Back to articles
Technology Insight

Mastering Traefik v3: Implementing an Automated Reverse Proxy for Docker Swarm Multi-VPS Clusters

May 30, 2026

Introduction to Modern Ingress Management in Distributed Environments

In the contemporary landscape of cloud-computing and microservices architecture, managing external access to containerized applications across a distributed infrastructure is a critical operational challenge. When scaling beyond a single virtual private server (VPS) into a Docker Swarm Multi-VPS cluster, traditional static reverse proxies like Nginx or Apache often become management bottlenecks. They require manual configuration updates and reloads every time a service scales, moves, or is newly deployed.

This is where Traefik v3 excels. Designed from the ground up as a cloud-native, modern reverse proxy and load balancer, Traefik integrates natively with container orchestrators. It eliminates manual intervention by utilizing automatic service discovery. Traefik listens directly to the orchestrator's API—in this case, Docker Swarm—and dynamically updates its routing rules in real-time as services are created, updated, or destroyed across your multi-node cluster.

The Architecture of Traefik v3 in a Multi-VPS Docker Swarm

Before diving into configuration, it is essential to understand how network traffic flows and how Traefik interacts with a Docker Swarm multi-node setup. In a multi-VPS Swarm cluster, you typically have one or more Manager nodes and multiple Worker nodes connected via a secure overlay network.

Traefik must be deployed on a Manager node because it requires access to the Docker daemon socket (/var/run/docker.sock) to monitor cluster events and inspect container metadata (labels). However, the applications being proxied can reside anywhere across the cluster on worker nodes, completely isolated from the public internet. Traefik acts as the single point of entry (Ingress), routing public HTTP/HTTPS traffic securely through the internal Swarm overlay network to the target containers.

Prerequisites and Environment Setup

To successfully implement this architecture, ensure your environment meets the following baseline requirements:

  • A functional Docker Swarm cluster consisting of at least two VPS instances (one Manager, one Worker).
  • A public static IP address mapped to your Manager node.
  • A registered domain name with wildcard or specific A records pointing to your Manager node's IP address (e.g., *.example.com).
  • Ports 80 (HTTP) and 443 (HTTPS) open on your firewall for public ingress traffic, alongside standard Docker Swarm mesh ports (2377, 7946, 4789).

Step-by-Step Guide: Deploying Traefik v3 via Docker Compose

In Docker Swarm, configuration is managed using stack files. We will define a docker-compose.yml file tailored for Traefik v3. This file leverages Swarm deployment constraints to ensure Traefik runs exclusively on a manager node, alongside configuring persistent volumes for SSL certificates.

1. Creating the Ingress Overlay Network

First, create a dedicated attachable overlay network that will act as the communication bridge between Traefik and your application services:

docker network create --driver=overlay --attachable traefik-public

2. The Traefik Stack Configuration File

Create a deployment file named traefik-stack.yml. Below is the production-ready structure optimized for Traefik v3:


version: '3.8'

services:
  traefik:
    image: traefik:v3.0
    command:
      - "--providers.docker=true"
      - "--providers.docker.swarmMode=true"
      - "--providers.docker.exposedByDefault=false"
      - "--entrypoints.web.address=:80"
      - "--entrypoints.websecure.address=:443"
      - "--certificatesresolvers.myresolver.acme.tlschallenge=true"
      - "[email protected]"
      - "--certificatesresolvers.myresolver.acme.storage=/letsencrypt/acme.json"
    ports:
      - target: 80
        published: 80
        protocol: tcp
        mode: host
      - target: 443
        published: 443
        protocol: tcp
        mode: host
    volumes:
      - /var/run/docker.sock:/var/run/docker.sock:ro
      - traefik-certificates:/letsencrypt
    networks:
      - traefik-public
    deploy:
      placement:
        constraints:
          - node.role == manager
      labels:
        - "traefik.enable=true"
        - "traefik.http.routers.api.rule=Host(`traefik.example.com`)"
        - "traefik.http.routers.api.service=api@internal"
        - "traefik.http.routers.api.entrypoints=websecure"
        - "traefik.http.routers.api.tls.certresolver=myresolver"
        - "traefik.http.services.api.loadbalancer.server.port=8080"

volumes:
  traefik-certificates:
networks:
  traefik-public:
    external: true
Important Note on Traefik v3 Syntax: Traefik v3 introduces explicit separation and deprecations over v2. Ensure you use exact entrypoint referencing and avoid obsolete syntax flags. Using mode: host on ports bypasses the Swarm routing mesh for incoming traffic, allowing Traefik to see the genuine client source IP addresses, which is crucial for logging and security analysis.

Automated Service Discovery: Deploying a Sample Web Application

With Traefik up and running, deploying an application that automates its own proxy configuration is remarkably straightforward. Traefik continuously polls the Swarm API. When it detects a container with specific traefik.* labels, it dynamically registers the router and service.

Create an application stack file named app-stack.yml:


version: '3.8'

services:
  webapp:
    image: nginx:alpine
    networks:
      - traefik-public
    deploy:
      replicas: 3
      labels:
        - "traefik.enable=true"
        - "traefik.http.routers.webapp.rule=Host(`app.example.com`)"
        - "traefik.http.routers.webapp.entrypoints=websecure"
        - "traefik.http.routers.webapp.tls.certresolver=myresolver"
        - "traefik.http.services.webapp.loadbalancer.server.port=80"

networks:
  traefik-public:
    external: true

Deploy the application using the command: docker stack deploy -c app-stack.yml myservice. Notice how we do not expose any host ports on the web application container. Traefik communicates internally via the traefik-public overlay network, isolating the app from raw public traffic while automatically generating a Let's Encrypt SSL certificate for app.example.com.

Best Practices for Multi-VPS Implementations

Operating a production-grade multi-node infrastructure requires adhering to strict operational protocols to ensure scalability, security, and persistence:

  1. Secure Data Persistence for SSL Certificates: In a multi-VPS swarm, containers can migrate between nodes. Since Let's Encrypt certificates are stored locally in acme.json, you must ensure Traefik remains locked to the manager node where the volume exists, or utilize a distributed network filesystem (such as GlusterFS or Ceph) if running multiple Traefik instances for high availability.
  2. Secure the Docker Socket: Access to /var/run/docker.sock gives a container root-level permissions over the host system. It is vital to ensure your Manager nodes are heavily firewalled and tightly controlled. For advanced production setups, consider utilizing a proxy tool like Tecnativa's Docker Socket Proxy to restrict Traefik's access strictly to read-only cluster events.
  3. Leverage TLS Snippets and Security Headers: Use Traefik v3 middlewares to enforce strict transport security (HSTS), prevent clickjacking, and enforce robust modern cipher suites across all upstream applications natively.

Conclusion

By pairing Traefik v3 with Docker Swarm Multi-VPS setups, you unlock an agile, self-healing enterprise infrastructure. Manual adjustments of configuration files become a thing of the past. As your infrastructure demands grow, scaling up involves nothing more than configuring your application's labels and letting Traefik handle the rest seamlessly. Implement this setup today to establish a resilient foundation for your distributed microservices.

Mastering Traefik v3: Implementing an Automated Reverse Proxy for Docker Swarm Multi-VPS Clusters | DPTCloud