Skip to main content

Traefik Role

Deploy the Traefik reverse proxy as a Podman quadlet.


Variables​

VariableTypeOptionsDefaultDescription
podman_userstring---{{ ansible_user }}system user for rootless podman operations
traefik_network_enabledbooltrue, falsetruecreate and manage the podman network
traefik_network_namestring---traefik-internalpodman network name
traefik_bind_ipstring---{{ ansible_facts['default_ipv4']['address'] }}host IP to bind exposed ports to
traefik_unprivileged_port_startinteger---80lowest host port rootless containers may bind
traefik_versionstring---v3.7.11container image version
traefik_autoupdatebooltrue, falsetrueenable podman auto-update for this container
traefik_networkslist of string---[]additional podman networks to join (by role name)
traefik_acme_enabledbooltrue, falsetrueenable ACME/Let's Encrypt certificates
traefik_acme_emailstring---""ACME account email
traefik_acme_ca_serverstring---https://acme-v02.api.letsencrypt.org/directoryACME CA server URL
traefik_acme_challenge_typestring---httpACME challenge type (dns, http, or tls)
traefik_acme_dns_providerstring---cloudflareDNS provider for DNS challenge
traefik_acme_dns_resolverslist of string---[]custom DNS resolvers for DNS challenge
traefik_acme_eab_enabledbooltrue, falsefalseenable external account binding for ACME
traefik_acme_eab_kidstring---""ACME EAB key ID
traefik_acme_eab_hmacstring---""ACME EAB HMAC key
traefik_http_redirect_httpsbooltrue, falsetrueredirect HTTP to HTTPS
traefik_middlewares_redirectdict---{}redirect middleware definitions (path/regex-based)
traefik_custom_middlewaresdict---{}custom traefik middleware definitions
traefik_tcp_entrypointslist of dict---[]TCP entrypoint definitions
traefik_http_serviceslist of dict---[]HTTP service/router definitions
traefik_tcp_serviceslist of dict---[]TCP service/router definitions
traefik_extra_fileslist of dict---[]arbitrary file entries with src (controller path) or source (target path), dest, optional mount, mode, and template
traefik_extra_dirslist of dict---[]arbitrary directory entries with src (controller directory) or source (target path), dest, optional mount and mode
traefik_entrypointstring---""optional container entrypoint override
traefik_proxy_enabledbooltrue, falsefalseenable HTTP proxy for image pulls
traefik_proxy_httpstring---""HTTP proxy URL
traefik_proxy_httpsstring---""HTTPS proxy URL
traefik_proxy_no_proxystring---""comma-separated list of proxy exclusions
traefik_proxy_envlist of string---[]generated proxy environment entries
traefik_network_driverstring---bridgepodman network driver
traefik_http_internal_portinteger---80internal HTTP entrypoint port
traefik_https_internal_portinteger---443internal HTTPS entrypoint port
traefik_environment_varsdict---{}extra environment variables for the container
traefik_log_levelstring---WARNtraefik log level
traefik_log_formatstring---jsontraefik log format
traefik_access_log_formatstring---jsonaccess log format
traefik_access_log_buffer_sizeinteger---10access log channel buffer size
traefik_metrics_enabledbooltrue, falsetrueenable Prometheus metrics endpoint
traefik_metrics_internal_portinteger---8082Prometheus metrics port inside the container
traefik_metrics_bind_ipstring---127.0.0.1bind IP for metrics endpoint
traefik_transport_timeouts_enabledbooltrue, falsefalseenable custom transport timeouts
traefik_transport_read_timeoutstring---12htransport read timeout (e.g. 12h)
traefik_transport_write_timeoutstring---12htransport write timeout (e.g. 12h)
traefik_transport_idle_timeoutstring---3mtransport idle timeout (e.g. 3m)
traefik_http3_enabledbooltrue, falsetrueenable HTTP/3 (QUIC)
traefik_http3_advertised_portinteger---443HTTP/3 advertised port