A clean, self-hosted web UI for your Traefik reverse proxy.
Routes, middlewares, Services, Plugins, certificates, crowdsec and logs, without editing YAML by hand.
Built for homelabbers who love Traefik but hate editing YAML at 2am.
curl -fsSL https://get-traefik.xyzlab.dev | bashInstalls the tm CLI and runs tm install. Six modes: Traefik + Traefik Manager together, Traefik Manager on its own (Docker or native), or the agent for a remote host (Docker, Docker + Traefik, or binary).
Afterwards tm manages the install: tm status, tm update, tm logs, tm reconfigure, tm doctor. Full guide
For an existing Traefik install.
services:
traefik-manager:
image: ghcr.io/chr0nzz/traefik-manager:latest
container_name: traefik-manager
restart: unless-stopped
ports:
- "5000:5000"
environment:
- COOKIE_SECURE=false
volumes:
- /path/to/traefik/dynamic.yml:/app/config/dynamic.yml
- /path/to/traefik-manager/config:/app/config
- /path/to/traefik-manager/backups:/app/backupsOpen http://your-server:5000 and the setup wizard takes it from there.
Routes - HTTP, TCP and UDP. Multiple domains and backends per route, each with its own scheme including h2c for cleartext HTTP/2, sticky sessions, health checks, priority, per-route certificate resolvers, editable tls.domains and TLS profiles. Guided presets for security headers and media streaming.
Services - build a load balancer, weighted, mirroring or failover service on its own, or balance a route across a mix of raw addresses and existing services with a weight on each row. Services Traefik Manager did not write stay read only until you take them over, which records ownership without touching the file.
Middlewares - 30 wizards covering auth, rate limiting, headers, CORS, redirects, prefixes, error pages and TLS client certificates, plus a raw YAML editor and your own reusable templates.
Dashboard and Route Map - a homepage-style grid of your apps with icons and health, and a topology map from entry point through middlewares to backend, coloured per hop.
Certificates - every certificate in acme.json, with expiry, the ones no router serves, and the ones whose resolver is gone from your static config. Filter by domain or by either of those. Mount the file read-write and set a restart method to remove them, one at a time or in bulk, with a timestamped backup you can restore.
Monitoring - live router and service health from the Traefik API, provider tabs for Docker, Kubernetes, Swarm, Nomad, ECS, Consul, Redis and more, which switch themselves on the first time Traefik reports routers from them, and CVE advisories for your running Traefik version.
Logs and CrowdSec - access log analytics and CrowdSec attacks, bans and decisions. Optional country flags and a world map, resolved on your own server.
Notifications - nine destinations: Discord, Slack, ntfy, Gotify, Pushover, Pushbullet, Telegram, UnifiedPush and generic webhooks. Route events to each one by category and severity, with quiet hours, hourly or daily digests, and errors that break through anyway. Desktop notifications while a tab is open.
Background monitoring - the server checks your routes on a schedule and tells you when a backend goes down or a pool degrades, alongside certificate expiry, Traefik and agent reachability, CrowdSec activity, GeoIP freshness and new releases. Alerts arrive whether or not the interface is open.
Static config editor - edit traefik.yml from the UI and apply it with a one-click restart, via socket proxy, poison pill or direct socket.
Plugins - see every Traefik plugin with the middlewares using it, install new ones, and get flagged when the catalog has a newer version.
Backups - timestamped local backups before every change, plus git push with commit history, diffs and one-click restore.
Multi-server - a lightweight Go agent runs beside Traefik on any remote host, and every tab works against whichever server you pick. No VPN, no SSH.
Security - bcrypt, TOTP two-factor, OIDC single sign-on, per-device API keys, CSRF protection, rate limiting, and secrets encrypted at rest.
Two layouts - Fluid fills the screen, Fixed caps the width.
Mobile - a native Android app on Google Play, and the web app installs as a PWA on any platform.
Full documentation.
| Runtime | Guide |
|---|---|
| Full stack, TM only, agent | |
| Compose, networking, behind Traefik | |
| Rootless, Quadlet, SELinux | |
| Native Python and systemd | |
| Community Applications and appdata paths | |
| Community app store, ports and routing | |
| TMA for multi-server management |
Overview · Configuration · Environment variables · Security · API · OIDC · Reset password · Beta
Questions, help and release news: Discord
One binary that installs and manages the whole stack. Six install modes: Traefik and Traefik Manager together, Traefik Manager on its own (Docker or native), or an agent for a remote host (Docker, Docker + Traefik, or binary). Afterwards tm status, tm update, tm logs, tm reconfigure, tm doctor and tm password reset manage it in place.
curl -fsSL https://get-traefik.xyzlab.dev | bashRepository · Releases · Docs
Native Android, rewritten in Kotlin and Jetpack Compose for v2. Needs Traefik Manager v1.10.1 or newer and a per-device API key from Settings - Authentication - API Keys.
Repository · Releases · Docs
| Layer | Technology |
|---|---|
| Backend | Python 3.11 · Flask 3.1 · Gunicorn |
| Agent | Go 1.25 · Alpine |
| Config | ruamel.yaml, preserving comments and Go templates |
| Auth | bcrypt · pyotp · CSRF · Flask-Limiter · Fernet |
| Frontend | Vanilla JS · Tailwind 3.4 · Phosphor Icons · Monaco · Twemoji country flags (CC-BY 4.0) |
| Geolocation | maxminddb · DB-IP Lite, local lookups only |
| Tests | pytest · ruff · go test, on every pull request |
All JS and CSS is bundled at build time - nothing is fetched from a CDN at runtime.
v1.15.0 is the first release that is not English-only. The whole interface is ready for translation - every page, dialog, tooltip, toast and server message - and the work happens on Weblate.
v1.15.0 ships in French, French (Canada), German, Spanish, Portuguese (Portugal), Portuguese (Brazil), Dutch, Chinese (Simplified), Russian, Czech and Danish, plus English spellings for the United States and the United Kingdom. Any other language is added on request.
| You want to | Where |
|---|---|
| Translate | Weblate - an account is needed to write, not to read. Nothing goes live on its own: Weblate opens a pull request here |
| Review a language | LANGUAGE-REVIEWERS.md - one named reviewer per language, and a language ships once it has a reviewer or passes an agent verification |
| Ask for a language | Open a language request |
| Read first | Handbook · Glossary · Do not translate |
| Report a wrong translation | Open a translation issue |
Traefik Manager deletes routers and rewrites live proxy configuration, so a mistranslated confirmation button is a destructive bug rather than a cosmetic one. Every translation is escaped when the page renders it, and CI rejects a translation that adds markup, links or control characters, or that changes a placeholder such as {name} or %(name)s.
Pull requests are welcome. See CONTRIBUTING.md for reporting bugs, suggesting features, and running the project locally.
Thanks as well to everyone who has opened an issue or a discussion - several features started as a question from someone running into something unexpected.