# traefik Stack — Secrets Reference # Source: traefik.env.template (rendered by deploy/provision-stack.py per # secrets/secrets-map.yaml — see secrets-map.yaml header for how # this works). traefik/traefik.env is rendered fresh on every # provisioning run and is NEVER committed to git. # # Add SECRET values to Woodpecker at: # https://woodpecker.bryanmail.net # homelab/compose-files → Settings → Secrets # # ⚠️ HIGH RISK: Traefik is the entry point for all homelab services. # If this stack fails, nothing is reachable from outside. # Migrate carefully. The Keepalived VIP (192.168.4.30) depends on this stack. # # ⚠️ 2026-09-12 INCIDENT: traefik.env was previously committed to git with a # literal "***REDACTED***" placeholder as KEEPALIVED_PASSWORD. Every # git-guard resync/checkout restored that broken value onto disk, # diverging from keepalived-backup's stale-but-correct in-memory value # and causing continuous VRRP auth failures + VIP instability. This was # the trigger for migrating this stack to Pattern C. If you ever see # KEEPALIVED_PASSWORD as a literal placeholder-looking string on disk # again, do NOT hand-edit it — check `git log traefik/` for a stray # commit and fix the template in Gitea instead. # ── SECRETS (add to Woodpecker) ───────────────────────────────────────── # Woodpecker secret name: traefik_keepalived_password # Used for: Keepalived VRRP authentication password # Must match across all 3 nodes (docker-1, docker-2, docker-3) # NOTE: classic VRRP simple-auth is silently # truncated to 8 chars by keepalived itself — keep # the value <= 8 characters, or be aware only the # first 8 are actually significant on the wire. # Env var in .env.template: KEEPALIVED_PASSWORD (via TRAEFIK_KEEPALIVED_PASSWORD) traefik_keepalived_password= # ── NON-SECRETS (safe in compose file or .env.template) ───────────────── # KEEPALIVED_VIRTUAL_IPS Python2BASH list of VIP addresses (192.168.4.30) — literal in template # ACME_EMAIL Let's Encrypt certificate email # TRUSTED_IPS Trusted proxy CIDR ranges # TRAEFIK_HOST Traefik dashboard hostname # SPEEDTEST_HOST Speedtest Traefik hostname # WHOAMI_HOST Whoami Traefik hostname # ── Provisioning (manifest-driven, deploy/provision-stack.py) ─────────── # # This stack is migrated — provisioning happens automatically via: # secrets/secrets-map.yaml (traefik: entry) # traefik/traefik.env.template (authoritative key list) # deploy/provision-stack.py (renders + ships traefik/traefik.env) # # The .woodpecker/deploy.yml provision-secrets step calls this with a # single line: `python3 deploy/provision-stack.py traefik`