Traefik as a gateway API controller
See webserver/traefik.md for general docs abour traefik
- Docs: Traefik & Kubernetes with Gateway API
- Docs: Kubernetes
- Docs: Traefik & Kubernetes with Gateway API
- Getting started with Kubernetes Gateway API and Traefik
Configuration
kubectl describe GatewayClass traefik
kubectl describe Gateway traefik --namespace kube-system
TLS
From Gateway API & ACME:
Traefik’s built‑in ACME/Let’s Encrypt integration works for
IngressRouteandIngressresources, but it does not issue certificates for Gateway API listeners. If you’re using the Gateway API, install cert‑manager (or another certificate controller) and reference the secret it creates ingateway.listeners.websecure.certificateRefs.
See also FR: Support configuring Letsencrypt certificates using Gateway API
DNS challenge
- Traefik docs: DNS challenge
- Docker-compose with Let's Encrypt: DNS Challenge
- LEGO Hetzner provider docs
ListenerSets
ListenerSets allow teams to define ports, hostnames, and TLS certificates in separate resources rather than cramming everything into one giant Gateway object which has a limit of 64 listeners
- Issue: Unable to recognize
ListenerSetsfrom other namespaces even withallowedListeners.namespaces.from: Allin Gateway spec.- Solution: Wait for Traefik 3.8 which includes Gateway API ListenerSet (GEP-1713) support
- Traefik helm chart: Listenersets missinging in default templates