# How to enable proxyprotocol on a service declared from docker swarm?

**URL:** <https://community.traefik.io/t/how-to-enable-proxyprotocol-on-a-service-declared-from-docker-swarm/9167>\
**Category:** Traefik v2\
**Tags:** tcp, docker-swarm\
**Created:** [December 30, 2020, 2:12pm UTC](https://community.traefik.io/t/how-to-enable-proxyprotocol-on-a-service-declared-from-docker-swarm/9167 "2020-12-30T14:12:10Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![OuterSystems](https://avatars.discourse-cdn.com/v4/letter/o/e480ec/32.png) [@OuterSystems](https://community.traefik.io/u/OuterSystems)\
**Post date:** [December 30, 2020, 2:12pm UTC](https://community.traefik.io/t/how-to-enable-proxyprotocol-on-a-service-declared-from-docker-swarm/9167/1 "2020-12-30T14:12:10Z")

</div>

Hi,

**The symptom**

My issue is this log line: level=error msg="field not found, node: proxyprotocol" providerName=docker container=...

**My setup**

I try to enable proxyprotocol for a service that I am running in a docker service/task/... but it doesn't seems to work. I use "docker stack deploy -c docker-compose.yml" with this file (cleared a bit):

```
version: "3.8"                                                                                                                     
                                                                                                                                 
services:                                                                                                                          
  blah:                                                                                                                           
    image: blah:latest                                                                                                     
    volumes:                                                                                                                                                                                                                             
      - ./data:/data                                                                                                               
    deploy:                                                                                                                        
      labels:                                                                                                                      
        traefik.enable: "true"                                                                                                     
        traefik.tcp.routers.tcp-587.entrypoints: "smtp"                                                                            
        traefik.tcp.routers.tcp-587.rule: "HostSNI(`*`)"                                                                           
        traefik.tcp.routers.tcp-587.service: "tcp-587"                                                                             
        traefik.tcp.services.tcp-587.loadbalancer.server.port: "587"                                                               
        traefik.tcp.services.tcp-587.loadbalancer.proxyprotocol.version: "2"  

```

**Some investigations**

1. I found the documentation: [Docker - Traefik](https://doc.traefik.io/traefik/master/routing/providers/docker/)  
With `"traefik.tcp.services.mytcpservice.loadbalancer.proxyprotocol.version=1"`.

2. In the code repo [GitHub - traefik/traefik: The Cloud Native Application Proxy](https://github.com/traefik/traefik) I had no match with this: `ag proxyprotocol | grep docker` and I have no match for golang files while have some with `ag proxyprotocol | grep kubernetes`.

So I'm asking if the feature is implemented for the docker provider.

Do I miss something?

---

<div class="post-metadata">

**Author:** ![bluepuma77](https://avatars.discourse-cdn.com/v4/letter/b/a9adbd/32.png) [@bluepuma77](https://community.traefik.io/u/bluepuma77)\
**Post date:** [August 31, 2022, 8:59am UTC](https://community.traefik.io/t/how-to-enable-proxyprotocol-on-a-service-declared-from-docker-swarm/9167/2 "2022-08-31T08:59:23Z")

</div>

ProxyProtocol should be declared at the EntryPoint in the Traefik static configuration ([docs](https://doc.traefik.io/traefik/routing/entrypoints/#proxyprotocol)).

`entrypoints.websecure.proxyProtocol.trustedIPs=1.2.3.4`

---

<div class="post-metadata">

**Author:** ![chimp490](https://avatars.discourse-cdn.com/v4/letter/c/bbce88/32.png) [@chimp490](https://community.traefik.io/u/chimp490)\
**Post date:** [February 9, 2026, 9:15pm UTC](https://community.traefik.io/t/how-to-enable-proxyprotocol-on-a-service-declared-from-docker-swarm/9167/3 "2026-02-09T21:15:33Z")

</div>

By my understanding @bluepuma77 ‘s answer is contradicting the v2 docs.

> Traefik supports [PROXY Protocol](https://www.haproxy.org/download/2.0/doc/proxy-protocol.txt) version 1 and 2 on TCP Services. It can be enabled by setting `proxyProtocol` **on the load balancer**.
> 
> ```ini
> ## Dynamic configuration
> [tcp.services]
> [tcp.services.my-service.loadBalancer]
> [tcp.services.my-service.loadBalancer.proxyProtocol]
> version = 1
> 
> ```

> **[Redirecting...](https://doc.traefik.io/traefik/v2.11/routing/services/#proxy-protocol)**

The section you are citing - [https://doc.traefik.io/traefik/v2.11/routing/entrypoints/#proxyprotocol](https://doc.traefik.io/traefik/v2.11/routing/entrypoints/#proxyprotocol) is about having Traefik accept the `proxyProtocol` which is by my understanding not what op wants.

I’m currently experiencing the same issue with a `traefik.http.service`.

---

<div class="post-metadata">

**Author:** ![bluepuma77](https://avatars.discourse-cdn.com/v4/letter/b/a9adbd/32.png) [@bluepuma77](https://community.traefik.io/u/bluepuma77)\
**Post date:** [February 10, 2026, 12:13pm UTC](https://community.traefik.io/t/how-to-enable-proxyprotocol-on-a-service-declared-from-docker-swarm/9167/4 "2026-02-10T12:13:36Z")

</div>

You can use ProxyProtocol on `entrypoints` ([reference](https://doc.traefik.io/traefik/v2.11/reference/static-configuration/cli/)) and TCP `services` ([reference](https://doc.traefik.io/traefik/v2.11/reference/dynamic-configuration/docker/)). It's seems not to be implemented for HTTP services, probably because the original IP is already included in the HTTP headers.

---

<div class="post-metadata">

**Author:** ![chimp490](https://avatars.discourse-cdn.com/v4/letter/c/bbce88/32.png) [@chimp490](https://community.traefik.io/u/chimp490)\
**Post date:** [February 10, 2026, 1:40pm UTC](https://community.traefik.io/t/how-to-enable-proxyprotocol-on-a-service-declared-from-docker-swarm/9167/5 "2026-02-10T13:40:59Z")

</div>

Thanks for confirming my suspicions. Did a bit more research after the post yesterday and it seems like the service (Stalwart Mail Server) expects the proxy header to be present if the global default trusted proxy is configured. → I’ll have to configure trusted proxies for each entrypoint individually independently from Traefik.
