Put Wildcard Certificates and SSL on EVERYTHING - Traefik + Portainer Tutorial

Sdílet
Vložit
  • čas přidán 20. 05. 2024
  • Today, we're going to use SSL for everything. No more self-sign certs. No more http. No more hosting things on odd ports. We're going all in with SSL for our internal services and our external services too. We going to set up a reverse proxy using Traefik, Portainer, and use that to get wildcard certificates from Let's Encrypt. Join me and let's secure all the things.
    Video Notes: technotim.live/posts/traefik-...
    Support me on Patreon: / technotim
    Sponsor me on GitHub: github.com/sponsors/timothyst...
    Subscribe on Twitch: / technotim
    Become a CZcams member: / @technotim
    Merch Shop 🛍️: l.technotim.live/shop
    Gear Recommendations: l.technotim.live/gear
    Get Help in Our Discord Community: l.technotim.live/discord
    2nd channel: / @technotimtalks
    (Affiliate links may be included in this description. I may receive a small commission at no cost to you.)
    00:00 - What are we doing today?
    01:03 - What do we need?
    02:51 - What is Traefik?
    03:51 - Setting up Traefik
    04:27 - Traefik configuration
    06:18 - Traefik with Docker Compose
    07:00 - Traefik Docker Compose File with Wildcards
    10:46 - Spinning Up Traefik
    12:09 - Traefik Dashboard
    12:34 - We have Wildcards!
    13:01 - Portainer Docker Compose
    15:19 - Spinning up Portainer
    15:41 - Portainer in Traefik Dashboard
    15:58 - Portainer now has SSL
    16:39 - Proxy Through Traefik to External Services (Proxmox)'
    17:34 - Traefik Routes Config
    21:38 - Apply Traefik Route Config
    22:26 - See Our New External Route
    22:45 - SSL for Proxmox with Traefik Reverse proxy
    23:41 - Hosting all of your Homelab Services with SSL
    23:59 - Which Reverse Proxy Are You Running?
    24:11 - Stream Highlight - "I built my server, not sure where to go from here..."
    #Traefik #Portainer #Homelab
    "Sun Run" is from Harris Heller's album Breaker.
    l.technotim.live/sb-music-lic...
    Thank you for watching!
  • Věda a technologie

Komentáře • 904

  • @TechnoTim
    @TechnoTim  Před 3 lety +69

    What are you using to get your certificates?

    • @dcprom0396
      @dcprom0396 Před 3 lety +2

      Internally Active Directory Certificate Services. Externally Let’s Encrypt.

    • @ryanbell85
      @ryanbell85 Před 3 lety +8

      Using Let's Encrpt via HAProxy on my PFSense machine.

    • @alexanderlangle3921
      @alexanderlangle3921 Před 3 lety +2

      Traefic exposed with lets encrypt direct.
      In my setup traefic stays untouched and requests the certs based on the service labels from the other containers

    • @rhb.digital
      @rhb.digital Před 3 lety

      LetsEncrypt and apache proxy... both esxi and proxmox works awesome this way.. also Jellyfin and more....

    • @tbhinteractieve
      @tbhinteractieve Před 3 lety +4

      Haproxy runs on my pfsense box and gets let's encrypt certs to all my hostnames.

  • @shawn2296
    @shawn2296 Před rokem +57

    Half the views came from me watching it over and over.

  • @henrysowell
    @henrysowell Před rokem +21

    I know this is an older video, but I just wanted to drop in and say thank you. I really appreciate all you do for the community

  • @PaulLittlefield
    @PaulLittlefield Před rokem +8

    The best video on SSL with Portainer and Træfik, period. Thank you so much for your slow and clear approach with excellent quality of video. Keep up the great work Tim! 🐧

  • @lfelfoldi
    @lfelfoldi Před 3 lety +201

    This is literally my first ever comment in 8 years. I really enjoy your content. You keep it simple, relatable, and most importantly you tied different services together not just one by one in all different videos. You show the end game scenario. Patreon it is brother.

