Pages touched: Sources/index, Sources/Dev/index, Sources/Homelab/index,
Wiki/index, Wiki/Reference/index, Wiki/Reference/{ob1,traefik,gitea},
Wiki/Homelab/proxmox, Wiki/Dev/pbs-hub, Wiki/Dev/ai-memory-architecture
Pages created: none
Entities promoted: none (proposed: trellis, vault-mcp, petalbrain, pbs-hub-mcp, knot-dns, herbyeos)
Synthesis: ai-memory-architecture updated (9->17 sources) for petalbrain consolidation,
shared public.embeddings, OB1 two-layer + reflection job, JSONL watcher, Trellis
Contradictions flagged: OB1 "Supabase" -> self-hosted pgvector:pg17/petalbrain + Ollama (corrected)
Tags proposed: none
Notes: 8 pipeline test artifacts flagged for cleanup (not deleted); session-note->session-notes
lint pending; Venture unchanged
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
3.5 KiB
| type | path | tags | created | updated | |||
|---|---|---|---|---|---|---|---|
| entity | Wiki/Reference |
|
2026-05-08 | 2026-05-24 |
Traefik
What it is
Traefik is the reverse proxy and ingress router for PBS infrastructure. It handles TLS termination, service routing, middleware chains, and integration with Cloudflare for DNS and tunnel-based access. Traefik runs as a Docker container in the PBS Linode stack and is the entry point for all HTTP/HTTPS traffic to PBS services.
Current state
Active at version 3.6.11 (upgraded March 2026 during the server stability hardening session). Key configurations:
- TLS — wildcard certificates via Let's Encrypt + Cloudflare DNS challenge
- Routing — all PBS services (WordPress, n8n, pbs-hub, Gitea, MySQL proxy, etc.) routed through Traefik labels
- Middleware —
block-wpcronmiddleware prevents direct HTTP access towp-cron.php(replaced by Supercronic sidecar) - Cloudflare Tunnel — Traefik sits behind Cloudflare Tunnel for MCP and some homelab services
- Knot DNS — primary and secondary DNS integrated with Traefik TLS pipeline
The homelab runs its own Traefik 3.7 on VM 102 (10.0.21.181) with Docker + file + ACME providers, separate from the PBS instance. It holds the LE prod wildcard *.herbylab.dev (Cloudflare DNS-01) and fronts a growing set of services — whoami, the Traefik dashboard (TLS + basicauth), pihole, and openwrt LuCI — each reachable behind a cloudflared tunnel (traefik-vm).
Where it lives
- PBS Linode Docker stack (
traefikservice in Docker Compose) - Config: labels on Docker Compose services +
traefik.yml/dynamic/config files - Homelab: separate Traefik instance (or shared) for
.herbylab.dev
Related projects
- Sources/Homelab/traefik-deployment — full Traefik deployment plan
- Sources/Homelab/server-stability-and-security-hardening — v3.6.11 upgrade
- Sources/Homelab/wp-cron-supercronic-deploy — block-wpcron middleware
- Sources/Homelab/ufw-docker-outage-fix — UFW + Docker/Traefik outbound rules fix
- Sources/Homelab/homelab-mcp-server — MCP server behind Traefik
- Sources/Homelab/2026-05-11-traefik-phase1-phase2-wildcard-canary — homelab VM 102: wildcard cert + canary
- Sources/Homelab/2026-05-21-traefik-routes-for-pihole-openwrt-us-test-authy-static-ip-cutove — pihole/openwrt routes
- Wiki/Reference/cloudflare — tunnel + DNS
- Wiki/Reference/authentik — auth layer
- Wiki/Homelab/homelab-ingress-stack — synthesis
History
- Ongoing — Core PBS ingress layer
- March 2026 — Upgraded to v3.6.11 during server stability work
- March 2026 —
block-wpcronmiddleware added when Supercronic replaced WP-Cron - 2026 — UFW
after.rulesfixed to restore Docker/Traefik outbound routing after UFW misconfiguration caused outage - 2026-05-06 — Traefik used as ingress for MCP server at
mcp.herbylab.dev - 2026-05-11 — Homelab Traefik 3.7 on VM 102: Phase 1.6 wildcard cert + Phase 2 canary; dashboard locked behind TLS+basicauth;
traefik-vmcloudflared tunnel - 2026-05-21 —
pihole+openwrtrouted on*.herbylab.dev;addPrefixredirect-loop and self-signed-backend (insecureSkipVerify) lessons captured