Back to articles
Technology Insight

Mastering Traefik v3: Automated Docker Reverse Proxy with Let's Encrypt DNS Challenge

June 3, 2026

Introduction to Modern Traffic Management

In the contemporary landscape of containerized applications and microservices, managing network traffic efficiently is paramount. As software architectures shift from monolithic structures to dynamic, distributed systems, traditional reverse proxies often struggle to keep pace. Manual configuration updates, complex routing tables, and tedious SSL certificate management can quickly become operational bottlenecks.

Enter Traefik v3, a modern, cloud-native HTTP reverse proxy and load balancer designed specifically to deploy microservices with ease. Unlike legacy solutions, Traefik integrates seamlessly with your existing infrastructure components—most notably Docker—to automatically discover services and configure routing on the fly. In this comprehensive guide, we will explore how to configure Traefik v3 as an automated reverse proxy that detects Docker containers dynamically and provisions wildcard SSL certificates using Let's Encrypt via the DNS-01 challenge.

Why Choose Traefik v3?

Traefik v3 introduces several enhancements over its predecessors, including improved performance, native support for HTTP/3, enhanced WebAssembly (Wasm) plugins, and a redesigned internal architecture for better resource utilization. For enterprise environments, it offers distinct advantages:

  • Configuration-Free Operation: Traefik constantly monitors your Docker daemon. When a new container is deployed with specific labels, Traefik automatically creates the necessary routes without requiring a restart.
  • Robust Let's Encrypt Integration: It handles the entire lifecycle of SSL/TLS certificates, including generation, validation, and renewal, completely in the background.
  • The Power of DNS Challenge: While the standard HTTP-01 challenge requires port 80 to be publicly accessible, the DNS-01 challenge verifies domain ownership by creating a temporary TXT record via your DNS provider's API (e.g., Cloudflare). This allows you to secure internal or firewalled services with valid, trusted SSL certificates, including wildcard domains (e.g., *.yourdomain.com).

Prerequisites and Architecture Overview

Before proceeding with the deployment, ensure you have the following prerequisites in place:

  1. A Linux server with Docker and Docker Compose installed.
  2. A registered domain name managed by a supported DNS provider (we will use Cloudflare for this guide).
  3. An API token from your DNS provider with permissions to edit DNS zones.

Security Note: Always restrict access to the Docker socket. Traefik requires access to /var/run/docker.sock to discover containers, so ensure your host security policies are aligned with best practices.

Step 1: Setting Up the Directory Structure

To maintain a clean production environment, we will organize our configuration files within a dedicated directory structure. Connect to your server via SSH and execute the following commands:

mkdir -p /opt/traefik/data
touch /opt/traefik/data/acme.json
chmod 600 /opt/traefik/data/acme.json
touch /opt/traefik/data/traefik.yml

The acme.json file is highly sensitive as it stores your private keys and generated certificates. Setting its permissions to 600 ensures that only the root owner can read and write to it, which is a strict requirement enforced by Traefik.

Step 2: Configuring Traefik v3 (traefik.yml)

Traefik utilizes a static configuration file to define entrypoints, providers, and certificate resolvers. Open the /opt/traefik/data/traefik.yml file and insert the following configuration:

api:
  dashboard: true
  insecure: false

entryPoints:
  web:
    address: ":80"
    http:
      redirections:
        entryPoint:
          to: websecure
          scheme: https

  websecure:
    address: ":443"
    http:
      tls:
        certResolver: cloudflare
        domains:
          - main: "yourdomain.com"
            sans:
              - "*.yourdomain.com"

providers:
  docker:
    exposedByDefault: false
    endpoint: "unix:///var/run/docker.sock"

certificatesResolvers:
  cloudflare:
    acme:
      email: "[email protected]"
      storage: "/letsencrypt/acme.json"
      dnsChallenge:
        provider: cloudflare
        resolvers:
          - "1.1.1.1:53"
          - "8.8.8.8:53"

Let's analyze the critical segments of this configuration:

