---
title: "Charmhub | Deploy Traefik Ingress Operator for Kubernetes\n using Charmhub\
  \ - The Open Operator Collection"
description: "Deploy the latest version of Traefik Ingress Operator for Kubernetes\n\
  \ as a Kubernetes Operator on any cloud."
url: https://charmhub.io/traefik-k8s/configurations
---

# Traefik Ingress Operator for Kubernetes

[Canonical IS DevOps](https://charmhub.io/publisher/canonical-is-devops "View all packages from Canonical IS DevOps")

* [Canonical IS DevOps](https://charmhub.io/publisher/canonical-is-devops "View all packages from Canonical IS DevOps")

Platform:

stable 32bad7a

```
juju deploy traefik-k8s
```

[Learn to deploy on juju >](https://juju.is/docs/juju/manage-applications)

* [basic\_auth\_user](https://charmhub.io/traefik-k8s/configurations#basic_auth_user)
* [enable\_experimental\_forward\_auth](https://charmhub.io/traefik-k8s/configurations#enable_experimental_forward_auth)
* [external\_hostname](https://charmhub.io/traefik-k8s/configurations#external_hostname)
* [loadbalancer\_annotations](https://charmhub.io/traefik-k8s/configurations#loadbalancer_annotations)
* [routing\_mode](https://charmhub.io/traefik-k8s/configurations#routing_mode)
* [tls-ca](https://charmhub.io/traefik-k8s/configurations#tls-ca)
* [tls-cert](https://charmhub.io/traefik-k8s/configurations#tls-cert)
* [tls-key](https://charmhub.io/traefik-k8s/configurations#tls-key)

[Learn about configurations >](https://juju.is/docs/juju/configuration#heading--application-configuration)

* basic\_auth\_user | string

  Enables the `basicAuth` middleware for **all** routes on this proxy.
  The format of this string must be: `name:hashed-password`, generated with e.g. htpasswd.
  Supported hashing algorithms are: MD5, SHA1, BCrypt.
  For more documentation see https://doc.traefik.io/traefik/middlewares/http/basicauth/
  Once this config option is set, the username/password pair will be required to authenticate
  http requests on all routes proxied by this traefik app.
* enable\_experimental\_forward\_auth | boolean

  Enables `forward-auth` middleware capabilities required to set up Identity and Access Proxy.
  This feature is experimental and may be unstable.
* external\_hostname | string

  The DNS name to be used by Traefik when providing its host to other applications. If unspecified, the address
  assigned to the ingress by the LoadBalancer will be used.
  external\_hostname must be a "bare" hostname - it cannot include a schema prefix or port.
* loadbalancer\_annotations | string

  A comma-separated list of annotations to apply to the LoadBalancer service.
  The format should be: `key1=value1,key2=value2,key3=value3`.
  These annotations are passed directly to the Kubernetes LoadBalancer service,
  enabling customization for specific cloud provider settings or integrations.
  Note that "key1=" will be interpreted as {"key1": ""} when passed to k8s. Annotation values can be empty strings.

  Example:
  "external-dns.alpha.kubernetes.io/hostname=example.com,service.beta.kubernetes.io/aws-load-balancer-type=nlb"

  Ensure the annotations are correctly formatted and adhere to Kubernetes' syntax and character set : https://kubernetes.io/docs/concepts/overview/working-with-objects/annotations/#syntax-and-character-set
  Invalid values will result in LoadBalancer being removed and all previously set annotations will be lost.
* routing\_mode | string

  Default: path

  The routing mode allows you to specify how Traefik going to generate
  routes on behalf of the requesters.

  Valid values are "path" and "subdomain".

  With the "path" routing mode, Traefik will use its externally-visible url,
  and create a route for the requester that will be structure like:

  `<external_url>/<requester_model_name>-<requester_application_name>-<requester-unit-index>`

  For example, an ingress-per-unit provider with `http://foo` external URL,
  will provide to the unit `my-unit/2` in the `my-model` model the
  following URL:

  `http://foo/my-model-my-unit-2`

  With the "subdomain" routing mode, Traefik will use its externally-visible url,
  and create a route for the requester that will be structure like:

  `<protocol>://<requester_model_name>-<requester_application_name>-<requester-unit-index>.<external_hostname>:<port>/`

  For example, an ingress-per-unit provider with `http://foo:8080` external URL,
  will provide to the unit `my-unit/2` in the `my-model` model the following URL:

  `http://my-model-my-unit-2.foo:8080`

  Note that, for 'subdomain' routing mode, the external\_hostname must be set and not be set to an IP address. This
  is because subdomains are not supported for IP addresses.
* tls-ca | string

  CA cert used for TLS termination.
* tls-cert | string

  SSL cert used for TLS termination. This will also accept full certificate chains.
* tls-key | string

  Key used for TLS termination.