    • @TechnoTim
      @TechnoTim  Před 3 lety +7

      Thank you so much! Glad I helped break the seal! Welcome!

    • @Heynmffc
      @Heynmffc Před 2 lety

      @Inu Yasha you can check on CZcams now. Homeboy only has one comment in 10 years.

    • @streambarhoum4464
      @streambarhoum4464 Před rokem

      @@TechnoTim
      Tim, Is there a self hosted alternative for sel hosted tunnel to get rid of cloudflare services and do the cloudflare job like providing ssl certificates, hiding ip and protection from ddos attacks etc..?? All it done by myself?
      I heard by something like RPoVP? Does it get the job done or there is another better solution replacing cloudflare and our entire network and ip from external world??

  • @patrickjoseph3412
    @patrickjoseph3412 Před 2 lety +6

    Just wanted to say thank you, Tim!!! I've been wanting to set up ssl for a few months now but have been intimidated by it all. After learning how to create a ansible playbook to update,upgrade-dist for my VMs last week . I was like I can do this ssl thing so I bought a domain and watched this video like 10 times but I now have my local services all running with ssl thanks to you. All your videos are great and very infomitve. You and the homelab CZcams community is amazing .. thank you again so much

  • @thiggs383
    @thiggs383 Před rokem +41

    I was originally soooo frustrated following this tutorial. I went step by step, and took SEVEN hours just to figure out that I had some typos! Thanks @Techno Tim, amazing tutorial. I'm so glad I stuck it out! For anyone else struggling, highly recommend looking over your work even when you copy and paste!

    • @TechnoTim
      @TechnoTim  Před rokem +4

      Thank you!!! Nice work!

    • @DShawConsulting
      @DShawConsulting Před 10 měsíci

      I got frustrated as well but then I realized that I mistakenly typed a - instead of an = on two lines…Thank you for the great tutorial @TechnoTim!

  • @einsteinx2
    @einsteinx2 Před rokem

    I just found your channel and have binged a few videos as I’m right in the process of upgrading my home Proxmox server and home network. I swear you somehow have a video for exactly each thing I was about to do, with detailed instructions and configs (NUT, Proxmox setup, SSL and FQDM for local services, etc etc). These are fantastic jumping off points for my own custom configs and I love that you go into such detail and explain WHY you do things not just a list of steps, as I usually will want a different configuration and am even more interested in the why than the how. Fantastic channel, I hope to see you continue to grow it!

    • @TechnoTim
      @TechnoTim  Před rokem

      Thank you so much!!! Welcome!!!

  • @CrashLoopBackOff-K8s
    @CrashLoopBackOff-K8s Před 2 lety +1

    Came across this video just today, and I wanted to leave a comment for the algorithm, along with liking and subscribing. Really appreciate you giving away the hours of trial and error that it had to have taken to get these configs dialed in. I also appreciate your clear and straightforward delivery. Great job with this.

  • @SirJohn2024
    @SirJohn2024 Před 4 měsíci +6

    After almost 3 years, this still works like a charm... Save my life... Kudos 👏😎

    • @Ibleoverhan
      @Ibleoverhan Před 3 měsíci

      About to step through this procedure myself. Good to know it still works ha ha.

    • @Mjolinir
      @Mjolinir Před 3 měsíci

      Just tried this today myself. When my Traefik site comes up its still using the default self-signed cert. Not sure why. I see a cert for my domain in the acme.json, it just doesn't seem to be using it. Not sure how to troubleshoot.

  • @mattvisaggio
    @mattvisaggio Před 9 měsíci +1

    I've watched this video twice fully and a few times in part over a period of several months. You've been a teacher for me and I appreciate you.

  • @floriantthebault521
    @floriantthebault521 Před 4 měsíci

    I've been looking to do that for over a year and a half and scratching my head because it all seemed far too complicated a setup to bother with it all. Until I finally found your video... Damn, that one is very useful and simple to follow... as well as sufficiently detailed to really understand how it works under. Very well done and useful, thanks!

