# \#docker

**URL:** https://community.traefik.io/tag/docker/3.md

[Latest](https://community.traefik.io/latest.md) · [Categories](https://community.traefik.io/categories.md) · [Tags](https://community.traefik.io/tags.md)

---

## [Actively maintained certificate extractor](https://community.traefik.io/t/actively-maintained-certificate-extractor/30266)

<div class="topic-metadata">

**Author:** [@kale1d0code](https://community.traefik.io/u/kale1d0code)\
**Replies:** 1\
**Last updated:** [October 6, 2026, 9:07pm UTC](https://community.traefik.io/t/actively-maintained-certificate-extractor/30266 "2026-10-06T21:07:38Z")

</div>

Hi All, nice to be part of the community :slight\_smile: we've had a long standing requirement to extract certificates from traefiks acme.json so they can be used by the services which require them (postfix, simplerisk,…

---

## [Trying to understand Traefik routing and resolve Step CA routing issues](https://community.traefik.io/t/trying-to-understand-traefik-routing-and-resolve-step-ca-routing-issues/19101)

<div class="topic-metadata">

**Author:** [@mikeschinkel](https://community.traefik.io/u/mikeschinkel)\
**Replies:** 5\
**Last updated:** [October 4, 2026, 2:28pm UTC](https://community.traefik.io/t/trying-to-understand-traefik-routing-and-resolve-step-ca-routing-issues/19101 "2026-10-04T14:28:44Z")

</div>

I have set up Traefik with Portainer and Step CA on a Debian 11 VM running on VMware ESXi and I have documented most of it in this Git repo). My goal for this will be to create a repo which can be used to install and co…

---

## [SHA hash changed for Traefik image v3.7.13 in Docker Hub ?](https://community.traefik.io/t/sha-hash-changed-for-traefik-image-v3-7-13-in-docker-hub/30253)

<div class="topic-metadata">

**Author:** [@mig5](https://community.traefik.io/u/mig5)\
**Replies:** 1\
**Last updated:** [September 25, 2026, 7:47am UTC](https://community.traefik.io/t/sha-hash-changed-for-traefik-image-v3-7-13-in-docker-hub/30253 "2026-09-25T07:47:04Z")

</div>

Hi there! I noticed that the manifest SHA hash has changed in Docker hub for Traefik v3.7.13. It went from: docker.io/library/traefik:v3.7.13@sha256:96780238b1bbda5a9bb997f4307ce69e798ad1cf6eb7f2dcc0a440823467d199 to…

---

## [Traefik not creating routers from docker labels](https://community.traefik.io/t/traefik-not-creating-routers-from-docker-labels/30235)

<div class="topic-metadata">

**Author:** [@RedToxyl](https://community.traefik.io/u/RedToxyl)\
**Replies:** 2\
**Last updated:** [September 13, 2026, 10:36am UTC](https://community.traefik.io/t/traefik-not-creating-routers-from-docker-labels/30235 "2026-09-13T10:36:16Z")

</div>

Hi there I am trying to move from a .yaml to docker labels based system. However, Traefik sometimes doesn't create routers from given docker labels. Sometimes it does, and I cannot for the life of me figure out why. Th…

---

## [ACME Cloudflare not working after 3.7.6+](https://community.traefik.io/t/acme-cloudflare-not-working-after-3-7-6/29983)

<div class="topic-metadata">

**Author:** [@dhjensen](https://community.traefik.io/u/dhjensen)\
**Replies:** 22\
**Last updated:** [September 8, 2026, 2:48pm UTC](https://community.traefik.io/t/acme-cloudflare-not-working-after-3-7-6/29983 "2026-09-08T14:48:23Z")

</div>

Hi guys, After I upgraded to version 3.7.6+ (Noticed this the first time in 3.7.8) I see the behavior in the log below. The behavior seen in the log goes away if I revert to version 3.7.5. If you need more info let me …

---

## [Traefik Middleware Plugin Download Fails Sites Dependent on It](https://community.traefik.io/t/traefik-middleware-plugin-download-fails-sites-dependent-on-it/29760)

<div class="topic-metadata">

**Author:** [@j0nny55555](https://community.traefik.io/u/j0nny55555)\
**Replies:** 1\
**Last updated:** [September 6, 2026, 6:08am UTC](https://community.traefik.io/t/traefik-middleware-plugin-download-fails-sites-dependent-on-it/29760 "2026-09-06T06:08:48Z")

