# How to Configure Docker Networking with Traefik: A Complete Guide

> Configure Docker networking with Traefik by creating a bridge network and using container labels to route traffic securely and efficiently.

- Repository: [Michael Royal/Self-Hosting-Guide](https://github.com/mikeroyal/Self-Hosting-Guide)
- Tags: how-to-guide
- Published: 2026-06-17

---

**Create a dedicated Docker bridge network, attach Traefik and your services to it, and use container labels to route traffic through Traefik's published ports while keeping backend containers isolated from the host.**

Traefik functions as a modern edge router and reverse proxy for containerized environments. When you configure Docker networking with Traefik according to the `mikeroyal/Self-Hosting-Guide` repository, you implement an isolated bridge network that enables automatic service discovery while securing internal containers. This architecture, referenced in the project's README at lines 460 and 5287, represents the recommended pattern for self-hosting with Docker and Traefik.

## Understanding the Docker Bridge Network Architecture

A **Docker bridge network** creates an isolated layer where containers can resolve each other by hostname without exposing ports directly to the host. According to the Self-Hosting-Guide's Docker Network entry at line 5287, this isolation prevents port conflicts and hides internal services from external networks.

The **Traefik Docker provider** watches Docker events and automatically creates routes for containers that expose ports and carry the appropriate labels. This provider reads the Docker socket to detect container start/stop events, eliminating the need for manual configuration reloads.

Three core components define this setup:

- **The proxy network** – A custom bridge network (typically named `proxy`) that only Traefik and public-facing services join
- **Container labels** – Metadata attached to containers that tells Traefik which hostnames, paths, and middleware to apply
- **Published ports** – Only Traefik's ports (80 and 443) publish to the host; backend services remain internal

## Step-by-Step Configuration

Follow these steps to implement the pattern documented in the Self-Hosting-Guide.

**Create the dedicated bridge network.**

```bash
docker network create proxy

```

This network isolates your services while allowing DNS resolution between containers.

**Configure Traefik with the Docker provider.**

Mount the Docker socket read-only so Traefik can monitor container events without full host access. Enable the Docker provider in your static configuration to activate automatic service discovery.

**Attach services to the network.**

Every container that Traefik should route to must join the `proxy` network. Do not publish ports for these backend services—only Traefik requires published ports.

**Apply routing labels.**

Add Docker labels to each service container defining the router rules, entrypoints, and TLS settings.

## Complete Docker Compose Configuration

Below is the minimal [`docker-compose.yml`](https://github.com/mikeroyal/Self-Hosting-Guide/blob/main/docker-compose.yml) from the Self-Hosting-Guide analysis that implements this networking pattern. This configuration creates the `proxy` network, runs Traefik with the Docker provider enabled, and deploys two example services that Traefik automates.

```yaml
version: "3.8"

services:
  traefik:
    image: traefik:v2.11
    command:
      - "--api.insecure=true"
      - "--providers.docker=true"
      - "--entrypoints.web.address=:80"
      - "--entrypoints.websecure.address=:443"
      - "--certificatesresolvers.myresolver.acme.tlschallenge=true"
      - "--certificatesresolvers.myresolver.acme.email=you@example.com"
      - "--certificatesresolvers.myresolver.acme.storage=/letsencrypt/acme.json"
    ports:
      - "80:80"
      - "443:443"
      - "8080:8080"
    volumes:
      - "/var/run/docker.sock:/var/run/docker.sock:ro"
      - "letsencrypt:/letsencrypt"
    networks:
      - proxy

  whoami:
    image: containous/whoami
    labels:
      - "traefik.enable=true"
      - "traefik.http.routers.whoami.rule=Host(`whoami.local`)"
      - "traefik.http.routers.whoami.entrypoints=web"
    networks:
      - proxy

  whoami-secure:
    image: containous/whoami
    labels:
      - "traefik.enable=true"
      - "traefik.http.routers.whoami-secure.rule=Host(`whoami-secure.local`)"
      - "traefik.http.routers.whoami-secure.entrypoints=websecure"
      - "traefik.http.routers.whoami-secure.tls=true"
      - "traefik.http.routers.whoami-secure.tls.certresolver=myresolver"
    networks:
      - proxy

networks:
  proxy:
    driver: bridge

volumes:
  letsencrypt:

```

**Key implementation details:**

- The `proxy` network uses the `bridge` driver, creating the isolated environment referenced at line 5287 of the Self-Hosting-Guide README
- Traefik mounts `/var/run/docker.sock` as read-only (`ro`) to safely monitor container lifecycles
- Backend services (`whoami` and `whoami-secure`) have no `ports` mapping, rendering them inaccessible except through Traefik
- Labels define the router rules; `traefik.enable=true` activates discovery for each container

## Advanced Networking Patterns

**Network isolation for databases.**

Create a second bridge network (e.g., `internal`) for databases or cache services that should never receive external traffic. Only attach these containers to the `internal` network, keeping them completely isolated from Traefik and the public-facing `proxy` network.

**Middleware configuration.**

Implement HTTPS redirects and authentication by adding middleware labels. For example, attach `traefik.http.middlewares.redirect-https.redirectscheme.scheme=https` to enforce secure connections, then reference this middleware in your router definitions.

**External configuration files.**

For complex setups, separate the static configuration (command-line arguments in Compose) from the dynamic configuration. Mount a [`traefik.yml`](https://github.com/mikeroyal/Self-Hosting-Guide/blob/main/traefik.yml) file and additional route definitions into the container to manage routing logic outside of Docker labels.

## Summary

- **Configure Docker networking with Traefik** by creating a dedicated bridge network that isolates services while enabling internal DNS resolution
- Reference the **Self-Hosting-Guide** at [`README.md`](https://github.com/mikeroyal/Self-Hosting-Guide/blob/main/README.md) line 460 for Traefik recommendations and line 5287 for Docker networking concepts
- Publish only **Traefik's ports** (80/443) to the host; backend containers remain internal to the bridge network
- Use **Docker labels** to define routing rules, entrypoints, and TLS settings for each service
- Mount the **Docker socket read-only** to allow Traefik's provider to detect container changes safely

## Frequently Asked Questions

### What Docker network driver should I use with Traefik?

Use the **bridge driver** for standard deployments. The bridge network creates an isolated subnet where containers communicate via internal DNS names without exposing ports to the host. This is the default and recommended driver for Traefik deployments as documented in the Self-Hosting-Guide.

### Do I need to publish ports for my backend services?

No. **Only publish ports for Traefik itself** (typically 80 and 443). Backend services should attach to the same bridge network as Traefik but omit any `ports` mapping in your Compose file. Traefik routes traffic to these containers using their internal network names and exposed ports, keeping them isolated from direct external access.

### How does Traefik discover new containers automatically?

Traefik uses the **Docker provider** to watch the Docker daemon via the mounted socket file. When you start a container with `traefik.enable=true` labels on the same network, Traefik detects the event and immediately creates or updates routes without requiring a restart or configuration reload.

### Can I use multiple networks with Traefik simultaneously?

Yes. You can attach Traefik to multiple networks—such as a `proxy` network for public services and an `internal` network for private backend communication. However, Traefik can only route to containers that share at least one network with it, so ensure any service requiring external access shares the `proxy` network.