Wood Chen

Configuring Traefik to Get Real Client IPs

0 comments153 views158 words

This post was translated from Chinese by AI. If anything reads oddly, the Chinese original is authoritative. 中文原文

The Problem

When using a CDN + Traefik + Docker architecture, the application sees the CDN node's IP instead of the user's real IP.

用户真实IP → CDN → Traefik → Docker容器
(58.32.x.x)   (117.85.x.x)    (显示117.85.x.x)

Cause

The CDN sets the user's real IP in the X-Forwarded-For header, but Traefik appends the IP it sees (the CDN node's IP) by default, resulting in:

X-Forwarded-For: 58.32.x.x, 117.85.x.x

If the application takes the last IP, it gets the CDN node's IP.

Solution

Add forwardedHeaders.trustedIPs to the Traefik configuration to trust upstream proxies:

entryPoints:
  web:
    address: ':80'
    forwardedHeaders:
      trustedIPs:
        - "0.0.0.0/0"
        - "::/0"
  websecure:
    address: ':443'
    forwardedHeaders:
      trustedIPs:
        - "0.0.0.0/0"
        - "::/0"

Configuration Details

  • 0.0.0.0/0 - Trust all IPv4 addresses
  • ::/0 - Trust all IPv6 addresses

With this configuration, Traefik uses the X-Forwarded-For passed by the CDN directly, without appending the node's IP.

Security Note

If you know the CDN's egress IP ranges, trust only those specific IPs rather than all addresses:

forwardedHeaders:
  trustedIPs:
    - "1.1.1.0/24"      # CDN IP range
    - "2.2.2.0/24"

Verification

After updating the configuration, restart Traefik and check whether the IPs in the application logs are the users' real IPs.

Related posts

Comments 0