Skip to main content
Version: Next

Traefik on Aruba Cloud

Deploy Traefik v3 — a cloud-native reverse proxy with automatic ACME TLS — on Aruba Cloud. Use it as the HTTPS entry point for any other service running on the same VM or in the same Docker network.

Provider version: arubacloud/arubacloud ~> 1.0 | Terraform: ≥ 1.9


Introduction​

Traefik automatically discovers Docker containers and proxies HTTPS traffic to them using service labels. TLS certificates are issued and renewed automatically via the ACME protocol using a provider such as Actalis ACME Certificates or Let's Encrypt — configure the certificatesResolvers entry with the appropriate caServer URL. Add any Docker container to the traefik-public network and label it — Traefik routes traffic automatically.


Architecture Overview​


Infrastructure Created​

ResourceDescription
arubacloud_cloudservertraefik-prod-vm (CSO1A2)
arubacloud_blockstorage20 GB boot disk
arubacloud_elasticipPublic IP
arubacloud_securitygroupTCP 80/443/8080/22 ingress

Estimated Monthly Cost​

ResourceEst. cost/mo
CSO1A2 VM~€10
20 GB disk~€3
Elastic IP~€5
Total~€18/mo

Variables​

Required​

arubacloud_client_id, arubacloud_client_secret, ssh_public_key, acme_email

Optional​

VariableDefaultDescription
traefik_version"v3.2"Docker image tag
enable_dashboardtrueEnable web dashboard on port 8080
dashboard_cidr"0.0.0.0/0"Dashboard source CIDR — restrict to your IP
ssh_cidr"0.0.0.0/0"SSH source CIDR — restrict to your IP

Deployment​

cd terraform-arubacloud-examples/traefik
cp terraform.tfvars.example terraform.tfvars
# Set acme_email in terraform.tfvars
terraform init && terraform apply

Adding a service behind Traefik​

SSH into the VM and add a Docker container with Traefik labels:

# In any docker-compose.yml on the same VM
services:
myapp:
image: nginx
labels:
- "traefik.enable=true"
- "traefik.http.routers.myapp.rule=Host(`myapp.example.com`)"
- "traefik.http.routers.myapp.entrypoints=websecure"
- "traefik.http.routers.myapp.tls.certresolver=letsencrypt"
networks:
- traefik-public

networks:
traefik-public:
external: true

Destroy​

terraform destroy

Security Recommendations​

  1. Restrict dashboard_cidr — the dashboard shows all routes and configuration. Limit to your IP.
  2. Disable the dashboard in production (enable_dashboard = false) if you don't actively use it.
  3. Use middlewares for authentication: basicAuth or forwardAuth (with Keycloak/Authentik) in front of services.

Troubleshooting​

Certificates not issuing​

  • DNS A record must point to the Elastic IP before the first request.
  • Check Traefik logs: ssh ubuntu@<IP> 'docker logs traefik --tail 100'
  • Port 80 must be reachable (Traefik uses HTTP-01 challenge).

Dashboard not accessible​

docker ps # Verify traefik container is running
docker logs traefik

References​