</div>

Really quick, the subject describes it - and I found the solution and was curious if there was any intent to make this more standardized, at least in documentation? The Traefik instances will come up, but the sites that…

---

## [Forwarding traffic to a game server running on Pterodactyl](https://community.traefik.io/t/forwarding-traffic-to-a-game-server-running-on-pterodactyl/23657)

<div class="topic-metadata">

**Author:** [@molemanx](https://community.traefik.io/u/molemanx)\
**Replies:** 7\
**Last updated:** [August 30, 2026, 5:53am UTC](https://community.traefik.io/t/forwarding-traffic-to-a-game-server-running-on-pterodactyl/23657 "2026-08-30T05:53:13Z")

</div>

Unsure if this is the correct place for issues like this, however I’ve been trying to set up a game server running on pterodactyl over the last week and I’m on the very last hurdle. I’ve successfully set up a game serve…

---

## [HTTP/1.0 Protocol Downgrade (PCI DSS) - Is it possible to reject HTTP/1.0 requests in Traefik?](https://community.traefik.io/t/http-1-0-protocol-downgrade-pci-dss-is-it-possible-to-reject-http-1-0-requests-in-traefik/29981)

<div class="topic-metadata">

**Author:** [@westsidetechsolution](https://community.traefik.io/u/westsidetechsolution)\
**Replies:** 2\
**Last updated:** [August 25, 2026, 7:48am UTC](https://community.traefik.io/t/http-1-0-protocol-downgrade-pci-dss-is-it-possible-to-reject-http-1-0-requests-in-traefik/29981 "2026-08-25T07:48:03Z")

</div>

I'm trying to satisfy a PCI DSS ASV scan that fails with the following finding: HTTP/1.0 Protocol Downgrade Detected The recommendation from the PCI vendor is that the server should reject HTTP/1.0 requests and only …

---

## [Using the error middleware always trigger an error: "the service "@provider" does not exist"](https://community.traefik.io/t/using-the-error-middleware-always-trigger-an-error-the-service-provider-does-not-exist/29946)

<div class="topic-metadata">

**Author:** [@NotaInutilis](https://community.traefik.io/u/NotaInutilis)\
**Replies:** 5\
**Last updated:** [August 10, 2026, 1:26pm UTC](https://community.traefik.io/t/using-the-error-middleware-always-trigger-an-error-the-service-provider-does-not-exist/29946 "2026-08-10T13:26:38Z")

</div>

Hi, I'd like to ask for some help with using the error middleware with Traefik 3.7.5 on Docker. I'm getting an error which looks unrelated and I'm not sure if it's a configuration issue or a bug. I'm trying to create an…

---

## [Traefik works but only if loadbalancer.server.port is included](https://community.traefik.io/t/traefik-works-but-only-if-loadbalancer-server-port-is-included/29970)

<div class="topic-metadata">

**Author:** [@radoeka](https://community.traefik.io/u/radoeka)\
**Replies:** 9\
**Last updated:** [July 17, 2026, 1:03pm UTC](https://community.traefik.io/t/traefik-works-but-only-if-loadbalancer-server-port-is-included/29970 "2026-07-17T13:03:55Z")

</div>

I'm very puzzled by the following, hopefully someone can shine a light on why this happening: Traefik works but only if I include the label: traefik.http.services.random-xbcz.loadbalancer.server.port: "80" But this la…

---

## [Traefik used to work perfectly, but now always falls back to default cert](https://community.traefik.io/t/traefik-used-to-work-perfectly-but-now-always-falls-back-to-default-cert/29968)

<div class="topic-metadata">

**Author:** [@pyrmion](https://community.traefik.io/u/pyrmion)\
**Replies:** 3\
**Last updated:** [July 11, 2026, 12:21pm UTC](https://community.traefik.io/t/traefik-used-to-work-perfectly-but-now-always-falls-back-to-default-cert/29968 "2026-07-11T12:21:57Z")

</div>

Hi! My Traefik setup was working perfectly. And then all of a sudden Traefik started serving not the certificates it requested via cloudflare/let's encrypt but the fallback Traefik one. I setup Traefik completely new …

