠

For any questions please contact me at www.djpic.net⁠

Tag summary

Content type

Image

Digest

sha256:db929fdda…

Size

52.7 MB

Last updated

5 days ago

docker pull djpic/traefik:3.7