  • @ImARichard
    @ImARichard Před 3 lety +4

    Love using traefik! It was actually where I started my homelab. A friend showed me traefik and something about it just caught my interest. Started spinning up a bunch of different containers with configs just for the sake of it.
    Great video!

  • @quazl
    @quazl Před 3 lety +6

    I use Nginx proxy manager, but this looks neat. I really need to move to wildcard, my let’s encrypt list is getting a little silly now.
    Thanks, Tim for all you do!

  • @bagellord
    @bagellord Před rokem

    Tim thank you so much for this video and tutorial. I got this up and running for my internal services, and it inspired me to also set up a separate process for the stuff I wanted to take external. Keep it up!

  • @jakeevermore162
    @jakeevermore162 Před 3 lety

    Exactly what I needed man, thank you so much! Really enjoy the videos! Super clear and fun to watch!

  • @ChappIOMusic
    @ChappIOMusic Před 3 lety +28

    Nice! I've been running this setup for a few years as well. With one difference: I configured the file provider to watch a directory of .yml files. (see the watch option and the directory option). This allows me to create a .yml file PER site and the watch option makes it so I don't have to restart the container and take down the proxy.

    • @paulgalow2728
      @paulgalow2728 Před rokem +1

      Did not know about the watch option. Great tip and thanks for sharing.

  • @MrTechnician_
    @MrTechnician_ Před 3 lety +4

    Absolutely love this channel. Incredible editing and great documentation. Just what I need to rebuild my homelab. :)

    • @TechnoTim
      @TechnoTim  Před 3 lety +1

      Thank you so much!

    • @MrTechnician_
      @MrTechnician_ Před 3 lety

      @@TechnoTim :D I’ve got big plans to rebuild my truenas server into a virtualization host for my home services (including truenas itself) and i will continue to refer to your videos.

  • @yukinok25
    @yukinok25 Před 3 lety

    Awesome tutorial, been using traefik since 1.0 but this video helped me to understand a few things clearly, thanks for your work!

  • @BenThatOneGuy
    @BenThatOneGuy Před 3 lety +2

    How do you literally upload exactly what i've been looking for, one day after i began reading up on it?!?
    As always, awesome video!

  • @rubydoe1997
    @rubydoe1997 Před 3 lety +20

    I was struggling with setting up a reverse proxy yesterday, today this video pops up in my feed. Great timing! :D

  • @Hydraulix
    @Hydraulix Před 3 lety +7

    Oh heck yeah!! Thanks Tim! This was just what I needed, like I mentioned last time!
    The k8s focused rancher ones were great, but I have been running portainer with regular docker containers and hoping for inspiration to add traefik. Had been using Caddy for certs and it's really easy, but Traefik supports SSO with Authelia and Caddy doesn't. Any odds on setting up SSO with Authelia next? Thanks very much, you're the best!!

  • @jdpdata
    @jdpdata Před rokem +32

    Hi Tim, great tutorial! I've been running SSL on all my homelabs projects for couple months now without any issues. But recently I had some problems renewing certificate. I found that I had to add 'delayBeforeCheck: 5' in traefik.yml file under dnsChallenge section for cert to renew. I guess Cloudflare has changed something on their end and I needed this line to add a delay for a few seconds otherwise I would always get certificate null error. You may want to add this to your documentation to help others encountering this issue. Banged my head for days until I figure this out. Thanks again for all your great tutorials.

    • @JakeThe_Dog
      @JakeThe_Dog Před rokem +3

      Holy Crap man! You've saved me hours of trial and error! I hope this gets the attention it deserves.

  • @amarul92
    @amarul92 Před 3 lety

    love that i found your channel, learning more here than i did at uni

  • @anishpatelwork
    @anishpatelwork Před rokem

    Amazing tutorial. I can't tell you how long I've been annoyed with my homelab services not using SSL or just using the self signed stuff... it's so nice to have these being properly secured now.

