How to Configure Docker Networking with Traefik: A Complete Guide

Create a dedicated Docker bridge network, attach Traefik and your services to it, and use container labels to route traffic through Traefik's published ports while keeping backend containers isolated from the host.

Traefik functions as a modern edge router and reverse proxy for containerized environments. When you configure Docker networking with Traefik according to the mikeroyal/Self-Hosting-Guide repository, you implement an isolated bridge network that enables automatic service discovery while securing internal containers. This architecture, referenced in the project's README at lines 460 and 5287, represents the recommended pattern for self-hosting with Docker and Traefik.

Understanding the Docker Bridge Network Architecture

A Docker bridge network creates an isolated layer where containers can resolve each other by hostname without exposing ports directly to the host. According to the Self-Hosting-Guide's Docker Network entry at line 5287, this isolation prevents port conflicts and hides internal services from external networks.

The Traefik Docker provider watches Docker events and automatically creates routes for containers that expose ports and carry the appropriate labels. This provider reads the Docker socket to detect container start/stop events, eliminating the need for manual configuration reloads.

Three core components define this setup:

  • The proxy network – A custom bridge network (typically named proxy) that only Traefik and public-facing services join
  • Container labels – Metadata attached to containers that tells Traefik which hostnames, paths, and middleware to apply
  • Published ports – Only Traefik's ports (80 and 443) publish to the host; backend services remain internal

Step-by-Step Configuration

Follow these steps to implement the pattern documented in the Self-Hosting-Guide.

Create the dedicated bridge network.

docker network create proxy

This network isolates your services while allowing DNS resolution between containers.

Configure Traefik with the Docker provider.

Mount the Docker socket read-only so Traefik can monitor container events without full host access. Enable the Docker provider in your static configuration to activate automatic service discovery.

Attach services to the network.

Every container that Traefik should route to must join the proxy network. Do not publish ports for these backend services—only Traefik requires published ports.

Apply routing labels.

Add Docker labels to each service container defining the router rules, entrypoints, and TLS settings.

Complete Docker Compose Configuration

Below is the minimal docker-compose.yml from the Self-Hosting-Guide analysis that implements this networking pattern. This configuration creates the proxy network, runs Traefik with the Docker provider enabled, and deploys two example services that Traefik automates.

version: "3.8"

services:
  traefik:
    image: traefik:v2.11
    command:
      - "--api.insecure=true"
      - "--providers.docker=true"
      - "--entrypoints.web.address=:80"
      - "--entrypoints.websecure.address=:443"
      - "--certificatesresolvers.myresolver.acme.tlschallenge=true"
      - "--certificatesresolvers.myresolver.acme.email=you@example.com"
      - "--certificatesresolvers.myresolver.acme.storage=/letsencrypt/acme.json"
    ports:
      - "80:80"
      - "443:443"
      - "8080:8080"
    volumes:
      - "/var/run/docker.sock:/var/run/docker.sock:ro"
      - "letsencrypt:/letsencrypt"
    networks:
      - proxy

  whoami:
    image: containous/whoami
    labels:
      - "traefik.enable=true"
      - "traefik.http.routers.whoami.rule=Host(`whoami.local`)"
      - "traefik.http.routers.whoami.entrypoints=web"
    networks:
      - proxy

  whoami-secure:
    image: containous/whoami
    labels:
      - "traefik.enable=true"
      - "traefik.http.routers.whoami-secure.rule=Host(`whoami-secure.local`)"
      - "traefik.http.routers.whoami-secure.entrypoints=websecure"
      - "traefik.http.routers.whoami-secure.tls=true"
      - "traefik.http.routers.whoami-secure.tls.certresolver=myresolver"
    networks:
      - proxy

networks:
  proxy:
    driver: bridge

volumes:
  letsencrypt:

Key implementation details:

  • The proxy network uses the bridge driver, creating the isolated environment referenced at line 5287 of the Self-Hosting-Guide README
  • Traefik mounts /var/run/docker.sock as read-only (ro) to safely monitor container lifecycles
  • Backend services (whoami and whoami-secure) have no ports mapping, rendering them inaccessible except through Traefik
  • Labels define the router rules; traefik.enable=true activates discovery for each container

Advanced Networking Patterns

Network isolation for databases.

Create a second bridge network (e.g., internal) for databases or cache services that should never receive external traffic. Only attach these containers to the internal network, keeping them completely isolated from Traefik and the public-facing proxy network.

Middleware configuration.

Implement HTTPS redirects and authentication by adding middleware labels. For example, attach traefik.http.middlewares.redirect-https.redirectscheme.scheme=https to enforce secure connections, then reference this middleware in your router definitions.

External configuration files.

For complex setups, separate the static configuration (command-line arguments in Compose) from the dynamic configuration. Mount a traefik.yml file and additional route definitions into the container to manage routing logic outside of Docker labels.

Summary

  • Configure Docker networking with Traefik by creating a dedicated bridge network that isolates services while enabling internal DNS resolution
  • Reference the Self-Hosting-Guide at README.md line 460 for Traefik recommendations and line 5287 for Docker networking concepts
  • Publish only Traefik's ports (80/443) to the host; backend containers remain internal to the bridge network
  • Use Docker labels to define routing rules, entrypoints, and TLS settings for each service
  • Mount the Docker socket read-only to allow Traefik's provider to detect container changes safely

Frequently Asked Questions

What Docker network driver should I use with Traefik?

Use the bridge driver for standard deployments. The bridge network creates an isolated subnet where containers communicate via internal DNS names without exposing ports to the host. This is the default and recommended driver for Traefik deployments as documented in the Self-Hosting-Guide.

Do I need to publish ports for my backend services?

No. Only publish ports for Traefik itself (typically 80 and 443). Backend services should attach to the same bridge network as Traefik but omit any ports mapping in your Compose file. Traefik routes traffic to these containers using their internal network names and exposed ports, keeping them isolated from direct external access.

How does Traefik discover new containers automatically?

Traefik uses the Docker provider to watch the Docker daemon via the mounted socket file. When you start a container with traefik.enable=true labels on the same network, Traefik detects the event and immediately creates or updates routes without requiring a restart or configuration reload.

Can I use multiple networks with Traefik simultaneously?

Yes. You can attach Traefik to multiple networks—such as a proxy network for public services and an internal network for private backend communication. However, Traefik can only route to containers that share at least one network with it, so ensure any service requiring external access shares the proxy network.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →