2017-08-26 10:12:44 +00:00
# Marathon Backend
2017-09-11 17:10:04 +00:00
Træfik can be configured to use Marathon as a backend configuration.
See also [Marathon user guide ](/user-guide/marathon ).
## Configuration
2017-08-26 10:12:44 +00:00
```toml
################################################################
# Mesos/Marathon configuration backend
################################################################
2017-09-11 17:10:04 +00:00
# Enable Marathon configuration backend.
2017-08-26 10:12:44 +00:00
[marathon]
# Marathon server endpoint.
# You can also specify multiple endpoint for Marathon:
2017-09-11 17:10:04 +00:00
# endpoint = "http://10.241.1.71:8080,10.241.1.72:8080,10.241.1.73:8080"
2017-08-26 10:12:44 +00:00
#
# Required
2017-09-11 17:10:04 +00:00
# Default: "http://127.0.0.1:8080"
2017-08-26 10:12:44 +00:00
#
endpoint = "http://127.0.0.1:8080"
2017-09-11 17:10:04 +00:00
# Enable watch Marathon changes.
2017-08-26 10:12:44 +00:00
#
# Optional
2017-09-11 17:10:04 +00:00
# Default: true
2017-08-26 10:12:44 +00:00
#
watch = true
# Default domain used.
# Can be overridden by setting the "traefik.domain" label on an application.
#
# Required
#
domain = "marathon.localhost"
2017-09-11 17:10:04 +00:00
# Override default configuration template.
# For advanced users :)
2017-08-26 10:12:44 +00:00
#
# Optional
#
# filename = "marathon.tmpl"
2017-09-11 17:10:04 +00:00
# Expose Marathon apps by default in Traefik.
2017-08-26 10:12:44 +00:00
#
# Optional
# Default: true
#
2017-09-11 17:10:04 +00:00
# exposedByDefault = false
2017-08-26 10:12:44 +00:00
2017-09-11 17:10:04 +00:00
# Convert Marathon groups to subdomains.
2017-08-26 10:12:44 +00:00
# Default behavior: /foo/bar/myapp => foo-bar-myapp.{defaultDomain}
# with groupsAsSubDomains enabled: /foo/bar/myapp => myapp.bar.foo.{defaultDomain}
#
# Optional
# Default: false
#
# groupsAsSubDomains = true
2017-09-11 17:10:04 +00:00
# Enable compatibility with marathon-lb labels.
2017-08-26 10:12:44 +00:00
#
# Optional
# Default: false
#
# marathonLBCompatibility = true
2017-11-21 09:48:04 +00:00
# Enable filtering using Marathon constraints..
# If enabled, Traefik will read Marathon constraints, as defined in https://mesosphere.github.io/marathon/docs/constraints.html
# Each individual constraint will be treated as a verbatim compounded tag.
# i.e. "rack_id:CLUSTER:rack-1", with all constraint groups concatenated together using ":"
#
# Optional
# Default: false
#
# filterMarathonConstraints = true
2017-09-11 17:10:04 +00:00
# Enable Marathon basic authentication.
2017-08-26 10:12:44 +00:00
#
# Optional
#
2017-09-11 17:10:04 +00:00
# [marathon.basic]
# httpBasicAuthUser = "foo"
# httpBasicPassword = "bar"
2017-08-26 10:12:44 +00:00
# TLS client configuration. https://golang.org/pkg/crypto/tls/#Config
#
# Optional
#
2017-09-11 17:10:04 +00:00
# [marathon.TLS]
# CA = "/etc/ssl/ca.crt"
# Cert = "/etc/ssl/marathon.cert"
# Key = "/etc/ssl/marathon.key"
# InsecureSkipVerify = true
2017-08-26 10:12:44 +00:00
2017-09-11 17:10:04 +00:00
# DCOSToken for DCOS environment.
# This will override the Authorization header.
2017-08-26 10:12:44 +00:00
#
# Optional
#
# dcosToken = "xxxxxx"
2017-09-11 17:10:04 +00:00
# Override DialerTimeout.
2017-08-26 10:12:44 +00:00
# Amount of time to allow the Marathon provider to wait to open a TCP connection
# to a Marathon master.
# Can be provided in a format supported by [time.ParseDuration](https://golang.org/pkg/time/#ParseDuration) or as raw
2017-09-11 17:10:04 +00:00
# values (digits).
# If no units are provided, the value is parsed assuming seconds.
2017-08-26 10:12:44 +00:00
#
# Optional
# Default: "60s"
2017-09-11 17:10:04 +00:00
#
2017-08-26 10:12:44 +00:00
# dialerTimeout = "60s"
# Set the TCP Keep Alive interval for the Marathon HTTP Client.
# Can be provided in a format supported by [time.ParseDuration](https://golang.org/pkg/time/#ParseDuration) or as raw
2017-09-11 17:10:04 +00:00
# values (digits).
# If no units are provided, the value is parsed assuming seconds.
2017-08-26 10:12:44 +00:00
#
# Optional
# Default: "10s"
#
# keepAlive = "10s"
# By default, a task's IP address (as returned by the Marathon API) is used as
# backend server if an IP-per-task configuration can be found; otherwise, the
# name of the host running the task is used.
# The latter behavior can be enforced by enabling this switch.
#
# Optional
# Default: false
#
2017-09-11 17:10:04 +00:00
# forceTaskHostname = true
2017-08-26 10:12:44 +00:00
# Applications may define readiness checks which are probed by Marathon during
2017-09-11 17:10:04 +00:00
# deployments periodically and the results exposed via the API.
# Enabling the following parameter causes Traefik to filter out tasks
# whose readiness checks have not succeeded.
# Note that the checks are only valid at deployment times.
# See the Marathon guide for details.
2017-08-26 10:12:44 +00:00
#
# Optional
# Default: false
#
2017-09-11 17:10:04 +00:00
# respectReadinessChecks = true
2017-08-26 10:12:44 +00:00
```
2017-09-11 17:10:04 +00:00
To enable constraints see [backend-specific constraints section ](/configuration/commons/#backend-specific ).