  • @elsammael
    @elsammael Před 3 lety +23

    This seems to be a bit more complex then what I am doing directly with PFSense and its HA Proxy and ACME plugins, but I like the nice dashboard that Traefik provides! Thanks Tim for the nice walk through!

    • @DrDingus
      @DrDingus Před rokem +1

      How is that setup going?

    • @theangelofspace155
      @theangelofspace155 Před 10 měsíci

      It does not go over how this intereact with the regular reverse proxy. I have been stucked for weeks. Since my pfsense forward everything to my main traefik.

    • @Psyt0s
      @Psyt0s Před 7 měsíci +1

      Automation man!! automation....

  • @BradleyHerbst
    @BradleyHerbst Před 3 lety +20

    I definitely prefer your more advanced videos will you show a whole solution like these. Keep it up!!

  • @cryptagion
    @cryptagion Před 6 měsíci

    I had spent two days trying to figure out how to do this, and I finally got it after carefully going through your video. Thank you so much for helping the community like this, I really appreciate it.

  • @mauricestriek2605
    @mauricestriek2605 Před 2 lety

    Dude! Nice work! It's not about the complexity, it's about the way you describe and explain something...you nailed both.

  • @vadiktuz
    @vadiktuz Před 3 lety +10

    Techno Tim is legit the best. Really motivating and quality IT configuration content

  • @sinister_kiid
    @sinister_kiid Před rokem +5

    Hey Tim, I'm having a hard time. I'm following this tutorial so that I can subsequently follow your pterodactyl tutorial and I think I may be in over my head. For example, @8.40 you say "just make sure you have a DNS entry pointing back to this portainer".
    Now, you said that so casually.. but how do I do that? Where do I find this portainers IP? Is it the IP of the server portainer is running on, or do I find that in portainers dashboard? Should I be going further back in your tutorials until I understand the things in this tutorial that do dont fully explain? and if so, where do I start?
    Thanks.

  • @FrigidSouls
    @FrigidSouls Před 9 měsíci

    Tim! You seem to know what I am working on every time a video comes out. Thank You!!!

  • @JPEaglesandKatz
    @JPEaglesandKatz Před rokem

    Big kudos to you Tim, a great guide and the only one I could find online that explains it so well! Keep on Rockin!!!!

  • @jrucker2004
    @jrucker2004 Před 2 lety +20

    In a more recent video (I think it was the overview of your whole lab) you mentioned you now have two instances of Traefik, one for external traffic, and the one described in this video.
    I spent several days trying to set up a second instance to pass external traffic along, and was never able to get it to work. Would you be willing to do a more in depth tutorial about that setup?

    • @cxl520
      @cxl520 Před rokem

      I just use you Pihole DNS setting for local DNS (must use as your main DNS), external use Cloudflare, both of them use the same certificate with different subdomains, It's just that the internal subdomains name can only be used on the internal network because this domain name is not exist on public DNS.

  • @hpe_adventures
    @hpe_adventures Před 3 lety +3

    Thank's for the video !
    What about doing the same thing within and for Rancher ?

  • @dionysiskouris9581
    @dionysiskouris9581 Před 2 lety +1

    I stumbled upon your channel today (started with high availability pihole), and I am amazed by the quality of your videos! It was insta subscribe, and I hope you will continue the excellent work Tim!

    • @TechnoTim
      @TechnoTim  Před 2 lety +1

      Thank you so much! Welcome!

  • @andreimihalescu209
    @andreimihalescu209 Před 2 lety

    You're a legend, this is a great match for my setup. Thanks for your research and hard work, saved me some time.

  • @BASthedog
    @BASthedog Před 3 lety +8

    How do you decide whether to use Kubernetes or Docker?

  • @rgmelkor
    @rgmelkor Před 10 měsíci +3

    Thanks for the video, can i add labels to a stack in another portainer environment (another proxmox host) ? how?

  • @jacdyb
    @jacdyb Před 2 lety

    Thank you very much. I am rebuilding my homelab and I was looking for instructions about certificates. Greatly explained, thanks again!

