# Adding entrypoints to a helm-deployed Traefik on K3s

**URL:** <https://community.traefik.io/t/adding-entrypoints-to-a-helm-deployed-traefik-on-k3s/14813>\
**Category:** Traefik v2\
**Tags:** tcp\
**Created:** [June 19, 2022, 10:45pm UTC](https://community.traefik.io/t/adding-entrypoints-to-a-helm-deployed-traefik-on-k3s/14813 "2022-06-19T22:45:45Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![lemmy04](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/lemmy04/32/3671_2.png) [@lemmy04](https://community.traefik.io/u/lemmy04)\
**Post date:** [June 19, 2022, 10:45pm UTC](https://community.traefik.io/t/adding-entrypoints-to-a-helm-deployed-traefik-on-k3s/14813/1 "2022-06-19T22:45:45Z")

</div>

Hi,

I have a k3s with traefik installed from the helm charts, seems to work fine, but now I need to add two additional tcp entrypoints, how do I do that on a "helmified" traefik?

cheers  
MH

---

<div class="post-metadata">

**Author:** ![jakubhajek](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/jakubhajek/32/3389_2.png) [@jakubhajek](https://community.traefik.io/u/jakubhajek)\
**Post date:** [June 21, 2022, 9:34am UTC](https://community.traefik.io/t/adding-entrypoints-to-a-helm-deployed-traefik-on-k3s/14813/2 "2022-06-21T09:34:36Z")

</div>

Hello @lemmy04

Thanks for using Traefik! 😃

While deploying [K3S together with Traefik](https://rancher.com/docs/k3s/latest/en/networking/#traefik-ingress-controller) installed the configuration has to be managed through [HelmChartConfig](https://rancher.com/docs/k3s/latest/en/helm/#customizing-packaged-components-with-helmchartconfig) CRD.

Here is the basic example of that custom resource. Please follow the official [Traefik Helm chart repository](https://github.com/traefik/traefik-helm-chart/) to learn more about other available [values](https://github.com/traefik/traefik-helm-chart/blob/master/traefik/values.yaml) that might be configured.

```yaml
apiVersion: helm.cattle.io/v1
kind: HelmChartConfig
metadata:
  name: traefik
  namespace: kube-system
spec:
  valuesContent: |-
    image:
      name: traefik
      tag: v2.7.1
    ports:
      tcp1: 
        port: 20000
        expose: true
        exposedPort: 20000
      tcp2: 
        port: 20001
        expose: true  
        exposedPort: 20001

```

Basically speaking, once that resource will be created, Helm Controller automatically notices the new config and transform the created Helm configuration into CLI arguments passed into Traefik.

Here is the result of the command `kubectl describe deployment traefik`

```auto
 traefik:
    Image: traefik:v2.7.1
    Ports: 20000/TCP, 20001/TCP, 9000/TCP, 8000/TCP, 8443/TCP
    Host Ports: 0/TCP, 0/TCP, 0/TCP, 0/TCP, 0/TCP
    Args:
      --global.checknewversion
      --global.sendanonymoususage
      --entryPoints.tcp1.address=:20000/tcp
      --entryPoints.tcp2.address=:20001/tcp
      --entryPoints.traefik.address=:9000/tcp
      --entryPoints.web.address=:8000/tcp
      --entryPoints.websecure.address=:8443/tcp
      --api.dashboard=true
      --ping=true
      --providers.kubernetescrd
      --providers.kubernetesingress
      --providers.kubernetesingress.ingressendpoint.publishedservice=kube-system/traefik
      --entrypoints.websecure.http.tls=true

```

Hope that helps,  
Thanks!

---

<div class="post-metadata">

**Author:** ![lemmy04](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/lemmy04/32/3671_2.png) [@lemmy04](https://community.traefik.io/u/lemmy04)\
**Post date:** [June 21, 2022, 9:54am UTC](https://community.traefik.io/t/adding-entrypoints-to-a-helm-deployed-traefik-on-k3s/14813/3 "2022-06-21T09:54:07Z")

</div>

So I just create a yaml file with content similar to the first example, and apply it?  
What if I deploye traefik into its own namespace, do I apply that new yaml file into that namespace, or still into kube-system?  
Or do I have to remove and redeploy traefik after applying that helmchartconfig?

---

<div class="post-metadata">

**Author:** ![jakubhajek](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/jakubhajek/32/3389_2.png) [@jakubhajek](https://community.traefik.io/u/jakubhajek)\
**Post date:** [June 21, 2022, 11:35am UTC](https://community.traefik.io/t/adding-entrypoints-to-a-helm-deployed-traefik-on-k3s/14813/4 "2022-06-21T11:35:09Z")

</div>

The solution I presented works for the default K3S deployment when Traefik is deployed in the `kube-system` namespace.