## Labels: overriding default behaviour
2018-01-02 10:08:02 +00:00
Marathon labels may be used to dynamically change the routing and forwarding behaviour.
They may be specified on one of two levels: Application or service.
### Application Level
2017-09-11 17:10:04 +00:00
2018-01-02 10:08:02 +00:00
The following labels can be defined on Marathon applications. They adjust the behaviour for the entire application.
2017-08-26 10:12:44 +00:00
2017-09-05 13:58:03 +00:00
| Label | Description |
|-----------------------------------------------------------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| `traefik.backend=foo` | assign the application to `foo` backend |
| `traefik.backend.maxconn.amount=10` | set a maximum number of connections to the backend. Must be used in conjunction with the below label to take effect. |
| `traefik.backend.maxconn.extractorfunc=client.ip` | set the function to be used against the request to determine what to limit maximum connections to the backend by. Must be used in conjunction with the above label to take effect. |
| `traefik.backend.loadbalancer.method=drr` | override the default `wrr` load balancer algorithm |
2017-10-10 13:24:03 +00:00
| `traefik.backend.loadbalancer.sticky=true` | enable backend sticky sessions (DEPRECATED) |
| `traefik.backend.loadbalancer.stickiness=true` | enable backend sticky sessions |
| `traefik.backend.loadbalancer.stickiness.cookieName=NAME` | Manually set the cookie name for sticky sessions |
2017-09-05 13:58:03 +00:00
| `traefik.backend.circuitbreaker.expression=NetworkErrorRatio() > 0.5` | create a [circuit breaker ](/basics/#backends ) to be used against the backend |
| `traefik.backend.healthcheck.path=/health` | set the Traefik health check path [default: no health checks] |
| `traefik.backend.healthcheck.interval=5s` | sets a custom health check interval in Go-parseable (`time.ParseDuration`) format [default: 30s] |
| `traefik.portIndex=1` | register port by index in the application's ports array. Useful when the application exposes multiple ports. |
| `traefik.port=80` | register the explicit application port value. Cannot be used alongside `traefik.portIndex` . |
| `traefik.protocol=https` | override the default `http` protocol |
| `traefik.weight=10` | assign this weight to the application |
| `traefik.enable=false` | disable this application in Træfik |
| `traefik.frontend.rule=Host:test.traefik.io` | override the default frontend rule (Default: `Host:{containerName}.{domain}` ). |
| `traefik.frontend.passHostHeader=true` | forward client `Host` header to the backend. |
| `traefik.frontend.priority=10` | override default frontend priority |
| `traefik.frontend.entryPoints=http,https` | assign this frontend to entry points `http` and `https` . Overrides `defaultEntryPoints` . |
| `traefik.frontend.auth.basic=EXPR` | Sets basic authentication for that frontend in CSV format: `User:Hash,User:Hash` . |
2017-08-26 10:12:44 +00:00
2018-01-02 10:08:02 +00:00
### Service Level
2017-09-11 17:10:04 +00:00
2018-01-02 10:08:02 +00:00
For applications that expose multiple ports, specific labels can be used to extract one frontend/backend configuration pair per port. Each such pair is called a _service_ . The (freely choosable) name of the service is an integral part of the service label name.
2017-08-26 10:12:44 +00:00
2017-09-05 13:58:03 +00:00
| Label | Description |
|--------------------------------------------------------|------------------------------------------------------------------------------------------------------|
| `traefik.<service-name>.port=443` | create a service binding with frontend/backend using this port. Overrides `traefik.port` . |
| `traefik.<service-name>.portIndex=1` | create a service binding with frontend/backend using this port index. Overrides `traefik.portIndex` . |
| `traefik.<service-name>.protocol=https` | assign `https` protocol. Overrides `traefik.protocol` . |
| `traefik.<service-name>.weight=10` | assign this service weight. Overrides `traefik.weight` . |
| `traefik.<service-name>.frontend.backend=fooBackend` | assign this service frontend to `foobackend` . Default is to assign to the service backend. |
| `traefik.<service-name>.frontend.entryPoints=http` | assign this service entrypoints. Overrides `traefik.frontend.entrypoints` . |
| `traefik.<service-name>.frontend.auth.basic=test:EXPR` | Sets basic authentication for that frontend in CSV format: `User:Hash,User:Hash` |
| `traefik.<service-name>.frontend.passHostHeader=true` | Forward client `Host` header to the backend. Overrides `traefik.frontend.passHostHeader` . |
| `traefik.<service-name>.frontend.priority=10` | assign the service frontend priority. Overrides `traefik.frontend.priority` . |
| `traefik.<service-name>.frontend.rule=Path:/foo` | assign the service frontend rule. Overrides `traefik.frontend.rule` . |