Traefik HTTPS Routing On Loopback, HTTP Redirected
Traefik from the upstream release: HTTPS routes in a watched directory, plain HTTP redirected, and the dashboard and API on a loopback admin entrypoint. Traefik has no config checker, and a broken route file leaves the previous routes serving. The live test fetches a page through the default route and sees the redirect and a 404 for an unknown host. Original role, live-tested on Rocky Linux 10.
Verification
Live-testedReally deployed to a container sandbox, proven idempotent (a second run changes nothing), verified against the role’s assertions, then torn down.
Conformance
- Static validation (yamllint · ansible-lint)
Provenance
- SHA-256 checksum
- Signature (pending)
Functional
- Live-tested - applied, verified, destroyed
Last verified 2026-10-02 · podman 4.9.3 · ansible 2.21.4 · how we verify
Cite it in your README
badge · attributionPaste this beside the module in the repository that uses it. The badge is rendered from this artifact's verification record, so it reads live-tested because the record says so, and the link lands on this page.
[](https://www.iac-bazaar.com/catalog/ansible-traefik?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)
Ansible role 1.0.0, live-tested on IaC Bazaar: [Traefik HTTPS Routing On Loopback, HTTP Redirected](https://www.iac-bazaar.com/catalog/ansible-traefik?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)
```yaml
# Traefik HTTPS Routing On Loopback, HTTP Redirected: https://www.iac-bazaar.com/catalog/ansible-traefik (download from your IaC Bazaar account)
```Preview:
Documentation
traefik
Traefik from the upstream release (sha256-verified), as a hardened system service with HTTPS routes from a watched directory, plain HTTP redirected to HTTPS, and the dashboard, API and /ping on a loopback admin entrypoint. Original role for EL 10, live-tested with podman on Rocky Linux 10.
No package, so the checksum is the whole story. EL 10 carries no
traefik; Traefik Labs ships a release with a checksum file beside it. The
role downloads both and has Ansible's get_url refuse the asset unless its
SHA-256 is the one in the vendor's file, then installs the binaries as
root's in /usr/local/bin, pinned by traefik_version.
A service account, a hardened unit, a loopback listener. traefik
is a system user with no shell that owns the data directory and nothing
else; the unit runs with NoNewPrivileges, PrivateTmp, ProtectHome and
ProtectSystem=strict. The listener is 127.0.0.1:8443 by default,
for a proxy that authenticates or a client on the same host; the live test
reads the listening sockets and expects loopback only.
There is no configuration checker, and a broken route file is
survivable. Traefik ships no check command (healthcheck and version are
the only subcommands) and starts with an unknown static key, so the role has
no validate: to offer - measured rather than assumed. What it does have is
resilience in the dynamic directory: a malformed file is logged ("Error
occurred during watcher callback") and the previous routes keep serving,
which is why routes live there and not in the static file.
Proven by a route. The live test serves a page on the default upstream,
fetches it over HTTPS through the default route, sees plain HTTP answered
with a redirect to HTTPS, sees an unknown host get no route (404), and reads
the route back from Traefik's API. Note that a router carrying a tls
section answers only on HTTPS - the reason the HTTP entrypoint redirects
rather than routing. Binding :80 and :443 needs traefik_privileged_ports,
which grants CAP_NET_BIND_SERVICE to the service account and nothing else
(measured both ways). Without it Traefik exits on permission denied and
systemd restarts it in a loop - and a play that only started the unit
reported success throughout, because a unit counts as started the moment its
process forks. The role therefore waits for /ping before it reports
success.
License
Commercial - IaC Bazaar EULA. (c) IaC Bazaar.
Usage code & full reference need an account
The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.
- Variables
- Test
Related modules
ansible-envoy
Envoy from the upstream release, SHA-256 pinned, with its listener and its admin interface on loopback and its bootstrap checked by the installed release before it lands. The live test proxies a request to an upstream it serves, stops the upstream and sees Envoy answer 503 itself, and reads both outcomes in the admin stats. Original role, live-tested on Rocky Linux 10.
ansible-haproxy-tls
HAProxy terminating TLS 1.2 and 1.3 only with a modern cipher policy, HTTP redirected to HTTPS, HSTS on every response including HAProxy's own error pages (http-after-response, which the live test proved http-response does not cover), a self-signed certificate until yours arrives, stats kept local. Original role, live-tested on Rocky Linux 10.
ansible-keepalived
keepalived on EL 10: one VRRP instance, checked by keepalived's own --config-test before it lands, with the configuration at 0600 because auth_pass is a cleartext secret. The live test waits for this node to take the virtual address, stops the service and asserts the address LEFT, then starts it and asserts it came back. Original role, live-tested on Rocky Linux 10.