  • @anibalandrade754
    @anibalandrade754 Před rokem

    Congrats for the tutorial! Very helpful. One of the best channels for the Home Lab enthusiasts.

  • @stuartwilson2277
    @stuartwilson2277 Před 3 lety +6

    Do you have network diagram, it helps some of us understand the flow and config easier.
    Great vid as always, well explained. Thanks Tim

    • @TechnoTim
      @TechnoTim  Před 2 lety

      I do! czcams.com/video/Cs8yOmTJNYQ/video.html

  • @ThisIsAitch
    @ThisIsAitch Před rokem +5

    Hey Tim, this is awesome, I have got everything internally and external, to docker, set up flawlessly. However, I think I might be missing something, as I am a little stuck on how to configure this to allow internet-facing external access.
    I have configured the Cloudflare DNS and port forwarded, but I think I am missing some key config on Traefik itself? I would absolutely love it if you could reply (or even make a video!) on how *you* would go about setting up internet facing services through Traefik!

    • @ChrisSuarez229
      @ChrisSuarez229 Před rokem +1

      Hi Tim, I'm having the same issues too. I've been able to get everything working while I'm on my local network. Once I'm outside, I get a "too many redirects" error. I'm using Cloudflare tunnels, and I've tried disabling any kind of redirect at the CF level with no luck. Each time I remove the redirect in Traefik I seem to break things. Any guidance will be greatly appreciated

  • @VoklavTube
    @VoklavTube Před 3 lety

    brilliant, amazing work. affordable and very valuable. Tim, you are a great man.

  • @rhb.digital
    @rhb.digital Před 3 lety +1

    great job man.. you're videos are always solid !! Greetings from Denmark

  • @squalazzo
    @squalazzo Před 3 lety +3

    Tim, i think there's a bit of a confusion in commands... there are a bit of "cd .." which you show in video but missing on docs page... also the config.yaml is done in the data folder, not in its parent one, as in video... please share full folders structure for both portainer and traefik, thanks :)
    oh, and again, you make a data folder inside portainer one, but you refer to the portainer one in docker-compose.yaml instead of data :)
    edit: adding that the user:password (encoded via htpasswd) generates other errors on the docker-compose up -d command, because some "$" in the password which triggers some variable substitution in while running docker-compose, that should be escaped some way... i fixed by removing the initial and final backtick and converting double back-slashes to single ones
    oh, and you need just the apache addon package, no need for the apache2 one to just generate password hashes

    • @squalazzo
      @squalazzo Před 3 lety

      man, you rock! All working here, after addressed the few problems i reported, thanks a lot!

    • @TechnoTim
      @TechnoTim  Před 3 lety +2

      @@squalazzo Thanks! Docs are open source and have been fixed!

  • @kylegl_
    @kylegl_ Před 2 lety +3

    Heads up. It looks like in the video you create your traefik config.yml in the traefik directory (traefik/config.yml). But it's supposed to be at traefik/data/config.yml. I got hung up on this for a while. The documentation does show it in the right place, however.

    • @TechnoTim
      @TechnoTim  Před 2 lety +2

      Thanks! Yeah, I noticed after the video. the docs should be right. Thank you and sorry!

  • @samtoohey93
    @samtoohey93 Před 2 lety +1

    I struggled so much with Swag and getting anything running securely. This vid honestly saved my sanity, thank you so much Tim!

  • @nadavraz4334
    @nadavraz4334 Před rokem

    It’s been a year but thank you for being an inspiration, you’re awesome 🎉

  • @x86cowboy
    @x86cowboy Před 3 lety +44

    If you had a network map or diagram of each step you were configuring; that would help a lot.

    • @TechnoTim
      @TechnoTim  Před 3 lety +12

      Great feedback!

