Skip to content

Software

Traefik Configurator

Version 1.3.1 · 19/09/2026
WordPress 5.6+ or Docker on any Linux host
Check your download: file names and SHA-256 checksums published 22/09/2026

Compare the checksum of the file you downloaded with the one listed here. If they differ, the file is not the one published on this page - delete it and download it again.

  • tpv-traefik-configurator-1.3.1.zipf07b3080d1287a4f574d3913f0ecd8d0b8199db7c5b4d987dc8cb3dfe6829db6
  • tpv-traefik-console-1.0.1.tar.gz679cfa30505dc92438a3187f0bdf537f6927d2f955c79cbbfbea5fa33c1496c7

Windows (PowerShell): Get-FileHash <file>   Linux: sha256sum <file>   macOS: shasum -a 256 <file>

How to install and use it

Docker console (any Linux host, x86-64)
  1. Load the image and start it. Put your own network in TPV_ALLOW_IPS: only those addresses can open the console.
    docker load -i tpv-traefik-console-1.0.1.tar.gz
    docker run -d --name tpv-console --restart unless-stopped \
      -p 8099:80 -v tpv-console-data:/data \
      -e TPV_ALLOW_IPS=192.168.1.0/24 \
      tpv-traefik-console:1.0.1
    docker logs tpv-console
  2. The log shows the administrator password once, at first start. Keep it.
  3. From any browser on that network, open http://<docker host>:8099 and sign in as admin.
  4. On Proxies, add your Traefik server. "Publish only" is enough for routing: the proxy pulls what you publish. To manage its static configuration and plugins too, choose SSH, press "Generate a key" and paste the commands it shows on the proxy as root - they fetch the helper from the console and let the key run nothing else - then press "Test the connection".
  5. On Routing, add routers, services and middlewares. On Publish, make a token and add the pull address it shows to your Traefik as an HTTP provider, then read the checks and publish. Static config and Traefik plugins change the proxy's own configuration, with the old copy kept to roll back to.
  6. The data volume holds everything - proxies, revisions and keys. Back it up. To upgrade, load the new image and run the same command with the new version; the volume is kept.
WordPress plugin
  1. In WordPress go to Plugins > Add New > Upload Plugin, choose tpv-traefik-configurator-1.3.1.zip, press Install Now, then Activate.
  2. Open Traefik in the admin menu. The overview lists the steps: on Settings make a token and copy the endpoint address, add it to your Traefik as an HTTP provider, then add domains on Hosts and publish.
  3. To change the proxy's static configuration and plugins as well, fill in the Proxy host tab and run the command it shows on the proxy, as root.

A question about installing or using it? Ask in the comments below, or through the contact page.

Problem

Traefik is configured by editing YAML on the machine, so a route change needs a shell, and a typo in the static file takes the proxy down at the moment the dashboard becomes unreachable.

Solution

Build the routing in a form and publish it at one token-protected URL the proxy fetches for itself; reach the machine only for the static file, over an SSH key pinned to a single command. Every static write backs up, restarts, verifies against a real request and restores the backup if the proxy does not come back.

Result

Routing changes without a restart or a shell, static changes cannot leave the proxy down, and a compromised website has no write path into the proxy. The same engine ships as a WordPress plugin and as a Docker console managing any number of proxies.

How I found it

The two kinds of Traefik configuration behave completely differently, and conflating them is what makes most tools for this either unsafe or useless. Dynamic configuration is fetched, so it can be published read-only and needs no credentials at all. Static configuration is read once at startup and never fetched, so it genuinely requires a way onto the machine — and that is the only part that does.

The self-hosted estate, from the public edge to the containers behind itA small public server joined back by an encrypted tunnel, a hypervisor of single-purpose containers behind it, detection on every host and blocking where blocking is cheap.
A small public server joined back by an encrypted tunnel, a hypervisor of single-purpose containers behind it, detection on every host and blocking where blocking is cheap.

Traefik is the reverse proxy in front of a great many self-hosted estates, and it is configured by editing YAML on the machine. That is fine until the person who needs a route added is not the person with a shell, or until a typo in the static file takes the proxy down at the exact moment nobody can reach the dashboard to see why.

The Traefik Configurator puts the whole of that behind a web interface, and does it without giving the web interface any power over the proxy it does not need.

Two products, one engine

A WordPress plugin, for an estate that already runs a site, and a Docker console that runs anywhere Docker or LXC does and manages any number of proxies. The schema, the YAML reader and writer, the emitter, the validator, the static-file surgery and the host connection are the same files in both: one implementation of the dangerous work, so a fix lands in both at once.

The proxy pulls; the website never pushes

Routers, services, middlewares and TLS options are built in a form, checked, and published at one read-only token-protected URL. Traefik fetches it for itself and reloads without restarting. No SSH key, no file share, no write path from the website to the proxy — a compromised site cannot reach in and rewrite anything; the worst it can do is serve a different document at a URL the proxy was told to trust.

Static configuration, which cannot be pulled

Entry points, certificate resolvers, logging and Traefik’s own plugins are read once at startup and never fetched, so changing them needs a way onto the machine. That connection is an SSH key pinned to a single command: a stolen key can run thirteen read-and-change verbs and nothing else — no shell, no port forwarding, no file copy. For a Traefik in a container, a small agent beside it does the same job over HTTP.

Nothing is written without a way back

Traefik has no offline configuration check, so the only honest way to know a static change is good is to make it and ask. Every write backs up, writes, restarts, waits for the proxy to answer a real request, and puts the backup back if it does not. Published routing keeps thirty revisions, each restorable in one click.

Installing a Traefik plugin without typing a Go module path

The plugins screen lists the public catalogue — fetched live, with a copy shipped inside the product so it still works on a proxy with no route to the internet. Pick one and the module and version are filled in; the version stays editable, because pinning it is a decision and not a default.

And a screen that says what is actually true

Everything shows three different answers to “what is the configuration”: the installation itself and whether its files can be written; every configuration file on the proxy’s disk, including the ones put there by hand years ago; and what the proxy is running right now from every provider at once, HTTP, TCP and UDP. The gap between those three is usually the whole of a problem.

Works with what you already have

Traefik 2 or 3 — the dialect is detected and the right syntax written, because publishing version 3 field names to a version 2 proxy makes it reject the whole file. Any WordPress, any Docker or LXC host, any proxy you can reach. It does not assume it is the only thing configuring your proxy: a file provider, Docker labels and Kubernetes all carry on working beside it.

Switching the configurator off freezes the published document and changes no routing at all — the proxy keeps serving exactly what it last fetched.

Leave a response

Every comment is read before it appears. Yours will not show up straight away, and that is not a fault.

Not published, and not used for anything else.