How did you deploy Traefik in its own namespace? I mean, what method did you use to deploy it?

---

<div class="post-metadata">

**Author:** ![lemmy04](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/lemmy04/32/3671_2.png) [@lemmy04](https://community.traefik.io/u/lemmy04)\
**Post date:** [June 21, 2022, 11:45am UTC](https://community.traefik.io/t/adding-entrypoints-to-a-helm-deployed-traefik-on-k3s/14813/5 "2022-06-21T11:45:24Z")

</div>

i created the namespace:  
`kubectl create ns traefik-v2`  
then I installed traefik:  
`helm install -n traefik-v2 traefik traefik/traefik`

so ... what exactly do I do with that HelmChartConfig? I have zero experience with helm...

All I need right now is to add 3270/tcp to my ports, so I can run tk4 in kubernetes.

---

<div class="post-metadata">

**Author:** ![jakubhajek](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/jakubhajek/32/3389_2.png) [@jakubhajek](https://community.traefik.io/u/jakubhajek)\
**Post date:** [June 21, 2022, 11:51am UTC](https://community.traefik.io/t/adding-entrypoints-to-a-helm-deployed-traefik-on-k3s/14813/6 "2022-06-21T11:51:16Z")

</div>

> [@lemmy04](#):
>
> helm install -n traefik-v2 traefik traefik/traefik

based on that, you don't use Traefik installed together with K3S, so you don't have to use HelmChartConfig.

I would recommend following the following workshops: Getting started with Traefik on K8S

[![](https://img.youtube.com/vi/CL5Cxxz-yHo/maxresdefault.jpg "Workshop: Getting Started with Traefik") ](https://www.youtube.com/watch?v=CL5Cxxz-yHo)

Here, in detail, we explain how to deploy Traefik by using the official Helm Chart.

Please ensure that you deploy K3S without Traefik.

For my testing purposes, I use K3D on my local workstation and use the following command to spin up a test K3S cluster in docker.

```auto
 k3d cluster create testing-traefik --k3s-arg "--disable=traefik@server:0" -p 80:80@loadbalancer -p 443:443@loadbalancer --agents 1

```

then you can create a dedicated namespace and deploy Traefik by using the Helm command you shared.

Hope that helps.

---

<div class="post-metadata">

**Author:** ![lemmy04](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/lemmy04/32/3671_2.png) [@lemmy04](https://community.traefik.io/u/lemmy04)\
**Post date:** [June 26, 2022, 7:11am UTC](https://community.traefik.io/t/adding-entrypoints-to-a-helm-deployed-traefik-on-k3s/14813/7 "2022-06-26T07:11:27Z")

</div>

> [@jakubhajek](#):
>
> `--entryPoints.websecure.address=:8443/tcp`

sorry... but that tutorial did not help.  
By now I have a working traefik, which even knows the entry point I have added.  
here's my values.yaml:

```auto
ports:
  x3270:
    port: 3270
    exposed: true
    exposedPort: 3270
additionalArguments:
  - "--entryPoints.x3270.address=:3270/tcp"

```

But when I look at the deployment I see **TWO**"--entryPoints"-lines, one might be a leftover from a previous experiment, how do I clean this up?

Anyway, I deploy my hercules emulator the same way that _used to work before_, see [From 0 to Kubernetes – Step 7, And now for something completely different… – Tux Online](https://www.tuxonline.tech/index.php/2021/04/16/from-0-to-kubernetes-and-now-for-something-completely-different/) and [tk4.yaml · GitHub](https://gist.github.com/lemmy04/f3c88619dfa900d744c57718dff49d01) and all I get is a "connection refused" from my 3270 telnet client...

Any further hint would be really useful.

