Overview
Traefik dashboard
The Traefik web dashboard, served on port 80 behind an HTTP Basic authentication middleware, showing the entrypoints, routers and services overview.
Traefik dashboard
Traefik HTTP routers
Traefik HTTP services
This is a repackaged open source software product wherein additional charges apply for cloudimg support services.
Overview Traefik Proxy is a modern, cloud-native reverse proxy and load balancer that makes publishing services simple. It discovers your services through file, Docker, Kubernetes and other providers, routes traffic with expressive rule matchers, terminates TLS and obtains certificates automatically from Let's Encrypt. This image delivers Traefik Proxy fully installed and configured as a system service, with a secured dashboard, the file provider watching a dynamic config directory and an ACME certificate resolver ready, so a production-grade edge router is running within minutes of launch.
Application Stack The Traefik static binary installed under /usr/local/bin and run by a dedicated unprivileged service account that is granted only the capability to bind privileged ports. A systemd service that starts Traefik on boot and restarts it on failure. The static configuration, the dynamic configuration directory and the Let's Encrypt certificate store on a dedicated data disk so configuration and certificates are independently resizable and survive instance replacement.
Reverse Proxy And Load Balancer The web entrypoint listens on port 80 and the websecure entrypoint on port 443. Drop router and middleware definitions into the watched dynamic config directory and Traefik hot-reloads them with no restart. Define backends, weighted load balancing, health checks, sticky sessions, rate limiting, headers, redirects, circuit breakers and more. An automatic Let's Encrypt certificate resolver is pre-configured so HTTPS is one DNS record and one router rule away.
Secure First Boot The Traefik dashboard ships with no authentication, so it is never exposed unprotected. The dashboard and API are published only through a router protected by an HTTP Basic authentication middleware. On the first boot of your instance a one-shot service generates a fresh dashboard password, unique to that instance, writes the bcrypt-hashed credential into the dynamic config and writes the password to a root-only file. No shared or default credentials ship in the image.
Ready To Use The dashboard is served on port 80 under the /dashboard path. Sign in with the generated administrator credentials to inspect routers, services, middlewares, entrypoints and TLS certificates in real time. Point a DNS record at the instance, add a router for your backend in the dynamic config directory and Traefik routes and secures it.
cloudimg Support 24/7 technical support by email and chat. Help with deployment, router and middleware configuration, provider setup, automatic TLS and Let's Encrypt, load balancing strategies, and edge hardening.
Use Cases An edge router and reverse proxy in front of web applications and APIs. Automatic HTTPS with Let's Encrypt. A load balancer across multiple backend instances. A single ingress point for microservices. TLS termination and HTTP to HTTPS redirection.
All product and company names are trademarks or registered trademarks of their respective holders. Use of them does not imply any affiliation with or endorsement by them.
Highlights
- Traefik Proxy preinstalled as a systemd service with the web (port 80) and websecure (port 443) entrypoints, the file provider watching a hot-reloading dynamic config directory and a Let's Encrypt certificate resolver pre-configured, no manual setup required
- The dashboard and API are published behind an HTTP Basic authentication middleware with the static config, dynamic config and ACME certificate store on a dedicated independently resizable data disk
- Hardened first boot generates a fresh dashboard password for every instance and stores the bcrypt-hashed credential in the dynamic config and the plaintext in a file only the root user can read, with 24/7 technical support from cloudimg
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Financing for AWS Marketplace purchases
Pricing
Free trial
- ...
Dimension | Description | Cost/hour |
|---|---|---|
t3.medium Recommended | t3.medium | $0.04 |
t2.micro | t2.micro instance type | $0.04 |
t3.micro | t3.micro instance type | $0.04 |
p4de.24xlarge | p4de.24xlarge instance type | $0.24 |
i7ie.18xlarge | i7ie.18xlarge instance type | $0.24 |
m6id.12xlarge | m6id.12xlarge instance type | $0.24 |
r8i-flex.xlarge | r8i-flex.xlarge instance type | $0.12 |
r5d.large | r5d.large instance type | $0.08 |
r5d.8xlarge | r5d.8xlarge instance type | $0.24 |
r8idb.8xlarge | r8idb.8xlarge instance type | $0.24 |
Vendor refund policy
Refunds available on request.
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
64-bit (x86) Amazon Machine Image (AMI)
Amazon Machine Image (AMI)
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
Initial release of Traefik Proxy 3.7.5 reverse proxy and load balancer.
Additional details
Usage instructions
Connect via SSH on port 22 as the default login user for your operating system variant (the user guide lists it per variant). The dashboard is served on port 80: browse to http://<instance-public-ip>/dashboard/ and sign in with user admin and the generated password. Retrieve the credentials with: sudo cat /root/traefik-credentials.txt. The web entrypoint (port 80) and websecure entrypoint (port 443) carry your proxied traffic. Define routers, services and middlewares by dropping YAML files into the watched dynamic config directory at /etc/traefik/dynamic/ (Traefik hot-reloads them); the static config is /etc/traefik/traefik.yml. To enable automatic HTTPS, point a DNS record at the instance and attach the pre-configured letsencrypt certificate resolver to a router. The configuration and the Let's Encrypt certificate store live on a dedicated data disk mounted at /etc/traefik.
Resources
Vendor resources
Support
Vendor support
cloudimg provides 24/7 technical support for this product by email and live chat. Our engineers help with deployment, configuration, updates, performance tuning and troubleshooting; critical issues receive a one hour average response. Contact support@cloudimg.co.uk .
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Similar products
