Skip to content

Releases: imnoobincoding/cf-real

v1.0.3

Choose a tag to compare

@imnoobincoding imnoobincoding released this 19 May 10:24

test

v1.0.2

Choose a tag to compare

@imnoobincoding imnoobincoding released this 19 May 10:00

Traefik Cloudflare Real IP Plugin - ✨ Version 1.0.2 Released! ✨ Enhanced!

ℹ️ Disclaimer & Original Work
This project is a fork of the original work by vincentinttsh (vincentinttsh/cloudflareip).
This version builds upon that foundation and includes the latest improvements and fixes (see "What's New").
A huge thank you to vincentinttsh for the original development! 🙏


When your Traefik Proxy runs behind a reverse proxy like Cloudflare (or another load balancer/firewall), Traefik, by default, only sees the IP of the intermediate proxy. The true client IP address remains hidden – a problem for logging, security, and analytics.

This plugin solves this issue! 🕵️‍♂️ It grabs the client IP from the Cf-Connecting-IP header (provided by Cloudflare) and correctly sets the crucial X-Forwarded-For and X-Real-IP headers. Of course, this only happens if the request comes from a trusted IP (configured via trustip).

This way, your backend applications always get the correct information about who is actually requesting them!

✨ What's New in v1.0.2?

(Please fill this section with the highlights of your v1.0.2 release!)
(If the change was removing the log import for better compatibility, you could write something like:)

  • Example: Internal code optimization to improve compatibility with Traefik's plugin system (e.g., adjusted logging mechanisms). ⚙️
  • Example: Minor stability improvements. 👍
  • Example: Updated test cases for more robust checks. 🧪

For a detailed list of all changes, please refer to the CHANGELOG.md (if available) or the GitHub Releases.

🚀 How it Works (Quick Overview)

  1. Check: The plugin inspects the RemoteAddr of the incoming request (the IP of Traefik's direct peer).
  2. Trust Check: Is the RemoteAddr in your trustip list?
    • ✅ Yes: The plugin reads the Cf-Connecting-IP header. If present, X-Forwarded-For and X-Real-IP are updated with this value.
    • ❌ No: No changes are made to the headers by this plugin.
  3. Result: Your services see the real client IP!

🌟 Key Features

  • 🌐 Reliably determines the real client IP behind Cloudflare (or similar proxies).
  • 📝 Sets the standard X-Forwarded-For and X-Real-IP headers.
  • 🛡️ Configurable trustip list for maximum security and control.
  • 🔌 Easy plug-and-play integration with Traefik Proxy.
  • 🔄 Compatible with the latest Traefik versions (v2.x & v3.x).

🛠️ Configuration

Prerequisites

  • Traefik v2.x or v3.x
  • Your Traefik setup receives traffic via Cloudflare (or a proxy that sets Cf-Connecting-IP).
  • You know the IPs of the proxy directly in front of Traefik (these are your trustips).

Plugin Configuration

The main setting is trustip:

Setting Type Required Description
trustip []string ✅ Yes A list of IP addresses/CIDR ranges. The plugin will only process requests from these IPs to extract the client IP from Cf-Connecting-IP. IMPORTANT: These are the IPs of the proxy that communicates directly with Traefik!

Static Configuration (Excerpt from traefik.yml or startup arguments)

Declare the plugin in your Traefik static configuration:

# traefik.yml

# For Traefik v2 (experimental section)
# experimental:
#   plugins:
#     # Your chosen plugin name
#     cloudflareRealIp:
#       modulename: [github.com/imnoobincoding/cf-real](https://github.com/imnoobincoding/cf-real)
#       version: v1.0.2 # <-- Your new release version!

# For Traefik v3
plugins:
  # Your chosen plugin name
  cloudflareRealIp:
    module: [github.com/imnoobincoding/cf-real](https://github.com/imnoobincoding/cf-real)
    version: v1.0.2 # <-- Your new release version!

v1.0.1

Choose a tag to compare

@imnoobincoding imnoobincoding released this 14 May 12:55

Traefik Cloudflare Real IP Plugin - 🎉 New Release v1.0.1! 🎉

ℹ️ Disclaimer & Original Work
This project is a fork of the original work by vincentinttsh (vincentinttsh/cloudflareip).
This version builds upon that foundation and includes the latest improvements and fixes (see "What's New").
A huge thank you to vincentinttsh for the original development! 🙏


When your Traefik Proxy runs behind a reverse proxy like Cloudflare (or another load balancer/firewall), Traefik, by default, only sees the IP of that intermediate proxy. The true client IP address remains hidden – a problem for logging, security, and analytics.

This plugin tackles this issue! 🕵️‍♂️ It grabs the client IP from the Cf-Connecting-IP header (provided by Cloudflare) and correctly sets the crucial X-Forwarded-For and X-Real-IP headers. Of course, this only happens if the request comes from a trusted IP (configured via trustip).

This way, your backend applications always get the correct information about who is actually requesting them!

✨ What's New in v1.0.1?

(Please fill this section with the highlights of your new release!)

  • Example: Bug fix for [specific issue]! 🐞
  • Example: Performance optimizations for even faster header processing! ⚡
  • Example: Added support for [new configuration option/feature]! ⚙️
  • Example: Documentation updated and expanded. 📚

For a detailed list of all changes, please refer to the CHANGELOG.md (if available) or the GitHub Releases.

🚀 How it Works (Quick Overview)

  1. Check: The plugin inspects the RemoteAddr of the incoming request (the IP of Traefik's direct peer).
  2. Trust Check: Is the RemoteAddr in your trustip list?
    • ✅ Yes: The plugin reads the Cf-Connecting-IP header. If present, X-Forwarded-For and X-Real-IP are updated with this value.
    • ❌ No: No changes are made to the headers by this plugin.
  3. Result: Your services see the real client IP!

🌟 Key Features

  • 🌐 Reliably determines the real client IP behind Cloudflare (or similar proxies).
  • 📝 Sets the standard X-Forwarded-For and X-Real-IP headers.
  • 🛡️ Configurable trustip list for maximum security and control.
  • 🔌 Easy plug-and-play integration with Traefik Proxy.
  • 🔄 (Optional, if applicable) Compatible with the latest Traefik versions.

🛠️ Configuration

Prerequisites

  • Traefik v2.x or v3.x
  • Your Traefik setup receives traffic via Cloudflare (or a proxy that sets Cf-Connecting-IP).
  • You know the IPs of the proxy directly in front of Traefik (these are your trustips).

Plugin Configuration

The main setting is trustip:

Setting Type Required Description
trustip []string ✅ Yes A list of IP addresses/CIDR ranges. The plugin will only process requests from these IPs to extract the client IP from Cf-Connecting-IP. IMPORTANT: These are the IPs of the proxy that communicates directly with Traefik!

Static Configuration (Excerpt from traefik.yml or startup arguments)

Declare the plugin in your Traefik static configuration:

# traefik.yml

# For Traefik v2 (experimental section)
# experimental:
#   plugins:
#     # Your chosen plugin name
#     cloudflareRealIp:
#       modulename: [github.com/imnoobincoding/cf-real](https://github.com/imnoobincoding/cf-real)
#       version: v1.0.1 # <-- Your new release version!

# For Traefik v3
plugins:
  # Your chosen plugin name
  cloudflareRealIp:
    module: [github.com/imnoobincoding/cf-real](https://github.com/imnoobincoding/cf-real)
    version: v1.0.1 # <-- Your new release version!

v1.0.0

Choose a tag to compare

@imnoobincoding imnoobincoding released this 12 May 15:33