{"id":5020,"date":"2026-09-29T08:00:00","date_gmt":"2026-09-29T08:00:00","guid":{"rendered":"https:\/\/netguide.io\/linux\/?p=5020"},"modified":"2026-09-29T08:00:00","modified_gmt":"2026-09-29T08:00:00","slug":"traefik-reverse-proxy-docker-einrichten","status":"publish","type":"post","link":"https:\/\/netguide.io\/linux\/de\/traefik-reverse-proxy-docker-einrichten\/","title":{"rendered":"Traefik als Reverse Proxy mit Docker einrichten"},"content":{"rendered":"<script type=\"text\/plain\" data-tcf=\"waiting-for-consent\" data-id=\"4797\" data-bid=\"2\" data-placement=\"4798\">PGRpdiBpZD0ibmV0Z3VpZGVhLTE4OTM4NjE2NjEiIGNsYXNzPSJuZXRndWlkZWEtYmVmb3JlLWNvbnRlbnQgbmV0Z3VpZGVhLWVudGl0eS1wbGFjZW1lbnQiPjxkaXYgY2xhc3M9Im5ldGd1aWRlYS1hZGxhYmVsIj5BZHZlcnRpc2VtZW50czwvZGl2PjxzY3JpcHQgYXN5bmMgc3JjPSIvL3BhZ2VhZDIuZ29vZ2xlc3luZGljYXRpb24uY29tL3BhZ2VhZC9qcy9hZHNieWdvb2dsZS5qcz9jbGllbnQ9Y2EtcHViLTYyNTg1NTYyNTcyNDU5OTgiIGNyb3Nzb3JpZ2luPSJhbm9ueW1vdXMiPjwvc2NyaXB0PjxpbnMgY2xhc3M9ImFkc2J5Z29vZ2xlIiBzdHlsZT0iZGlzcGxheTpibG9jazsiIGRhdGEtYWQtY2xpZW50PSJjYS1wdWItNjI1ODU1NjI1NzI0NTk5OCIgCmRhdGEtYWQtc2xvdD0iMzQ5NDExNTM0MiIgCmRhdGEtYWQtZm9ybWF0PSJhdXRvIj48L2lucz4KPHNjcmlwdD4gCihhZHNieWdvb2dsZSA9IHdpbmRvdy5hZHNieWdvb2dsZSB8fCBbXSkucHVzaCh7fSk7IAo8L3NjcmlwdD4KPC9kaXY+<\/script>\n<p class=\"wp-block-paragraph\">Wer mehrere Docker-Dienste unter eigenen Domains erreichbar machen will, braucht einen Reverse Proxy. Traefik ist daf\u00fcr besonders beliebt, weil er neue Container <strong>automatisch erkennt<\/strong> und HTTPS-Zertifikate von selbst besorgt. In dieser ausf\u00fchrlichen Anleitung richtest du <strong>Traefik als Reverse Proxy mit Docker<\/strong> ein \u2013 inklusive automatischer Service-Erkennung \u00fcber Labels und kostenlosem HTTPS per Let\u2019s Encrypt.<\/p>\n\n\n\t\t\t\t<div class=\"wp-block-uagb-table-of-contents uagb-toc__align-left uagb-toc__columns-1  uagb-block-1ffd1ad5      \"\n\t\t\t\t\tdata-scroll= \"1\"\n\t\t\t\t\tdata-offset= \"30\"\n\t\t\t\t\tstyle=\"\"\n\t\t\t\t>\n\t\t\t\t<div class=\"uagb-toc__wrap\">\n\t\t\t\t\t\t<div class=\"uagb-toc__title\">\n\t\t\t\t\t\t\tInhaltsverzeichnis\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<div class=\"uagb-toc__list-wrap \">\n\t\t\t\t\t\t<ol class=\"uagb-toc__list\"><li class=\"uagb-toc__list\"><a href=\"#was-ist-traefik-und-warum-eignet-es-sich-f\u00fcr-docker\" class=\"uagb-toc-link__trigger\">Was ist Traefik \u2013 und warum eignet es sich f\u00fcr Docker?<\/a><li class=\"uagb-toc__list\"><a href=\"#voraussetzungen\" class=\"uagb-toc-link__trigger\">Voraussetzungen<\/a><li class=\"uagb-toc__list\"><a href=\"#schritt-1-das-traefik-grundger\u00fcst-per-compose\" class=\"uagb-toc-link__trigger\">Schritt 1: Das Traefik-Grundger\u00fcst per Compose<\/a><li class=\"uagb-toc__list\"><a href=\"#schritt-2-einen-dienst-\u00fcber-labels-anbinden\" class=\"uagb-toc-link__trigger\">Schritt 2: Einen Dienst \u00fcber Labels anbinden<\/a><li class=\"uagb-toc__list\"><a href=\"#schritt-3-http-automatisch-auf-https-umleiten\" class=\"uagb-toc-link__trigger\">Schritt 3: HTTP automatisch auf HTTPS umleiten<\/a><li class=\"uagb-toc__list\"><a href=\"#traefik-im-vergleich-zu-anderen-reverse-proxys\" class=\"uagb-toc-link__trigger\">Traefik