  • Entrypoints: We define web (port 80) and websecure (port 443). A global redirect is established to seamlessly upgrade all incoming HTTP traffic to encrypted HTTPS connections.
  • Docker Provider: Setting exposedByDefault: false is an essential security measure. It prevents Traefik from inadvertently exposing containers to the public internet unless they explicitly contain an enabling label.
  • Certificates Resolvers: We configure the cloudflare resolver utilizing the ACME protocol for Let's Encrypt. The dnsChallenge block specifies the provider and utilizes upstream DNS resolvers (Cloudflare and Google) to verify the TXT record propagation quickly.

Step 3: Deploying Traefik via Docker Compose

With our static configuration ready, we can now define the deployment structure using Docker Compose. Create a docker-compose.yml file inside the /opt/traefik/ directory:

version: '3.8'

services:
  traefik:
    image: traefik:v3.0
    container_name: traefik
    restart: always
    ports:
      - "80:80"
      - "443:443"
    environment:
      - [email protected]
      - CF_DNS_API_TOKEN=your_cloudflare_api_token_here
    volumes:
      - /var/run/docker.sock:/var/run/docker.sock:ro
      - ./data/traefik.yml:/traefik.yml:ro
      - ./data/acme.json:/letsencrypt/acme.json
    labels:
      - "traefik.enable=true"
      - "traefik.http.routers.dashboard.rule=Host(`traefik.yourdomain.com`)"
      - "traefik.http.routers.dashboard.service=api@internal"
      - "traefik.http.routers.dashboard.entrypoints=websecure"
      - "traefik.http.routers.dashboard.middlewares=auth"
      - "traefik.http.middlewares.auth.basicauth.users=admin:$$apr1$$h67jmqre$$B7v7D1M9XvJQ9K7B1lVvF0"
    networks:
      - proxy

networks:
  proxy:
    external: true

Note: Before executing this composition, ensure you create the external network via your terminal using docker network create proxy. Additionally, replace the CF_DNS_API_TOKEN with your actual token and generate a secure basic authentication password string using a tool like htpasswd to shield your administrative dashboard from unauthorized eyes.

Step 4: Testing Automatic Container Discovery

To witness the true capability of Traefik v3, let us deploy an isolated application container (e.g., Nginx) and observe how Traefik dynamically configures routing and provisions SSL automatically.

Create a test configuration file named test-app.yml:

version: '3.8'

services:
  webapp:
    image: nginx:alpine
    container_name: demo-webapp
    restart: always
    labels:
      - "traefik.enable=true"
      - "traefik.http.routers.webapp.rule=Host(`app.yourdomain.com`)"
      - "traefik.http.routers.webapp.entrypoints=websecure"
      - "traefik.http.services.webapp.loadbalancer.server.port=80"
    networks:
      - proxy

networks:
  proxy:
    external: true

Execute docker compose -f test-app.yml up -d. Within moments, Traefik detects the new container via the Unix socket, initiates the Let's Encrypt DNS challenge, communicates with Cloudflare to validate the domain ownership via TXT records, generates the wildcard/specific SSL certificate, and opens the routing path. You can now access [https://app.yourdomain.com](https://app.yourdomain.com) with a fully trusted, green-locked SSL certificate without ever modifying a web server configuration file.

Conclusion and Best Practices

By implementing Traefik v3 with Docker and DNS-01 challenges, you have successfully decoupled your infrastructure routing from manual server configurations. This architecture offers massive scalability, unmatched agility for DevOps workflows, and iron-clad security protocols suitable for production-tier environments.

As you move forward, consider implementing production safeguards such as setting up rate-limiting middlewares, monitoring Traefik metrics via Prometheus, and ensuring your acme.json configurations are regularly backed up securely. Traefik v3 bridges the gap between infrastructure complexity and modern automation, letting you focus entirely on building applications rather than managing paths.

Mastering Traefik v3: Automated Docker Reverse Proxy with Let's Encrypt DNS Challenge | DPTCloud