    • @TechnoTim
      @TechnoTim  Před 2 lety +3

      I do now czcams.com/video/Cs8yOmTJNYQ/video.html

    • @streambarhoum4464
      @streambarhoum4464 Před rokem

      @@TechnoTim
      Sorry Tim for this long reply , I just wanted to point out the importance of the topic to ensure privacy protection, so do not be tempted by the positives that they decorate for the public, because cloud servers, including cloudflare, can track all users of their platform! And many other negatives... That is why we had to find a private alternative that could not be tracked, even if it was difficult for us to protect it locally.
      With much thanks and appreciation

  • @yuriw777
    @yuriw777 Před 3 lety +3

    Great video thx 👍
    One question - could this had been done in Rancher ? Why not Rancher if yes, why docker ?

    • @sig_kill
      @sig_kill Před 2 lety

      He did a video where he set up Let's Encrypt and Traefik on Rancher, about 8 months before this one... I think this is more of a "because we can" video instead of following along the vein of setting up one holistic infrastructure consistent with the other videos. I landed here first, and realized I probably want to follow along with that video instead. It would have been nice for Tim to call that out, though.

  • @4tech917
    @4tech917 Před rokem

    Hello Timothy, thanks for the tutorials. i've followed the documentation. finally it works

  • @mariembuenaventura1278
    @mariembuenaventura1278 Před 3 lety +1

    Thank you so much sir. I just have so many prerequisite skills that I need to learn to fully understand the concept.

  • @laka0013
    @laka0013 Před měsícem

    Took me a while to get this working, but now everything is up and running thanks to your guide! TYVM!

  • @beprivatecdblind7831
    @beprivatecdblind7831 Před 4 měsíci

    thank for this between you and Christian Lempa I was able to get traefik working the way I wanted.

  • @flahiker
    @flahiker Před 3 lety

    Interesting approach. I was using a domain for my home network but had to issue Lets Encrypt certs for each service I wanted to host on the network. I will need to give this a go. Thanks for the great tutorial (once again!)

  • @refinery__
    @refinery__ Před 2 lety

    Worked like a charm. Took me a while to figure out how to connect another DNS provider, but i got it up and running! Thank you very much

  • @JonaYepiz
    @JonaYepiz Před 3 lety

    Man you are seriously awesome i am still trying to catch up to all the tutorials you post you are great

  • @alexanderaric4006
    @alexanderaric4006 Před rokem

    Just watched it again a year later..... amazing material, thank you Tim.

  • @DShawConsulting
    @DShawConsulting Před rokem +1

    Thanks for the great tutorial. After fixing a few of my typos and scratching my head a bunch I got everything to work! Liked and subscribed!

    • @TechnoTim
      @TechnoTim  Před 10 měsíci

      Glad it helped! Thank you!

  • @raulpeiroten-ayuso7553

    simple
    straight to the point! i am subscribing!

  • @krzychaczu
    @krzychaczu Před rokem

    This is gold! Thank you for sharing, Tim! 👍🏅

  • @TheFunny298
    @TheFunny298 Před 2 lety

    Thanks a ton for this godly work :) I have completed my setup using AWS Route 53 DNS Provider.

  • @TheRobMozza
    @TheRobMozza Před 2 lety

    I literally need to rewatch this, thanks TT

  • @randleqgod
    @randleqgod Před 3 lety

    This is exactly what I needed! THANK YOU!!!!

  • @cutebot3342
    @cutebot3342 Před 2 lety +1

    We need more people you! Absolutely great explanations and content!

  • @conorkeane
    @conorkeane Před 3 lety +1

    Duuuuuuuuude, just got this working now! Thanks for the guide Tim!

  • @TheoParis
    @TheoParis Před 3 lety

    Congrats on almost 50k subscribers 👏🏼

  • @CharlieBasta
    @CharlieBasta Před 2 lety +1

    This is an amazing video walkthrough. You are very good at educating and explaining things. Thank you.

  • @cxl520
    @cxl520 Před rokem +2

    Nice! I just learn how to config Round Robin and Failover under services in dynamic config file, I will implement this later. With this feature, this thing is even more powerful for home LAB.

  • @TheRowie75
    @TheRowie75 Před 3 lety

    You are awesome man!! TXH for sharing your nice stuff!

  • @jeremye997
    @jeremye997 Před rokem

    thanks for the great content man! you really know your stuff!