im Vergleich zu anderen Reverse Proxys<\/a><li class=\"uagb-toc__list\"><a href=\"#das-traefik-dashboard\" class=\"uagb-toc-link__trigger\">Das Traefik-Dashboard<\/a><li class=\"uagb-toc__list\"><a href=\"#middlewares-zugriffsschutz-und-mehr\" class=\"uagb-toc-link__trigger\">Middlewares: Zugriffsschutz und mehr<\/a><li class=\"uagb-toc__list\"><a href=\"#h\u00e4ufige-fragen-zu-traefik\" class=\"uagb-toc-link__trigger\">H\u00e4ufige Fragen zu Traefik<\/a><li class=\"uagb-toc__list\"><a href=\"#warum-bekomme-ich-kein-https-zertifikat\" class=\"uagb-toc-link__trigger\">Warum bekomme ich kein HTTPS-Zertifikat?<\/a><li class=\"uagb-toc__list\"><a href=\"#muss-ich-traefik-neu-starten-wenn-ich-einen-dienst-hinzuf\u00fcge\" class=\"uagb-toc-link__trigger\">Muss ich Traefik neu starten, wenn ich einen Dienst hinzuf\u00fcge?<\/a><li class=\"uagb-toc__list\"><a href=\"#ist-traefik-f\u00fcr-anf\u00e4nger-geeignet\" class=\"uagb-toc-link__trigger\">Ist Traefik f\u00fcr Anf\u00e4nger geeignet?<\/a><li class=\"uagb-toc__list\"><a href=\"#fazit\" class=\"uagb-toc-link__trigger\">Fazit<\/a><\/ol>\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Was ist Traefik \u2013 und warum eignet es sich f\u00fcr Docker?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Traefik ist ein moderner, cloud-nativer Reverse Proxy und Load Balancer. Sein gr\u00f6\u00dfter Vorteil gegen\u00fcber klassischen L\u00f6sungen: Er liest die Docker-Labels deiner Container aus und konfiguriert Routen dadurch <strong>dynamisch zur Laufzeit<\/strong>. Startest du einen neuen Container mit den passenden Labels, ist er sofort erreichbar \u2013 ohne dass du eine Konfigurationsdatei anfassen musst. Das macht Traefik ideal f\u00fcr Setups, die h\u00e4ufig wachsen. Die Docker-Grundlagen dazu findest du in <a href=\"https:\/\/netguide.io\/linux\/de\/docker-compose-installieren-ubuntu-debian\/\">Docker Compose installieren<\/a>.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">Voraussetzungen<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Docker und Docker Compose<\/strong> auf dem Server.<\/li>\n\n\n\n<li><strong>Eine Domain,<\/strong> deren DNS auf deinen Server zeigt.<\/li>\n\n\n\n<li><strong>Offene Ports 80 und 443<\/strong> in der <a href=\"https:\/\/netguide.io\/linux\/de\/ufw-firewall-einrichten-linux\/\">Firewall<\/a>, damit Let\u2019s Encrypt Zertifikate ausstellen kann.<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">Schritt 1: Das Traefik-Grundger\u00fcst per Compose<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Lege eine <code>docker-compose.yml<\/code> an. Traefik l\u00e4uft selbst als Container und bekommt Zugriff auf den Docker-Socket, um andere Container zu erkennen:<\/p>\n\n\n\n<div class=\"wp-block-kevinbatdorf-code-block-pro\" data-code-block-pro-font-family=\"Code-Pro-JetBrains-Mono\" style=\"font-size:.875rem;font-family:Code-Pro-JetBrains-Mono,ui-monospace,SFMono-Regular,Menlo,Monaco,Consolas,monospace;line-height:1.25rem;--cbp-tab-width:2;tab-size:var(--cbp-tab-width, 2)\"><span style=\"display:block;padding:16px 0 0 16px;margin-bottom:-1px;width:100%;text-align:left;background-color:#24292e\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"54\" height=\"14\" viewBox=\"0 0 54 14\"><g fill=\"none\" fill-rule=\"evenodd\" transform=\"translate(1 1)\"><circle cx=\"6\" cy=\"6\" r=\"6\" fill=\"#FF5F56\" stroke=\"#E0443E\" stroke-width=\".5\"><\/circle><circle cx=\"26\" cy=\"6\" r=\"6\" fill=\"#FFBD2E\" stroke=\"#DEA123\" stroke-width=\".5\"><\/circle><circle cx=\"46\" cy=\"6\" r=\"6\" fill=\"#27C93F\" stroke=\"#1AAB29\" stroke-width=\".5\"><\/circle><\/g><\/svg><\/span><span role=\"button\" tabindex=\"0\" style=\"color:#e1e4e8;display:none\" aria-label=\"Copy\" class=\"code-block-pro-copy-button\"><pre class=\"code-block-pro-copy-button-pre\" aria-hidden=\"true\"><textarea class=\"code-block-pro-copy-button-textarea\" tabindex=\"-1\" aria-hidden=\"true\" readonly>services:\n  traefik:\n    image: traefik:v3.1\n    container_name: traefik\n    restart: unless-stopped\n    command:\n      - \"--providers.docker=true\"\n      - \"--providers.docker.exposedbydefault=false\"\n      - \"--entrypoints.web.address=:80\"\n      - \"--entrypoints.websecure.address=:443\"\n      - \"--certificatesresolvers.le.acme.email=mail@example.de\"\n      - \"--certificatesresolvers.le.acme.storage=\/letsencrypt\/acme.json\"\n      - \"--certificatesresolvers.le.acme.httpchallenge.entrypoint=web\"\n    ports:\n      - \"80:80\"\n      - \"443:443\"\n    volumes:\n      - \/var\/run\/docker.sock:\/var\/run\/docker.sock:ro\n      - .\/letsencrypt:\/letsencrypt<\/textarea><\/pre><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" style=\"width:24px;height:24px\" fill=\"none\" viewBox=\"0 0 24 24\" stroke=\"currentColor\" stroke-width=\"2\"><path class=\"with-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2m-6 9l2 2 4-4\"><\/path><path class=\"without-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2\"><\/path><\/svg><\/span><pre class=\"shiki github-dark\" style=\"background-color: #24292e\" tabindex=\"0\"><code><span class=\"line\"><span style=\"color: #85E89D\">services<\/span><span style=\"color: #E1E4E8\">:<\/span><\/span>\n<span class=\"line\"><span style=\"color: #85E89D\">  traefik<\/span><span style=\"color: #E1E4E8\">:<\/span><\/span>\n<span class=\"line\"><span style=\"color: #85E89D\">    image<\/span><span style=\"color: #E1E4E8\">: <\/span><span style=\"color: #9ECBFF\">traefik:v3.1<\/span><\/span>\n<span class=\"line\"><span style=\"color: #85E89D\">    container_name<\/span><span style=\"color: #E1E4E8\">: <\/span><span style=\"color: #9ECBFF\">traefik<\/span><\/span>\n<span class=\"line\"><span style=\"color: #85E89D\">    restart<\/span><span style=\"color: #E1E4E8\">: <\/span><span style=\"color: #9ECBFF\">unless-stopped<\/span><\/span>\n<span class=\"line\"><span style=\"color: #85E89D\">    command<\/span><span style=\"color: #E1E4E8\">:<\/span><\/span>\n<span class=\"line\"><span style=\"color: #E1E4E8\">      - <\/span><span style=\"color: #9ECBFF\">\"--providers.docker=true\"<\/span><\/span>\n<span class=\"line\"><span style=\"color: #E1E4E8\">      - <\/span><span style=\"color: #9ECBFF\">\"--providers.docker.exposedbydefault=false\"<\/span><\/span>\n<span class=\"line\"><span style=\"color: #E1E4E8\">      - <\/span><span style=\"color: #9ECBFF\">\"--entrypoints.web.address=:80\"<\/span><\/span>\n<span class=\"line\"><span style=\"color: #E1E4E8\">      - <\/span><span style=\"color: #9ECBFF\">\"--entrypoints.websecure.address=:443\"<\/span><\/span>\n<span class=\"line\"><span style=\"color: #E1E4E8\">      - <\/span><span style=\"color: #9ECBFF\">\"--certificatesresolvers.le.acme.email=mail@example.de\"<\/span><\/span>\n<span class=\"line\"><span style=\"color: #E1E4E8\">      - <\/span><span style=\"color: #9ECBFF\">\"--certificatesresolvers.le.acme.storage=\/letsencrypt\/acme.json\"<\/span><\/span>\n<span class=\"line\"><span style=\"color: #E1E4E8\">      - <\/span><span style=\"color: #9ECBFF\">\"--certificatesresolvers.le.acme.httpchallenge.entrypoint=web\"<\/span><\/span>\n<span class=\"line\"><span style=\"color: #85E89D\">    ports<\/span><span style=\"color: #E1E4E8\">:<\/span><\/span>\n<span class=\"line\"><span style=\"color: #E1E4E8\">      - <\/span><span style=\"color: #9ECBFF\">\"80:80\"<\/span><\/span>\n<span class=\"line\"><span style=\"color: #E1E4E8\">      - <\/span><span style=\"color: #9ECBFF\">\"443:443\"<\/span><\/span>\n<span class=\"line\"><span style=\"color: #85E89D\">    volumes<\/span><span style=\"color: #E1E4E8\">:<\/span><\/span>\n<span class=\"line\"><span style=\"color: #E1E4E8\">      - <\/span><span style=\"color: #9ECBFF\">\/var\/run\/docker.sock:\/var\/run\/docker.sock:ro<\/span><\/span>\n<span class=\"line\"><span style=\"color: #E1E4E8\">      - <\/span><span style=\"color: #9ECBFF\">.\/letsencrypt:\/letsencrypt<\/span><\/span><\/code><\/pre><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">Die Option <code>exposedbydefault=false<\/code> ist ein wichtiger Sicherheitsschalter: Nur Container, die du ausdr\u00fccklich mit Labels markierst, werden ver\u00f6ffentlicht.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">Schritt 2: Einen Dienst \u00fcber Labels anbinden<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Jetzt kommt der Clou: Einen beliebigen Container machst du erreichbar, indem du ihm die passenden Traefik-Labels gibst. Beispiel f\u00fcr einen einfachen Webdienst:<\/p>\n\n\n\n<div class=\"wp-block-kevinbatdorf-code-block-pro\" data-code-block-pro-font-family=\"Code-Pro-JetBrains-Mono\" style=\"font-size:.875rem;font-family:Code-Pro-JetBrains-Mono,ui-monospace,SFMono-Regular,Menlo,Monaco,Consolas,monospace;line-height:1.25rem;--cbp-tab-width:2;tab-size:var(--cbp-tab-width, 2)\"><span style=\"display:block;padding:16px 0 0 16px;margin-bottom:-1px;width:100%;text-align:left;background-color:#24292e\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"54\" height=\"14\" viewBox=\"0 0 54 14\"><g fill=\"none\" fill-rule=\"evenodd\" transform=\"translate(1 1)\"><circle cx=\"6\" cy=\"6\" r=\"6\" fill=\"#FF5F56\" stroke=\"#E0443E\" stroke-width=\".5\"><\/circle><circle cx=\"26\" cy=\"6\" r=\"6\" fill=\"#FFBD2E\" stroke=\"#DEA123\" stroke-width=\".5\"><\/circle><circle cx=\"46\" cy=\"6\" r=\"6\" fill=\"#27C93F\" stroke=\"#1AAB29\" stroke-width=\".5\"><\/circle><\/g><\/svg><\/span><span role=\"button\" tabindex=\"0\" style=\"color:#e1e4e8;display:none\" aria-label=\"Copy\" class=\"code-block-pro-copy-button\"><pre class=\"code-block-pro-copy-button-pre\" aria-hidden=\"true\"><textarea class=\"code-block-pro-copy-button-textarea\" tabindex=\"-1\" aria-hidden=\"true\" readonly>services:\n  whoami:\n    image: traefik\/whoami\n    container_name: whoami\n    restart: unless-stopped\n    labels:\n      - \"traefik.enable=true\"\n      - \"traefik.http.routers.whoami.rule=Host(`app.example.de`)\"\n      - \"traefik.http.routers.whoami.entrypoints=websecure\"\n      - \"traefik.http.routers.whoami.tls.certresolver=le\"<\/textarea><\/pre><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" style=\"width:24px;height:24px\" fill=\"none\" viewBox=\"0 0 24 24\" stroke=\"currentColor\" stroke-width=\"2\"><path class=\"with-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2m-6 9l2 2 4-4\"><\/path><path class=\"without-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2\"><\/path><\/svg><\/span><pre class=\"shiki github-dark\" style=\"background-color: #24292e\" tabindex=\"0\"><code><span class=\"line\"><span style=\"color: #85E89D\">services<\/span><span style=\"color: #E1E4E8\">:<\/span><\/span>\n<span class=\"line\"><span style=\"color: #85E89D\">  whoami<\/span><span style=\"color: #E1E4E8\">:<\/span><\/span>\n<span class=\"line\"><span style=\"color: #85E89D\">    image<\/span><span style=\"color: #E1E4E8\">: <\/span><span style=\"color: #9ECBFF\">traefik\/whoami<\/span><\/span>\n<span class=\"line\"><span style=\"color: #85E89D\">    container_name<\/span><span style=\"color: #E1E4E8\">: <\/span><span style=\"color: #9ECBFF\">whoami<\/span><\/span>\n<span class=\"line\"><span style=\"color: #85E89D\">    restart<\/span><span style=\"color: #E1E4E8\">: <\/span><span style=\"color: #9ECBFF\">unless-stopped<\/span><\/span>\n<span class=\"line\"><span style=\"color: #85E89D\">    labels<\/span><span style=\"color: #E1E4E8\">:<\/span><\/span>\n<span class=\"line\"><span style=\"color: #E1E4E8\">      - <\/span><span style=\"color: #9ECBFF\">\"traefik.enable=true\"<\/span><\/span>\n<span class=\"line\"><span style=\"color: #E1E4E8\">      - <\/span><span style=\"color: #9ECBFF\">\"traefik.http.routers.whoami.rule=Host(`app.example.de`)\"<\/span><\/span>\n<span class=\"line\"><span style=\"color: #E1E4E8\">      - <\/span><span style=\"color: #9ECBFF\">\"traefik.http.routers.whoami.entrypoints=websecure\"<\/span><\/span>\n<span class=\"line\"><span style=\"color: #E1E4E8\">      - <\/span><span style=\"color: #9ECBFF\">\"traefik.http.routers.whoami.tls.certresolver=le\"<\/span><\/span><\/code><\/pre><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">Traefik erkennt den Container, richtet die Route <code>app.example.de<\/code> ein und besorgt automatisch ein g\u00fcltiges HTTPS-Zertifikat. Mehr zur Container-Kommunikation erkl\u00e4rt <a href=\"https:\/\/netguide.io\/linux\/de\/docker-netzwerke-erklaert\/\">Docker Netzwerke erkl\u00e4rt<\/a>.