---

## [ACME: "server misbehaving"](https://community.traefik.io/t/acme-server-misbehaving/29951)

<div class="topic-metadata">

**Author:** [@precariousDolphin](https://community.traefik.io/u/precariousDolphin)\
**Replies:** 2\
**Last updated:** [June 28, 2026, 9:42am UTC](https://community.traefik.io/t/acme-server-misbehaving/29951 "2026-06-28T09:42:42Z")

</div>

Today I received notifications that me server certificates have expired. The logfile entries say this. 2026-06-26T11:44:19Z INF Error renewing ACME certificate: {Main:nextcloud.domain.one SANs:\[\]} error="get directory a…

---

## [TCP catch all only working with TLS](https://community.traefik.io/t/tcp-catch-all-only-working-with-tls/29940)

<div class="topic-metadata">

**Author:** [@juffma](https://community.traefik.io/u/juffma)\
**Replies:** 4\
**Last updated:** [June 15, 2026, 1:59pm UTC](https://community.traefik.io/t/tcp-catch-all-only-working-with-tls/29940 "2026-06-15T13:59:43Z")

</div>

I'm trying to expose coturn TCP over Traefik (latest version 3.7.5). Yet I've hit a wall where Traefik will only forwards TLS traffic. Naturally I've set up a TCP router (with TLS passthrough since coturn runs TCP/TLS a…

---

## [Extremely high CPU usage with WireGuard](https://community.traefik.io/t/extremely-high-cpu-usage-with-wireguard/25401)

<div class="topic-metadata">

**Author:** [@LegendaryFire](https://community.traefik.io/u/LegendaryFire)\
**Replies:** 2\
**Last updated:** [June 15, 2026, 6:13am UTC](https://community.traefik.io/t/extremely-high-cpu-usage-with-wireguard/25401 "2026-06-15T06:13:14Z")

</div>

I have Traefik configured in Docker, and WireGuard is working fine but I noticed when uploading a large file to my server, Traefik CPU usage uses up every bit of my CPU utilization on an Intel i3 12100. The labels I'm r…

---

## [Default Certificate request error: Cannot issue for "traefik-traefik": Domain name needs at least one dot](https://community.traefik.io/t/default-certificate-request-error-cannot-issue-for-traefik-traefik-domain-name-needs-at-least-one-dot/29916)

<div class="topic-metadata">

**Author:** [@reibuehl](https://community.traefik.io/u/reibuehl)\
**Replies:** 3\
**Last updated:** [June 5, 2026, 10:18am UTC](https://community.traefik.io/t/default-certificate-request-error-cannot-issue-for-traefik-traefik-domain-name-needs-at-least-one-dot/29916 "2026-06-05T10:18:00Z")

</div>

I have set the following labels on my traefik container to generate a default certificate: - "traefik.enable=true" - "traefik.tls.stores.default.defaultgeneratedcert.resolver=le" - "traefik.tls.stores.default.defa…

---

## [Requesting certificate via DNS-01 fails with "some credentials information are missing"](https://community.traefik.io/t/requesting-certificate-via-dns-01-fails-with-some-credentials-information-are-missing/29911)

<div class="topic-metadata">

**Author:** [@reibuehl](https://community.traefik.io/u/reibuehl)\
**Replies:** 6\
**Last updated:** [June 2, 2026, 11:09pm UTC](https://community.traefik.io/t/requesting-certificate-via-dns-01-fails-with-some-credentials-information-are-missing/29911 "2026-06-02T23:09:49Z")

</div>

I am trying to setup Traefik 3.7 with ACME DNS-01 Challenge. I have specified the HETZNER\_API\_TOKEN environment variable in Portainer for the Traefik stack but I keep getting this error message: Unable to obtain ACME ce…

---

## [Prevent bringing down traefik if label is misconfigured](https://community.traefik.io/t/prevent-bringing-down-traefik-if-label-is-misconfigured/29913)

<div class="topic-metadata">

**Author:** [@RustyNova016](https://community.traefik.io/u/RustyNova016)\
**Replies:** 0\
**Last updated:** [June 2, 2026, 10:41pm UTC](https://community.traefik.io/t/prevent-bringing-down-traefik-if-label-is-misconfigured/29913 "2026-06-02T22:41:00Z")

</div>

I'm running traefik on docker, which reverse proxies komodo, a docker manager, and plenty other containers. I exclusively use labels to configure the different containers's reverse proxies. Everything works fine, except…

