Configuring Traefik to Get Real Client IPs
This post was translated from Chinese by AI. If anything reads oddly, the Chinese original is authoritative. 中文原文
The Problem
When using a CDN + Traefik + Docker architecture, the application sees the CDN node's IP instead of the user's real IP.
用户真实IP → CDN → Traefik → Docker容器
(58.32.x.x) (117.85.x.x) (显示117.85.x.x)
Cause
The CDN sets the user's real IP in the X-Forwarded-For header, but Traefik appends the IP it sees (the CDN node's IP) by default, resulting in:
X-Forwarded-For: 58.32.x.x, 117.85.x.x
If the application takes the last IP, it gets the CDN node's IP.
Solution
Add forwardedHeaders.trustedIPs to the Traefik configuration to trust upstream proxies:
entryPoints:
web:
address: ':80'
forwardedHeaders:
trustedIPs:
- "0.0.0.0/0"
- "::/0"
websecure:
address: ':443'
forwardedHeaders:
trustedIPs:
- "0.0.0.0/0"
- "::/0"
Configuration Details
0.0.0.0/0- Trust all IPv4 addresses::/0- Trust all IPv6 addresses
With this configuration, Traefik uses the X-Forwarded-For passed by the CDN directly, without appending the node's IP.
Security Note
If you know the CDN's egress IP ranges, trust only those specific IPs rather than all addresses:
forwardedHeaders:
trustedIPs:
- "1.1.1.0/24" # CDN IP range
- "2.2.2.0/24"
Verification
After updating the configuration, restart Traefik and check whether the IPs in the application logs are the users' real IPs.
Comments 0