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">Schritt 3: HTTP automatisch auf HTTPS umleiten<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Damit niemand versehentlich unverschl\u00fcsselt zugreift, leitest du den gesamten HTTP-Verkehr auf HTTPS um. Erg\u00e4nze dazu im <code>command<\/code>-Block von Traefik:<\/p>\n\n\n\n<div class=\"wp-block-kevinbatdorf-code-block-pro\" data-code-block-pro-font-family=\"Code-Pro-JetBrains-Mono\" style=\"font-size:.875rem;font-family:Code-Pro-JetBrains-Mono,ui-monospace,SFMono-Regular,Menlo,Monaco,Consolas,monospace;line-height:1.25rem;--cbp-tab-width:2;tab-size:var(--cbp-tab-width, 2)\"><span style=\"display:block;padding:16px 0 0 16px;margin-bottom:-1px;width:100%;text-align:left;background-color:#24292e\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"54\" height=\"14\" viewBox=\"0 0 54 14\"><g fill=\"none\" fill-rule=\"evenodd\" transform=\"translate(1 1)\"><circle cx=\"6\" cy=\"6\" r=\"6\" fill=\"#FF5F56\" stroke=\"#E0443E\" stroke-width=\".5\"><\/circle><circle cx=\"26\" cy=\"6\" r=\"6\" fill=\"#FFBD2E\" stroke=\"#DEA123\" stroke-width=\".5\"><\/circle><circle cx=\"46\" cy=\"6\" r=\"6\" fill=\"#27C93F\" stroke=\"#1AAB29\" stroke-width=\".5\"><\/circle><\/g><\/svg><\/span><span role=\"button\" tabindex=\"0\" style=\"color:#e1e4e8;display:none\" aria-label=\"Copy\" class=\"code-block-pro-copy-button\"><pre class=\"code-block-pro-copy-button-pre\" aria-hidden=\"true\"><textarea class=\"code-block-pro-copy-button-textarea\" tabindex=\"-1\" aria-hidden=\"true\" readonly>- \"--entrypoints.web.http.redirections.entrypoint.to=websecure\"\n- \"--entrypoints.web.http.redirections.entrypoint.scheme=https\"<\/textarea><\/pre><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" style=\"width:24px;height:24px\" fill=\"none\" viewBox=\"0 0 24 24\" stroke=\"currentColor\" stroke-width=\"2\"><path class=\"with-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2m-6 9l2 2 4-4\"><\/path><path class=\"without-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2\"><\/path><\/svg><\/span><pre class=\"shiki github-dark\" style=\"background-color: #24292e\" tabindex=\"0\"><code><span class=\"line\"><span style=\"color: #E1E4E8\">- <\/span><span style=\"color: #9ECBFF\">\"--entrypoints.web.http.redirections.entrypoint.to=websecure\"<\/span><\/span>\n<span class=\"line\"><span style=\"color: #E1E4E8\">- <\/span><span style=\"color: #9ECBFF\">\"--entrypoints.web.http.redirections.entrypoint.scheme=https\"<\/span><\/span><\/code><\/pre><\/div>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">Traefik im Vergleich zu anderen Reverse Proxys<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Traefik ist nicht die einzige Option. Welche L\u00f6sung passt, h\u00e4ngt vom Anspruch ab:<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table><thead><tr><th>L\u00f6sung<\/th><th>St\u00e4rke<\/th><th>Ideal f\u00fcr<\/th><\/tr><\/thead><tbody><tr><td><strong>Traefik<\/strong><\/td><td>Automatische Erkennung per Labels<\/td><td>Dynamische Docker-Setups<\/td><\/tr><tr><td><strong>Nginx Proxy Manager<\/strong><\/td><td>Grafische Oberfl\u00e4che<\/td><td>Einsteiger, wenige Dienste<\/td><\/tr><tr><td><strong>Caddy<\/strong><\/td><td>Minimale Textkonfiguration<\/td><td>Schlanke, statische Setups<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Wer lieber eine grafische Oberfl\u00e4che nutzt, greift zum <a href=\"https:\/\/netguide.io\/linux\/de\/mit-dem-nginx-proxy-manager-docker-container-ueber-das-internet-verfuegbar-machen\/\">Nginx Proxy Manager<\/a>. F\u00fcr minimale Konfiguration ist <a href=\"https:\/\/netguide.io\/linux\/de\/caddy-reverse-proxy-https-einrichten\/\">Caddy<\/a> eine Alternative.