  • @uuu12343
    @uuu12343 Před rokem

    I've been watching your older videos because they seem to always be relevant LMAO, but really good stuff
    Recently been testing out on containerizing/dockerizing my home lab/server utilities that were originally installed on host system
    What are your thoughts, do you think it's better to install on host system? Or to install via docker(-compose)?

  • @ChristopheSaelens
    @ChristopheSaelens Před 3 lety

    Very informative video. Thanks to you I finally got this working!

  • @rickdavidson8895
    @rickdavidson8895 Před rokem

    Best tutorial on this topic I have seen. Thank you!

    • @TechnoTim
      @TechnoTim  Před rokem +1

      You should check out my others 😅. Thank you!

  • @zacs1114
    @zacs1114 Před 3 lety

    Great video! Reverse proxy has always been a pain for me. Would love to see your take on scripting things like toolset installs or container initializations.

  • @NgodingPython
    @NgodingPython Před rokem

    I patiently followed your guide, and now everything on my homelab is using wildcard certificate from my domain name
    thank you, you are my inspiration for building self hosting app

  • @CleverNinja
    @CleverNinja Před rokem

    I've been using NGINX for about 2 years to setup reverse proxy at home. This method seems ALOT easier in comparison to managing a long .conf file or multiple .conf files for subdomains. I'm gonna have to look into setting this up when I have a long weekend free

  • @edzme
    @edzme Před 2 lety

    i love how you explain things, thank you for that

  • @paolonervi2208
    @paolonervi2208 Před rokem

    Hi Tim,super useful as Always..thank you!!!greetings from Italy.

  • @streambarhoum4464
    @streambarhoum4464 Před rokem +2

    @Techno Tim
    Sorry Tim for this long reply , I just wanted to point out the importance of the topic to ensure privacy protection, so do not be tempted by the positives that they decorate for the public, because cloud servers, including cloudflare, can track all users of their platform! And many other negatives... That is why we had to find a private alternative that could not be tracked, even if it was difficult for us to protect it locally.
    With much thanks and appreciation

  • @TheRevilhong
    @TheRevilhong Před 3 lety

    When you mean everything, Probably can share more on integration of ssh, ldaps, smtps, and etc.
    Thanks and appreciated for the knowledge sharing.

  • @ZimTachyon
    @ZimTachyon Před 10 měsíci

    Tim, you are inspirational. I hope this small token of my appreciation keeps you inspired.

  • @Jrac86
    @Jrac86 Před rokem +1

    Thanks! Your videos are awesome and are extremely helpful as I start up my own home lab

    • @TechnoTim
      @TechnoTim  Před rokem

      Great to hear! Thank you so much!!!!!

  • @vvsxmja
    @vvsxmja Před 3 měsíci

    Very straightforward and helpful, +1 for this video

  • @mewintle
    @mewintle Před 2 lety +1

    I love the way this skips along the surface of the topic, allowing my brain to see the big picture with just enough anchor points to make it concrete and relatable. I know what a container and a reverse proxy and a DNS server are and how certificates work. I don’t need or want to be distracted by any explanations of those. We need to keep it moving or my buffer will overflow. I can explore sub-topics separately.
    You have a perfect style for a top-down learner. Thank you.

  • @andydiep4162
    @andydiep4162 Před 2 lety

    THANK YOU SO MUCH! it took so long to try to set it up but it worked. THANKS!

    • @TechnoTim
      @TechnoTim  Před 2 lety +1

      Congrats! It’s a great feeling isn’t it???