---

## [unable to generate a certificate for the domains \[traefik-docker\]](https://community.traefik.io/t/unable-to-generate-a-certificate-for-the-domains-traefik-docker/29879)

<div class="topic-metadata">

**Author:** [@Vladimir](https://community.traefik.io/u/Vladimir)\
**Replies:** 4\
**Last updated:** [May 26, 2026, 8:57pm UTC](https://community.traefik.io/t/unable-to-generate-a-certificate-for-the-domains-traefik-docker/29879 "2026-05-26T20:57:17Z")

</div>

When I run docker logs traefik I see a lot of errors like this: 2026-05-13T08:39:35Z ERR Unable to obtain ACME certificate for domains error="unable to generate a certificate for the domains \[traefik-docker\]: acme: err…

---

## [Traefik is not compatible with Angular](https://community.traefik.io/t/traefik-is-not-compatible-with-angular/29880)

<div class="topic-metadata">

**Author:** [@Vladimir](https://community.traefik.io/u/Vladimir)\
**Replies:** 4\
**Last updated:** [May 23, 2026, 7:29am UTC](https://community.traefik.io/t/traefik-is-not-compatible-with-angular/29880 "2026-05-23T07:29:33Z")

</div>

While developing this wonderful tool, which uses Angular as the frontend framework and Traefik as a reverse proxy, I encountered the following problem. The Angular documentation Read route state • Angular describes tha…

---

## [Middleware attached to service](https://community.traefik.io/t/middleware-attached-to-service/29886)

<div class="topic-metadata">

**Author:** [@gcmlabs](https://community.traefik.io/u/gcmlabs)\
**Replies:** 5\
**Last updated:** [May 18, 2026, 12:27pm UTC](https://community.traefik.io/t/middleware-attached-to-service/29886 "2026-05-18T12:27:50Z")

</div>

Hello, i'm using docker compose to setup a service. I need to define a middleware to strip a prefix from all the requests coming to the service. There will be other routers in the future with different hostnames that ne…

---

## [Dashboard authentication with usersFile](https://community.traefik.io/t/dashboard-authentication-with-usersfile/29864)

<div class="topic-metadata">

**Author:** [@HeSitated](https://community.traefik.io/u/HeSitated)\
**Replies:** 4\
**Last updated:** [May 12, 2026, 2:19pm UTC](https://community.traefik.io/t/dashboard-authentication-with-usersfile/29864 "2026-05-12T14:19:47Z")

</div>

I've got traefik running and want to use a userFile for authentication. Without authentication it all works, but as soon as I add the usersFile label, I get the popup to enter my name and the password but that is it.... …

---

## [Multiple ports on the same service](https://community.traefik.io/t/multiple-ports-on-the-same-service/29847)

<div class="topic-metadata">

**Author:** [@Nitrousoxide](https://community.traefik.io/u/Nitrousoxide)\
**Replies:** 2\
**Last updated:** [May 8, 2026, 2:32am UTC](https://community.traefik.io/t/multiple-ports-on-the-same-service/29847 "2026-05-08T02:32:06Z")

</div>

I'm attempting to setup a calibre route and service for both the webpage and the opds server. I'm... strugglilng to get this to work, despite looking through other examples throughout the forums. Starting this up resul…

---

## [Traefik with DNS Challenge behind firewall](https://community.traefik.io/t/traefik-with-dns-challenge-behind-firewall/29846)

<div class="topic-metadata">

**Author:** [@Baldaccilab\_IT](https://community.traefik.io/u/Baldaccilab_IT)\
**Replies:** 2\
**Last updated:** [April 30, 2026, 12:11pm UTC](https://community.traefik.io/t/traefik-with-dns-challenge-behind-firewall/29846 "2026-04-30T12:11:56Z")

</div>

Good morning, i am new to Traefik and im trying to setup the reverse proxy with TLS Letsencrypt certificate using DNS challenge with docker behind a firewall at the moment in my homelab for testing before put it in prod…

---

## [Docker Image 3.6.13 Updated without release notes](https://community.traefik.io/t/docker-image-3-6-13-updated-without-release-notes/29827)

<div class="topic-metadata">

**Author:** [@Atlas27](https://community.traefik.io/u/Atlas27)\
**Replies:** 0\
**Last updated:** [April 18, 2026, 1:32pm UTC](https://community.traefik.io/t/docker-image-3-6-13-updated-without-release-notes/29827 "2026-04-18T13:32:21Z")

</div>

The latest docker image was updated without a noted release while using the same tags. Latest release in ghcr Latest release noted on github Are existing tags expected to be updated inplace?

