Darren David
Explorer
- Joined
- Feb 27, 2014
- Messages
- 54
I'm new to TrueNAS Scale after many years running TrueNAS Core happily behind pfSense and NGINX (via NGINX Proxy Manager), where all of my jails had unique IPs. Now on TrueNAS Scale, I'm looking to set up a split horizon DNS with pfSense, where:
Official TrueNAS guides and countless posts all refer to Traefik as the recommended way to handle ingress for apps, and I'll run it if I must, but I'm hoping to not complicate my setup if I don't need to. Will Traefik solve my issues here, specifically, will running Traefik on TrueNAS Scale (behind NGINX) to handle ingress only for Scale apps solve my cert issues? Is that the secret magic (maegik?) Traefik provides - properly handling Kubernetes routing? FWIW, I've tried HAproxy on my pfSense machine and hit the same issues I'm hitting with NGINX.
I should mention that I don't want to use Traefik to replace NGINX Proxy Manager unless I can host it outside of the TrueNAS Scale machine, because for <reasons> the TrueNAS Scale machine will not always be running 24/7, and I have other hosts on the LAN that require reverse proxy.
- internal-only TrueNAS Scale VMs and container-based apps are available at https://<appname>.internal.lan instead of http://<truenas_ip>:<port>
- externally-available apps are available at <appname.mydomain.tld>.
Official TrueNAS guides and countless posts all refer to Traefik as the recommended way to handle ingress for apps, and I'll run it if I must, but I'm hoping to not complicate my setup if I don't need to. Will Traefik solve my issues here, specifically, will running Traefik on TrueNAS Scale (behind NGINX) to handle ingress only for Scale apps solve my cert issues? Is that the secret magic (maegik?) Traefik provides - properly handling Kubernetes routing? FWIW, I've tried HAproxy on my pfSense machine and hit the same issues I'm hitting with NGINX.
I should mention that I don't want to use Traefik to replace NGINX Proxy Manager unless I can host it outside of the TrueNAS Scale machine, because for <reasons> the TrueNAS Scale machine will not always be running 24/7, and I have other hosts on the LAN that require reverse proxy.