v1.0.1
Traefik Cloudflare Real IP Plugin - π New Release v1.0.1! π
βΉοΈ Disclaimer & Original Work
This project is a fork of the original work by vincentinttsh (vincentinttsh/cloudflareip).
This version builds upon that foundation and includes the latest improvements and fixes (see "What's New").
A huge thank you to vincentinttsh for the original development! π
When your Traefik Proxy runs behind a reverse proxy like Cloudflare (or another load balancer/firewall), Traefik, by default, only sees the IP of that intermediate proxy. The true client IP address remains hidden β a problem for logging, security, and analytics.
This plugin tackles this issue! π΅οΈββοΈ It grabs the client IP from the Cf-Connecting-IP header (provided by Cloudflare) and correctly sets the crucial X-Forwarded-For and X-Real-IP headers. Of course, this only happens if the request comes from a trusted IP (configured via trustip).
This way, your backend applications always get the correct information about who is actually requesting them!
β¨ What's New in v1.0.1?
(Please fill this section with the highlights of your new release!)
- Example: Bug fix for [specific issue]! π
- Example: Performance optimizations for even faster header processing! β‘
- Example: Added support for [new configuration option/feature]! βοΈ
- Example: Documentation updated and expanded. π
For a detailed list of all changes, please refer to the CHANGELOG.md (if available) or the GitHub Releases.
π How it Works (Quick Overview)
- Check: The plugin inspects the
RemoteAddrof the incoming request (the IP of Traefik's direct peer). - Trust Check: Is the
RemoteAddrin yourtrustiplist?- β
Yes: The plugin reads the
Cf-Connecting-IPheader. If present,X-Forwarded-ForandX-Real-IPare updated with this value. - β No: No changes are made to the headers by this plugin.
- β
Yes: The plugin reads the
- Result: Your services see the real client IP!
π Key Features
- π Reliably determines the real client IP behind Cloudflare (or similar proxies).
- π Sets the standard
X-Forwarded-ForandX-Real-IPheaders. - π‘οΈ Configurable
trustiplist for maximum security and control. - π Easy plug-and-play integration with Traefik Proxy.
- π (Optional, if applicable) Compatible with the latest Traefik versions.
π οΈ Configuration
Prerequisites
- Traefik v2.x or v3.x
- Your Traefik setup receives traffic via Cloudflare (or a proxy that sets
Cf-Connecting-IP). - You know the IPs of the proxy directly in front of Traefik (these are your
trustips).
Plugin Configuration
The main setting is trustip:
| Setting | Type | Required | Description |
|---|---|---|---|
trustip |
[]string |
β Yes | A list of IP addresses/CIDR ranges. The plugin will only process requests from these IPs to extract the client IP from Cf-Connecting-IP. IMPORTANT: These are the IPs of the proxy that communicates directly with Traefik! |
Static Configuration (Excerpt from traefik.yml or startup arguments)
Declare the plugin in your Traefik static configuration:
# traefik.yml
# For Traefik v2 (experimental section)
# experimental:
# plugins:
# # Your chosen plugin name
# cloudflareRealIp:
# modulename: [github.com/imnoobincoding/cf-real](https://github.com/imnoobincoding/cf-real)
# version: v1.0.1 # <-- Your new release version!
# For Traefik v3
plugins:
# Your chosen plugin name
cloudflareRealIp:
module: [github.com/imnoobincoding/cf-real](https://github.com/imnoobincoding/cf-real)
version: v1.0.1 # <-- Your new release version!