---

## [Appropriate limit for maxResponseBodySize](https://community.traefik.io/t/appropriate-limit-for-maxresponsebodysize/29702)

<div class="topic-metadata">

**Author:** [@johnw](https://community.traefik.io/u/johnw)\
**Replies:** 5\
**Last updated:** [April 17, 2026, 10:34am UTC](https://community.traefik.io/t/appropriate-limit-for-maxresponsebodysize/29702 "2026-04-17T10:34:32Z")

</div>

Hi, I recently started getting a lot of warnings in my log for each of the applications I set up forward auth (through Authentik) for. WRN ForwardAuth 'maxResponseBodySize' is not configured, allowing unlimited response…

---

## [HTTP healthckeck not using hostname for SNI](https://community.traefik.io/t/http-healthckeck-not-using-hostname-for-sni/29822)

<div class="topic-metadata">

**Author:** [@felixl](https://community.traefik.io/u/felixl)\
**Replies:** 1\
**Last updated:** [April 15, 2026, 3:06pm UTC](https://community.traefik.io/t/http-healthckeck-not-using-hostname-for-sni/29822 "2026-04-15T15:06:57Z")

</div>

Hello there. I’m running Traefik 3.6.13 and have troubles to get the healthcheck working for a HTTPS backend running on Apache. The healthcheck always fails. My service configuration in Traefik looks like: http: ... …

---

## [TCP passthrough routing failing when falling back from QUIC to TCP?](https://community.traefik.io/t/tcp-passthrough-routing-failing-when-falling-back-from-quic-to-tcp/29803)

<div class="topic-metadata">

**Author:** [@cod](https://community.traefik.io/u/cod)\
**Replies:** 4\
**Last updated:** [April 15, 2026, 3:05pm UTC](https://community.traefik.io/t/tcp-passthrough-routing-failing-when-falling-back-from-quic-to-tcp/29803 "2026-04-15T15:05:04Z")

</div>

Hello community, maybe someone has an idea. I have an strange issue: I have set up traefik for TLS passthrough to another traefik which is terminating TLS and then forwarding the traffic to a nextcloud container. It w…

---

## [Make Traefiks log available for CrowdSec in Docker](https://community.traefik.io/t/make-traefiks-log-available-for-crowdsec-in-docker/29802)

<div class="topic-metadata">

**Author:** [@smibcorp](https://community.traefik.io/u/smibcorp)\
**Replies:** 5\
**Last updated:** [April 13, 2026, 2:45pm UTC](https://community.traefik.io/t/make-traefiks-log-available-for-crowdsec-in-docker/29802 "2026-04-13T14:45:22Z")

</div>

Hello, I’m trying to set up Traefik with Crowdsec which need the Traefik logs to work, but unfortunately I can’t seem to do it in the correct way. I’ve have to admit that this is not my forte, to put it bluntly I’m a no…

---

## [Traefik ignores containers with two routers?](https://community.traefik.io/t/traefik-ignores-containers-with-two-routers/29817)

<div class="topic-metadata">

**Author:** [@wigedev](https://community.traefik.io/u/wigedev)\
**Replies:** 2\
**Last updated:** [April 10, 2026, 7:37pm UTC](https://community.traefik.io/t/traefik-ignores-containers-with-two-routers/29817 "2026-04-10T19:37:27Z")

</div>

I am using docker compose to set up my container, there are two sets of routes, one for internal traffic and one for external traffic. These are separated because I intend to add a rule for a prefix and prefix stripping …

---

## [Traefik docker socket](https://community.traefik.io/t/traefik-docker-socket/29807)

<div class="topic-metadata">

**Author:** [@mrnoname](https://community.traefik.io/u/mrnoname)\
**Replies:** 6\
**Last updated:** [April 10, 2026, 2:19pm UTC](https://community.traefik.io/t/traefik-docker-socket/29807 "2026-04-10T14:19:19Z")

</div>

hello, I want to connect to my docker-socket proxy provided by linuxserver.io, but I want to keep it reading my local docker containers. can someone help please

[Next page](https://community.traefik.io/tag/docker/3.md?match_all_tags=true&page=1&tags%5B%5D=docker)