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">Das Traefik-Dashboard<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Traefik bringt ein Web-Dashboard mit, das alle erkannten Router und Services anzeigt \u2013 praktisch zur Fehlersuche. Aktiviere es mit <code>--api.dashboard=true<\/code> und sichere es unbedingt mit einer Authentifizierung ab, bevor du es \u00f6ffentlich erreichbar machst. Ein ungesch\u00fctztes Dashboard verr\u00e4t Angreifern zu viel \u00fcber deine Infrastruktur.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">Middlewares: Zugriffsschutz und mehr<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Ein starkes Feature von Traefik sind sogenannte <strong>Middlewares<\/strong>. Sie h\u00e4ngen sich zwischen Anfrage und Dienst und erledigen Zusatzaufgaben \u2013 ebenfalls per Label konfiguriert. Besonders n\u00fctzlich sind:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Basic Auth:<\/strong> sch\u00fctzt einen Dienst mit Benutzername und Passwort, bevor er \u00fcberhaupt erreichbar ist.<\/li>\n\n\n\n<li><strong>Rate Limiting:<\/strong> begrenzt die Anfragen pro Zeitraum und bremst so einfache Angriffe aus.<\/li>\n\n\n\n<li><strong>IP-Whitelist:<\/strong> l\u00e4sst nur bestimmte Quell-IPs zu.<\/li>\n\n\n\n<li><strong>Security Headers:<\/strong> setzt sinnvolle HTTP-Header wie HSTS automatisch.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">So sch\u00fctzt du etwa ein sensibles Admin-Panel mit wenigen Labels, ohne den Dienst selbst anzupassen. F\u00fcr einen zus\u00e4tzlichen Schutz auf Netzwerkebene sorgt eine <a href=\"https:\/\/netguide.io\/linux\/de\/ufw-firewall-einrichten-linux\/\">UFW-Firewall<\/a>.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">H\u00e4ufige Fragen zu Traefik<\/h3>\n\n\n\n<h3 class=\"wp-block-heading\">Warum bekomme ich kein HTTPS-Zertifikat?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Die h\u00e4ufigsten Ursachen: Die Domain zeigt nicht auf den Server, Port 80 ist nicht erreichbar (Let\u2019s Encrypt braucht ihn f\u00fcr die HTTP-Challenge) oder die E-Mail-Adresse fehlt. Pr\u00fcfe DNS und Firewall zuerst.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Muss ich Traefik neu starten, wenn ich einen Dienst hinzuf\u00fcge?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Nein. Genau das ist der Vorteil: Traefik erkennt neue Container mit passenden Labels automatisch und richtet die Route zur Laufzeit ein \u2013 ganz ohne Neustart.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Ist Traefik f\u00fcr Anf\u00e4nger geeignet?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Die Label-Logik hat eine gewisse Lernkurve. Wer nur wenige Dienste betreibt und eine Oberfl\u00e4che bevorzugt, startet leichter mit dem Nginx Proxy Manager und wechselt sp\u00e4ter zu Traefik.