
Traefik Proxy API and Dashboard
Protect the Traefik Proxy API and dashboard internal service as an upstream web application.
Overview
The Traefik Proxy API and dashboard are HTTP endpoints exposed by the api@internal service. The dashboard depends on both the /dashboard/ and /api paths.
Traefik Proxy API and Dashboard can expose sensitive application data or administrative functions. A Pomerium route adds identity-aware policy before a user reaches the selected endpoint while the service keeps its own detailed permissions.
Pomerium controls who can reach the selected Traefik API and dashboard route. Traefik Proxy remains responsible for its provider configuration, API behavior, and operational controls.
How it works
Create a Pomerium HTTPS route for the selected private HTTP endpoint. Configure the application public URL and trusted proxy settings for the Pomerium origin.
Keep application authentication and granular authorization active when the service needs them. Give API and automation clients a reviewed noninteractive authentication path.
Create a secured Traefik router for api@internal and place its selected public origin behind Pomerium. Test API requests, dashboard assets, the trailing slash, and any base-path configuration.
Example
Platform operators use a Pomerium HTTPS route for a secured Traefik internal service router. Traefik keeps its provider configuration and operational controls.
Considerations
- Route both /api and /dashboard. The dashboard path needs its trailing slash.
- Keep api.insecure disabled. Expose the internal service through a secured router.
