readystack/traefik:v3.7.13-CE-ubuntu24.04-r1
A hardened, cosign-signed, offline-rebuildable build of github.com/traefik/traefik v3.7.13 (MIT), built clean-room from official upstream source by ReadyStack.
cosign verify --key https://readystack.dev/keys/cosign.pub --insecure-ignore-tlog=true readystack/traefik:v3.7.13-CE-ubuntu24.04-r1.This image follows the ReadyStack release-tag convention:
The current release is v3.7.13-CE-ubuntu24.04-r1 — the release on sale at readystack.dev. Release tags use the pattern <upstream-version>-CE-<base-os>-r<N>; the current one is hermetically built, signed, attested, and supported under your ReadyStack agreement.
Earlier release tags (an older version or revision in the same pattern) are superseded. They stay pullable so existing deployments can pin them, but they are no longer patched or re-graded: move to the current release. A superseded release's build kit is available through support.
Any tag beginning with internal- is an engineering-pipeline artifact published for build observability. It is unsupported, may change or disappear without notice, and must not be used in production.
# ✓ current release
docker pull readystack/traefik:v3.7.13-CE-ubuntu24.04-r1
# ✗ unsupported (do not pull)
docker pull readystack/traefik:internal-...
Each release tag is signed; verify with cosign verify --key https://readystack.dev/keys/cosign.pub --insecure-ignore-tlog=true readystack/traefik:v3.7.13-CE-ubuntu24.04-r1 (ReadyStack keeps signatures off the public transparency log, so the check is key-only). Support: [email protected].
Single container, single static binary, foreground process. No relational database, no user accounts. Only the FILE provider is enabled by default (--providers.file.filename=/etc/traefik/traefik-dynamic.yml, baked into the image's ENTRYPOINT; the shipped file is an empty configuration, {}); the docker, kubernetes and other providers are off until you add their flag as an extra command-line argument (see Docker provider in the handbooks). Mounting /var/run/docker.sock by itself changes nothing (tested).
docker run -d --name traefik -p 80:80 -p 443:443 -p 127.0.0.1:8080:8080 readystack/traefik:v3.7.13-CE-ubuntu24.04-r1
Starts Traefik in the foreground as PID 1. Port 80 is the web entrypoint, 443 is websecure, and 8080 carries the REST API and dashboard together — published to 127.0.0.1 only here because that API has no authentication at all (see Administrator password in the handbooks). GET http://127.0.0.1:8080/ping answered 200 OK about 1-2 seconds after start in testing. The baked dynamic-config file is an empty configuration ({}), so nothing is actually routed until you add configuration (see File provider or Docker provider in the handbooks). The archive ships no Compose file.
The complete --network=none build kit to recreate this exact image yourself — plus admin/DB/API handbooks, the build's validation records, and signed provenance — is at readystack.dev/buy.html.
— ReadyStack · readystack.dev
Content type
Image
Digest
sha256:dbfb364ab…
Size
166.7 MB
Last updated
15 minutes ago
docker pull readystack/traefik:v3.7.13-CE-ubuntu24.04-r1