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">Fazit<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Traefik nimmt dir bei wachsenden Docker-Umgebungen die meiste Arbeit ab: Container erkennen, Routen anlegen, Zertifikate verwalten \u2013 alles automatisch \u00fcber Labels. Nach dem einmaligen Aufsetzen f\u00fcgst du neue Dienste nur noch per Label hinzu. Achte auf die Absicherung des Dashboards und offene Ports 80\/443, dann steht deinem selbst gehosteten Setup nichts im Weg. Passend dazu: <a href=\"https:\/\/netguide.io\/linux\/de\/docker-container-automatisch-aktualisieren-watchtower\/\">Container automatisch aktualisieren<\/a>.<\/p>\n<script type=\"text\/plain\" data-tcf=\"waiting-for-consent\" data-id=\"4799\" data-bid=\"2\" data-placement=\"4800\">PGRpdiBpZD0ibmV0Z3VpZGVhLTMzMjM1OTgyOTYiIGNsYXNzPSJuZXRndWlkZWEtYWZ0ZXItY29udGVudCBuZXRndWlkZWEtZW50aXR5LXBsYWNlbWVudCI+PGRpdiBjbGFzcz0ibmV0Z3VpZGVhLWFkbGFiZWwiPkFkdmVydGlzZW1lbnRzPC9kaXY+PHNjcmlwdCBhc3luYyBzcmM9Ii8vcGFnZWFkMi5nb29nbGVzeW5kaWNhdGlvbi5jb20vcGFnZWFkL2pzL2Fkc2J5Z29vZ2xlLmpzP2NsaWVudD1jYS1wdWItNjI1ODU1NjI1NzI0NTk5OCIgY3Jvc3NvcmlnaW49ImFub255bW91cyI+PC9zY3JpcHQ+PGlucyBjbGFzcz0iYWRzYnlnb29nbGUiIHN0eWxlPSJkaXNwbGF5OmJsb2NrOyIgZGF0YS1hZC1jbGllbnQ9ImNhLXB1Yi02MjU4NTU2MjU3MjQ1OTk4IiAKZGF0YS1hZC1zbG90PSI0NTU5Nzg1MDAyIiAKZGF0YS1hZC1mb3JtYXQ9ImF1dG8iPjwvaW5zPgo8c2NyaXB0PiAKKGFkc2J5Z29vZ2xlID0gd2luZG93LmFkc2J5Z29vZ2xlIHx8IFtdKS5wdXNoKHt9KTsgCjwvc2NyaXB0Pgo8L2Rpdj4=<\/script>","protected":false},"excerpt":{"rendered":"<p>Traefik als Reverse Proxy mit Docker einrichten: automatische Service-Erkennung per Labels, HTTPS mit Let\u2019s Encrypt und ein praxisnahes Compose-Beispiel.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_uag_custom_page_level_css":"","site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[231,9],"tags":[],"class_list":["post-5020","post","type-post","status-publish","format-standard","hentry","category-docker","category-linux"],"uagb_featured_image_src":{"full":false,"thumbnail":false,"medium":false,"medium_large":false,"large":false,"1536x1536":false,"2048x2048":false},"uagb_author_info":{"display_name":"Tobias","author_link":"https:\/\/netguide.io\/linux\/author\/tobias-pries\/"},"uagb_comment_info":0,"uagb_excerpt":"Traefik als Reverse Proxy mit Docker einrichten: automatische Service-Erkennung per Labels, HTTPS mit Let\u2019s Encrypt und ein praxisnahes Compose-Beispiel.","brizy_media":[],"_links":{"self":[{"href":"https:\/\/netguide.io\/linux\/wp-json\/wp\/v2\/posts\/5020","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/netguide.io\/linux\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/netguide.io\/linux\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/netguide.io\/linux\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/netguide.io\/linux\/wp-json\/wp\/v2\/comments?post=5020"}],"version-history":[{"count":1,"href":"https:\/\/netguide.io\/linux\/wp-json\/wp\/v2\/posts\/5020\/revisions"}],"predecessor-version":[{"id":5555,"href":"https:\/\/netguide.io\/linux\/wp-json\/wp\/v2\/posts\/5020\/revisions\/5555"}],"wp:attachment":[{"href":"https:\/\/netguide.io\/linux\/wp-json\/wp\/v2\/media?parent=5020"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/netguide.io\/linux\/wp-json\/wp\/v2\/categories?post=5020"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/netguide.io\/linux\/wp-json\/wp\/v2\/tags?post=5020"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}