---

<div class="post-metadata">

**Author:** ![R-in-Tokyo](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/r-in-tokyo/32/7941_2.png) [@R-in-Tokyo](https://community.traefik.io/u/R-in-Tokyo)\
**Post date:** [December 9, 2023, 5:45am UTC](https://community.traefik.io/t/adding-entrypoints-to-a-helm-deployed-traefik-on-k3s/14813/8 "2023-12-09T05:45:07Z")

</div>

Hello @jakubhajek the current example on k3s docs for the [traefik-config.yaml](https://docs.k3s.io/helm)

```auto
apiVersion: helm.cattle.io/v1
kind: HelmChartConfig
metadata:
  name: traefik
  namespace: kube-system
spec:
  valuesContent: |-
    image:
      name: traefik
      tag: v2.8.5
    forwardedHeaders:
      enabled: true
      trustedIPs:
        - 10.0.0.0/8
    ssl:
      enabled: true
      permanentRedirect: false

```

when this is auto deployed via adding to the /server/manifets folder , there is k3s gives an ErrImagePull.

commenting out the image tag solves that as a work around. But I'de like to solve this issue correctly.  
K3S, current trafeik. yaml uses

`chart: https://%{KUBERNETES_API}%/static/charts/traefik-crd-25.0.2+up25.0.0.tgz`

I thought the issue was an incorrect image tag, and should be v2.10.5.... but this also causes the error.

Ultimately I'de like to correctly format that traefik-config.yaml to enable http3, unfotunatly guides only give outdated bits and pieces.

my current traefik-config.yaml

```auto
apiVersion: helm.cattle.io/v1
kind: HelmChartConfig
metadata:
  name: traefik
  namespace: kube-system
spec:
  valuesContent: |-
    image:
      name: traefik
      #tag: v2.10.5 
    forwardedHeaders:
      enabled: true
      trustedIPs:
        - 10.0.0.0/8
    api:
      dashboard: true
    ports:
      traefik:
        expose: true    
      websecure:
        http3:
          enabled: true
          advertisedPort: 443           	 	    
    ssl:
      enabled: true
      permanentRedirect: false

```

---

<div class="post-metadata">

**Author:** ![srajappa](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/srajappa/32/10522_2.png) [@srajappa](https://community.traefik.io/u/srajappa)\
**Post date:** [February 28, 2025, 6:09pm UTC](https://community.traefik.io/t/adding-entrypoints-to-a-helm-deployed-traefik-on-k3s/14813/9 "2025-02-28T18:09:50Z")

</div>

How do we persist these updates ? Imagine the new endpoints must be established as part of startup.

I want a new cluster to have an HTTP, HTTPS and TCP endpoint at port say 450. How should we configure the traefik.yaml in the directory /var/lib/rancher/k3s/server/manifests ?

---

<div class="post-metadata">

**Author:** ![srajappa](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/srajappa/32/10522_2.png) [@srajappa](https://community.traefik.io/u/srajappa)\
**Post date:** [February 28, 2025, 9:25pm UTC](https://community.traefik.io/t/adding-entrypoints-to-a-helm-deployed-traefik-on-k3s/14813/10 "2025-02-28T21:25:22Z")

</div>

I already have a traefik where the entrypoints `web` and `websecure` exists.

I want to introduce `passthrough` entrypoint as well. Will the file be edited like below ?

```auto
apiVersion: helm.cattle.io/v1
kind: HelmChartConfig
metadata:
  name: traefik
  namespace: kube-system
spec:
  valuesContent: |-
    image:
      name: traefik
      tag: v2.7.1
    ports:
      web: 
        port: 8000
        expose: true
        exposedPort: 80
      websecure: 
        port: 8443
        expose: true  
        exposedPort: 443
      passthrough:
        port: 8450
        expose: true 
        exposedPort: 450

```

OR

```auto
apiVersion: helm.cattle.io/v1
kind: HelmChartConfig
metadata:
  name: traefik
  namespace: kube-system
spec:
  valuesContent: |-
    image:
      name: traefik
      tag: v2.8.5
    ports:
      passthrough:
        port: 8450
        expose: true 
        exposedPort: 450

```

---

<div class="post-metadata">

**Author:** ![srajappa](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/srajappa/32/10522_2.png) [@srajappa](https://community.traefik.io/u/srajappa)\
**Post date:** [July 8, 2025, 9:56am UTC](https://community.traefik.io/t/adding-entrypoints-to-a-helm-deployed-traefik-on-k3s/14813/11 "2025-07-08T09:56:06Z")

</div>

# Solution for traefik-27.0.201\_up27.0.2

If someone is still searching to how one needs to solve for adding custom entrypoints for latest version of Traefik, please add the following `HelmChartConfig`

```auto
apiVersion: helm.cattle.io/v1
kind: HelmChartConfig
metadata:
  name: traefik
  namespace: kube-system
spec:
  valuesContent: |-
    ports:
      passthrough:
        port: 8450
        expose:
          default: true 
        exposedPort: 450

```

As per documentation, one also needs to create appropriate `service` which gets deployed as `svc-*` in the kubernetes clusters.

And the `spec.valuesContent==>expose.default` will help you configure the same.
