Traefik passthrough
The kis.ai routing model covers the shapes most services need. Everything else
Traefik supports is still reachable: write it verbatim under
traefik.static and traefik.dynamic, and it is merged into the configuration the gateway
generates.
This is how ACME resolvers, rate limits, compression, HTTP/3, tracing, custom TLS options and the dashboard are configured. Traefik’s own documentation is the reference for what goes inside these blocks.
By convention, keep passthrough in one file, such as common.yaml, rather than spreading it across
a routing directory.
The two blocks
Section titled “The two blocks”traefik: static: certificatesResolvers: letsencrypt: acme: storage: /var/lib/gateway/acme.json httpChallenge: { entryPoint: web }
dynamic: http: middlewares: strict-rate-limit: rateLimit: { average: 100, burst: 200 } gzip-all: compress: {}| Block | Maps to | Changes at runtime |
|---|---|---|
traefik.static | Traefik’s static configuration | No. Boot only |
traefik.dynamic | Traefik’s dynamic configuration | Yes. Hot-reloaded with the rest of the routing plane |
Referring to it from a route
Section titled “Referring to it from a route”Passthrough definitions are inert until something names them.
routes: - name: main domainmap: main entrypoint: websecure certresolver: letsencrypt # a traefik.static resolver extramiddlewares: [strict-rate-limit, gzip-all] # traefik.dynamic middlewares endpoints: [to-svc]extramiddlewares run alongside the middlewares the gateway generates. A certresolver or an
extramiddlewares entry that names something undeclared is refused at load, so a typo fails the
reload rather than quietly serving without the rate limit.
Paths the gateway owns
Section titled “Paths the gateway owns”Some paths are generated by the gateway or are sharp enough to warrant a deliberate decision elsewhere. Writing to one of them fails at boot with an error naming the path, rather than silently overriding what the gateway produced.
In traefik.static
Section titled “In traefik.static”| Path | Why |
|---|---|
entryPoints.websecure, entryPoints.websecureinternal | Generated from the listener configuration. Declare listeners in entrypoints: |
providers.kisai | The provider that carries every route and service the gateway builds |
global | The gateway sets version checking and anonymous usage reporting off |
log, accessLog.filePath | Keeps logging from being silenced or redirected. Use the gateway’s own log and loglevel keys |
experimental.plugins, experimental.localPlugins | Traefik plugins are interpreted Go, which is arbitrary code inside the gateway process |
serversTransport.insecureSkipVerify, serversTransport.rootCAs | The global backend-TLS verification switch. For one target, scope it with traefik.dynamic.http.serversTransports.<name>, which is explicit and reviewable |
api.insecure | Serves the dashboard with no authentication. On a public listener that publishes the topology, the certificates, every route and every backend URL |
In traefik.dynamic
Section titled “In traefik.dynamic”| Path | Why |
|---|---|
http.routers, tcp.routers | The gateway owns route definitions |
http.services, tcp.services | The gateway owns service definitions |
tls.options.default, tls.options.kisaitlsinternal | The hardened TLS defaults that generated routes rely on |
Defining new names alongside these is fine and is the intended path. A tls.options.modern of
your own is accepted; weakening tls.options.default underneath every existing route is not.
Exposing the dashboard safely
Section titled “Exposing the dashboard safely”gateway.svc config generate dashboardRoute the dashboard like any other application, behind a domainmap and the kisai-auth middleware.
That gives it TLS, tenancy and authentication from the same machinery everything else uses.
Do not reach for api.insecure. It is protected for the reason above, and the boot will refuse it.
A worked example: Let’s Encrypt over HTTP-01
Section titled “A worked example: Let’s Encrypt over HTTP-01”traefik: static: certificatesResolvers: letsencrypt: acme: storage: /var/lib/gateway/acme.json httpChallenge: { entryPoint: web }
routes: - name: public domainmap: acme-prod entrypoint: websecure certresolver: letsencrypt endpoints: [api]Three things have to line up: the resolver names an entrypoint that exists, that entrypoint is reachable from the internet on port 80, and the storage path is writable by the process. A browser showing a self-signed certificate usually means one of those three.
DNS-01 is configured the same way, with the provider block Traefik documents for your DNS service.
See also
Section titled “See also”- Security: the edge posture these protections are part of
- Configuration: the kis.ai model’s own keys