Traefik Manager

Traefik Manager

WHAT IS IT?

Traefik Manager is a self-hosted web UI for running the Traefik reverse proxy: routes, services, middlewares, plugins, certificates, logs and CrowdSec. The backend is Flask, and the app writes Traefik's dynamic configuration files for you instead of leaving you in a text editor. The README is upfront about its audience: homelabbers who love Traefik but hate editing YAML at 2am.

Only File provider entries can be edited, in the YAML files you mount into the container. Routes declared through Docker labels, Kubernetes, Swarm or Nomad show up in read-only tabs fed by the Traefik API, so that API has to be reachable.

WHY IS IT INTERESTING?

  • HTTP, TCP and UDP routes: several domains and backends per route, sticky sessions, health checks, priority, and a certificate resolver and TLS profile per route. YAML is rewritten with ruamel.yaml, which keeps comments and Go templates intact.
  • Services and middlewares: weighted, mirroring or failover load balancers, and 30 middleware wizards (auth, rate limiting, headers, CORS, redirects, error pages), including a forward-auth template for Authelia. Services written outside the app stay read-only until you explicitly take them over.
  • Route map: a topology view that follows each request from entry point through middlewares to backend, with health shown at every hop.
  • Certificates: everything in acme.json with expiry dates, certificates no router serves, and those whose resolver is gone from the static config. Removing one needs acme.json mounted read-write and goes through a timestamped backup.
  • Background monitoring: route health, certificate expiry, CrowdSec activity and new releases, pushed to Discord, Slack, ntfy, Gotify, Telegram or a webhook even when no browser tab is open.
  • Multi-server: a Go agent runs next to each remote Traefik, and every tab in the UI switches to whichever server you pick, with no VPN or SSH involved.
  • Backups: a timestamped copy before every change, plus optional git push with history, diffs and restore.

The traefik.yml editor restarts Traefik through a socket proxy, a "poison pill" or direct Docker socket access; the docs recommend the socket proxy, which limits the app to restarts. With no password and no OIDC configured, the UI is open to anyone, behind a red warning. Secrets (TOTP seeds, OIDC secrets, git tokens...) are Fernet-encrypted, but unless you set OTP_ENCRYPTION_KEY the key is generated into the same /app/config volume.

The repository was created in March 2026, and v1.15.0 shipped on October 1, 2026, the twelfth release since September 1. It is the first one that is not English-only, with French among the new languages. A single developer wrote most of the commits.

USE CASES

  • Add a route to a new homelab service without opening dynamic.yml.
  • Spot a dead backend or a certificate close to expiry at a glance, and get the alert on ntfy or Telegram.
  • Run the Traefik instances of several machines from one UI through the agent.
  • Keep a git history of the whole dynamic configuration, with one-click rollback.