Skip to content

Compatible with account required

Traefik

Traefik deployment Prefers ACME resolver. File or Kubernetes secret update when deploying an already-issued cert. ssh/WinRM sessions use pinned host keys. Dynamic TLS store or Kubernetes secret

Verification: test_verified. Connection: unknown. Credentials: none. Live E2E: no.

No disposable Traefik host with pinned known_hosts and a TLS listener is configured.

What sslcertificates.io can do

Traefik deployment Prefers ACME resolver. File or Kubernetes secret update when deploying an already-issued cert. ssh/WinRM sessions use pinned host keys. Dynamic TLS store or Kubernetes secret Capabilities: atomic_write, config_test, reload, tls_verify, rollback. Authentication uses api_token.

Required permissions

Restricted service account. Commands are allowlisted: Dynamic TLS store or Kubernetes secret. Known-host verification is mandatory.

Setup

Open Dashboard → Integrations → Traefik. Enter the credentials described on this page. Values are encrypted at rest and never shown again. Run Test connection. Discovery runs only after authentication succeeds. Select a discovered resource. Do not paste opaque IDs unless the provider cannot enumerate them. Perform the certificate or notification action, then confirm the external system matches. Disconnect removes stored credentials and owned test resources created by sslcertificates.io.

Known limitations

User-supplied shell is rejected. A successful file write is not enough; the TLS endpoint must present the new fingerprint.

Official sources

Fact checked 2026-09-20. https://www.haproxy.com/documentation/ Traefik is a trademark of its owner. sslcertificates.io is not a partner or certified reseller unless a written agreement exists.

Capabilities

atomic_write config_test reload tls_verify rollback

Connect

Create an account to connect

Traefik is a trademark of its owner. sslcertificates.io is not a partner or certified reseller unless a written agreement exists.