Traefik Role
Deploy the Traefik reverse proxy as a Podman quadlet.
Variables
| Variable | Type | Options | Default | Description |
|---|---|---|---|---|
podman_user | string | --- | {{ ansible_user }} | system user for rootless podman operations |
traefik_network_enabled | bool | true, false | true | create and manage the podman network |
traefik_network_name | string | --- | traefik-internal | podman network name |
traefik_bind_ip | string | --- | {{ ansible_facts['default_ipv4']['address'] }} | host IP to bind exposed ports to |
traefik_unprivileged_port_start | integer | --- | 80 | lowest host port rootless containers may bind |
traefik_version | string | --- | v3.7.11 | container image version |
traefik_autoupdate | bool | true, false | true | enable podman auto-update for this container |
traefik_networks | list of string | --- | [] | additional podman networks to join (by role name) |
traefik_acme_enabled | bool | true, false | true | enable ACME/Let's Encrypt certificates |
traefik_acme_email | string | --- | "" | ACME account email |
traefik_acme_ca_server | string | --- | https://acme-v02.api.letsencrypt.org/directory | ACME CA server URL |
traefik_acme_challenge_type | string | --- | http | ACME challenge type (dns, http, or tls) |
traefik_acme_dns_provider | string | --- | cloudflare | DNS provider for DNS challenge |
traefik_acme_dns_resolvers | list of string | --- | [] | custom DNS resolvers for DNS challenge |
traefik_acme_eab_enabled | bool | true, false | false | enable external account binding for ACME |
traefik_acme_eab_kid | string | --- | "" | ACME EAB key ID |
traefik_acme_eab_hmac | string | --- | "" | ACME EAB HMAC key |
traefik_http_redirect_https | bool | true, false | true | redirect HTTP to HTTPS |
traefik_middlewares_redirect | dict | --- | {} | redirect middleware definitions (path/regex-based) |
traefik_custom_middlewares | dict | --- | {} | custom traefik middleware definitions |
traefik_tcp_entrypoints | list of dict | --- | [] | TCP entrypoint definitions |
traefik_http_services | list of dict | --- | [] | HTTP service/router definitions |
traefik_tcp_services | list of dict | --- | [] | TCP service/router definitions |
traefik_extra_files | list of dict | --- | [] | arbitrary file entries with src (controller path) or source (target path), dest, optional mount, mode, and template |
traefik_extra_dirs | list of dict | --- | [] | arbitrary directory entries with src (controller directory) or source (target path), dest, optional mount and mode |
traefik_entrypoint | string | --- | "" | optional container entrypoint override |
traefik_proxy_enabled | bool | true, false | false | enable HTTP proxy for image pulls |
traefik_proxy_http | string | --- | "" | HTTP proxy URL |
traefik_proxy_https | string | --- | "" | HTTPS proxy URL |
traefik_proxy_no_proxy | string | --- | "" | comma-separated list of proxy exclusions |
traefik_proxy_env | list of string | --- | [] | generated proxy environment entries |
traefik_network_driver | string | --- | bridge | podman network driver |
traefik_http_internal_port | integer | --- | 80 | internal HTTP entrypoint port |
traefik_https_internal_port | integer | --- | 443 | internal HTTPS entrypoint port |
traefik_environment_vars | dict | --- | {} | extra environment variables for the container |
traefik_log_level | string | --- | WARN | traefik log level |
traefik_log_format | string | --- | json | traefik log format |
traefik_access_log_format | string | --- | json | access log format |
traefik_access_log_buffer_size | integer | --- | 10 | access log channel buffer size |
traefik_metrics_enabled | bool | true, false | true | enable Prometheus metrics endpoint |
traefik_metrics_internal_port | integer | --- | 8082 | Prometheus metrics port inside the container |
traefik_metrics_bind_ip | string | --- | 127.0.0.1 | bind IP for metrics endpoint |
traefik_transport_timeouts_enabled | bool | true, false | false | enable custom transport timeouts |
traefik_transport_read_timeout | string | --- | 12h | transport read timeout (e.g. 12h) |
traefik_transport_write_timeout | string | --- | 12h | transport write timeout (e.g. 12h) |
traefik_transport_idle_timeout | string | --- | 3m | transport idle timeout (e.g. 3m) |
traefik_http3_enabled | bool | true, false | true | enable HTTP/3 (QUIC) |
traefik_http3_advertised_port | integer | --- | 443 | HTTP/3 advertised port |