  • @beprivatecdblind7831
    @beprivatecdblind7831 Před rokem

    Great video, took a about 5 hours to trouble shoot some issues, and when I worked them out felt stupid. For those like me who take a little time (yes a silly pun) to catch on. The txt record error in my case was fixed with adding a 5 minute delay to the letsencrypt request, `delayBeforeCheck: 5` put it after the dnsChallenge provider. Not sure why but I had issues with putting quotes around the ports in the compose file you did not have them, but when looking at Christian Lempa's recent video and compose file he did, once I removed them it fixed one of my issues. :)

  • @streambarhoum4464
    @streambarhoum4464 Před rokem +2

    Hey Man thanks for all your great efforts in this wonderful channel , yet i would ask you if is it worth to use traeffik or nginix only with port forwarding, or using cloudflare zeroTrust without port forwarding, or use them both.. In order to get optimum security for local network ?
    Which is the best solution ?
    Also, im confused if we could trust cloudflare for securing our network?

  • @carstenr.1682
    @carstenr.1682 Před rokem +1

    Thanks a lot, you helped me to setup Traefik perfectly.

  • @southtowntn
    @southtowntn Před rokem

    You can do this if have a dynamic IP address from your ISP. I image most non business location are going to have a dynamic IP address from their ISP. There are several DDNS (Dynamic DNS) options, some free some a paid service. I use Cloudflare DNS, for this. In short you run/host a small utility that checks your current IP address at a set interval to your current DNS record. If it doesn't match then with an API key it updates the DNS record at Cloudflare. I use an inbound VPN, host a PBX, cloud storage, ect. and it just works despite having a dynamic IP address. I set it up in pfSense to handle the DDNS since it is at the head of the network. Not everyone is using pfSense, but there is also docker containers out there that do the same thing.

  • @joshanderson4658
    @joshanderson4658 Před rokem +2

    I think I'm getting myself confused on what to put in on the host sections. Is it the domain that I set up internally via pihole or is it the domain through cloud fare? I'm still getting familiar with things to setup my pterodactyl server. 😅 Love your videos by the way!

  • @henderstech
    @henderstech Před 2 lety

    Thank you for your videos. I use videos like this to learn and I appreciate it so much.

  • @robertsv539
    @robertsv539 Před 2 lety +1

    Love these videos on ensuring that SSL is used ubiquitously across services. Is there any chance you can create the same but with NPM as Traefik is a bit of a pain to manage if there's a large count of dunning containers.

  • @jeremyhu7808
    @jeremyhu7808 Před rokem

    Thanks so much for the walkthrough, really straightforwards to follow, even for someone newer to self-hosting and linux.
    I noticed at 5:17 you suggest binding to the docker socket; I've read on various other Traefik/docker guides that this can be a security liability. Have you ever tried addressing this? I noticed that /var/run/docker.sock was set as read-only in the docker-compose, but I heard this doesn't really get around the security issues.

  • @wholoki
    @wholoki Před 2 měsíci

    Very helpful, thank you! I did notice that it didn't cover sending traffic via docker (these templates do ip:port), so I am diving in to see if I can find anything!

  • @shetuamin
    @shetuamin Před 2 lety

    Thanks for great tutorial. Today i finished this and get ssl every container.

  • @DeadlyDragon_
    @DeadlyDragon_ Před 3 lety +2

    I prefer nginx for my reverse proxy currently. I do separate my internal records(bind) from my recursive resolver (pi-hole) bind has always been 100% reliable. And because of that it is the fallback for when pihole decides to become brain less (happens more than it should)

  • @joransrb
    @joransrb Před 2 lety

    This is great video and got me up and running in no time, thanks 😊 I got a question tho, or a video request. How can you use this setup with multiple domains and ex 2 different cloudflare accounts? (I got my personal CF account with domainA, but also want to use a secondary CF account on domainB) is this something you could do a video on? Been all over Reddit/Traefik git issues etc but I can’t wrap my head around it.
    Anyways, imma check out your stream and keep up the awesome videos :)

  • @ckthmpson
    @ckthmpson Před 10 měsíci +1

    I've been wanting to make the switch from NPM to Traefik for the longest time, but the complexity has always caused be to shy away. This put me over the edge. Thanks so much @TechnoTim. One area I'm not clear about...how would one extend this to services that do need to be reachable externally? Is it as simple as port forwarding 443 to the Docker Host? And if one wanted a separate cert services that are not local, what does that config look like?