2022-04-15 15:44:08 +02:00
---
title: "Traefik DigestAuth Documentation"
description: "Traefik Proxy's HTTP DigestAuth middleware restricts access to your services to known users. Read the technical documentation."
---
2019-02-26 05:50:07 -08:00
# DigestAuth
Adding Digest Authentication
2021-02-11 14:34:04 +01:00
{: .subtitle }
2019-02-26 05:50:07 -08:00
2021-06-11 15:30:05 +02:00
![BasicAuth ](../../assets/img/middleware/digestauth.png )
2019-02-26 05:50:07 -08:00
2021-02-11 14:34:04 +01:00
The DigestAuth middleware restricts access to your services to known users.
2019-02-26 05:50:07 -08:00
## Configuration Examples
2023-05-10 15:28:05 +02:00
```yaml tab="Docker & Swarm"
2019-09-05 13:42:04 +02:00
# Declaring the user list
2019-03-29 12:34:05 +01:00
labels:
2019-09-23 17:00:06 +02:00
- "traefik.http.middlewares.test-auth.digestauth.users=test:traefik:a2688e031edb4be6a3797f3882655c05,test2:traefik:518845800f9e2bfb1f1f740ec24f074e"
2019-04-03 14:32:04 +02:00
```
```yaml tab="Kubernetes"
# Declaring the user list
2023-03-20 15:38:08 +01:00
apiVersion: traefik.io/v1alpha1
2019-04-03 14:32:04 +02:00
kind: Middleware
metadata:
name: test-auth
spec:
digestAuth:
2019-09-05 13:42:04 +02:00
secret: userssecret
2019-03-29 12:34:05 +01:00
```
2019-10-15 18:34:08 +03:00
```yaml tab="Consul Catalog"
# Declaring the user list
- "traefik.http.middlewares.test-auth.digestauth.users=test:traefik:a2688e031edb4be6a3797f3882655c05,test2:traefik:518845800f9e2bfb1f1f740ec24f074e"
```
2019-07-22 09:58:04 +02:00
```yaml tab="File (YAML)"
2019-09-05 13:42:04 +02:00
# Declaring the user list
2019-07-22 09:58:04 +02:00
http:
middlewares:
test-auth:
digestAuth:
users:
2019-09-23 17:00:06 +02:00
- "test:traefik:a2688e031edb4be6a3797f3882655c05"
- "test2:traefik:518845800f9e2bfb1f1f740ec24f074e"
2019-07-22 09:58:04 +02:00
```
2021-06-19 00:08:08 +02:00
```toml tab="File (TOML)"
# Declaring the user list
[http.middlewares]
[http.middlewares.test-auth.digestAuth]
users = [
"test:traefik:a2688e031edb4be6a3797f3882655c05",
"test2:traefik:518845800f9e2bfb1f1f740ec24f074e",
]
```
2019-09-05 13:42:04 +02:00
## Configuration Options
2021-02-11 14:34:04 +01:00
!!! tip
2019-02-26 05:50:07 -08:00
Use `htdigest` to generate passwords.
2019-07-01 11:30:05 +02:00
### `users`
2019-02-26 05:50:07 -08:00
The `users` option is an array of authorized users. Each user will be declared using the `name:realm:encoded-password` format.
2019-09-23 14:32:04 +02:00
!!! note ""
2021-02-11 14:34:04 +01:00
2019-09-05 13:42:04 +02:00
- If both `users` and `usersFile` are provided, the two are merged. The contents of `usersFile` have precedence over the values in `users` .
2021-02-11 14:34:04 +01:00
- For security reasons, the field `users` doesn't exist for Kubernetes IngressRoute, and one should use the `secret` field instead.
2019-09-05 13:42:04 +02:00
2023-05-10 15:28:05 +02:00
```yaml tab="Docker & Swarm"
2019-09-05 13:42:04 +02:00
labels:
2019-09-23 17:00:06 +02:00
- "traefik.http.middlewares.test-auth.digestauth.users=test:traefik:a2688e031edb4be6a3797f3882655c05,test2:traefik:518845800f9e2bfb1f1f740ec24f074e"
2019-09-05 13:42:04 +02:00
```
```yaml tab="Kubernetes"
2023-03-20 15:38:08 +01:00
apiVersion: traefik.io/v1alpha1
2019-09-05 13:42:04 +02:00
kind: Middleware
metadata:
name: test-auth
spec:
digestAuth:
secret: authsecret
---
apiVersion: v1
kind: Secret
metadata:
name: authsecret
namespace: default
data:
users: |2
2019-09-12 10:18:04 +02:00
dGVzdDp0cmFlZmlrOmEyNjg4ZTAzMWVkYjRiZTZhMzc5N2YzODgyNjU1YzA1CnRlc3QyOnRyYWVmaWs6NTE4ODQ1ODAwZjllMmJmYjFmMWY3NDBlYzI0ZjA3NGUKCg==
2019-09-05 13:42:04 +02:00
```
2019-10-15 18:34:08 +03:00
```yaml tab="Consul Catalog"
- "traefik.http.middlewares.test-auth.digestauth.users=test:traefik:a2688e031edb4be6a3797f3882655c05,test2:traefik:518845800f9e2bfb1f1f740ec24f074e"
```
2019-09-05 13:42:04 +02:00
```yaml tab="File (YAML)"
http:
middlewares:
test-auth:
digestAuth:
users:
2019-09-23 17:00:06 +02:00
- "test:traefik:a2688e031edb4be6a3797f3882655c05"
- "test2:traefik:518845800f9e2bfb1f1f740ec24f074e"
2019-09-05 13:42:04 +02:00
```
2019-02-26 05:50:07 -08:00
2021-06-19 00:08:08 +02:00
```toml tab="File (TOML)"
[http.middlewares]
[http.middlewares.test-auth.digestAuth]
users = [
"test:traefik:a2688e031edb4be6a3797f3882655c05",
"test2:traefik:518845800f9e2bfb1f1f740ec24f074e",
]
```
2019-07-01 11:30:05 +02:00
### `usersFile`
2019-02-26 05:50:07 -08:00
The `usersFile` option is the path to an external file that contains the authorized users for the middleware.
The file content is a list of `name:realm:encoded-password` .
2019-09-23 14:32:04 +02:00
!!! note ""
2021-02-11 14:34:04 +01:00
2019-09-05 13:42:04 +02:00
- If both `users` and `usersFile` are provided, the two are merged. The contents of `usersFile` have precedence over the values in `users` .
2021-06-19 00:08:08 +02:00
- Because it does not make much sense to refer to a file path on Kubernetes, the `usersFile` field doesn't exist for Kubernetes IngressRoute, and one should use the `secret` field instead.
2019-09-05 13:42:04 +02:00
2023-05-10 15:28:05 +02:00
```yaml tab="Docker & Swarm"
2019-09-05 13:42:04 +02:00
labels:
2019-09-23 17:00:06 +02:00
- "traefik.http.middlewares.test-auth.digestauth.usersfile=/path/to/my/usersfile"
2019-09-05 13:42:04 +02:00
```
```yaml tab="Kubernetes"
2023-03-20 15:38:08 +01:00
apiVersion: traefik.io/v1alpha1
2019-09-05 13:42:04 +02:00
kind: Middleware
metadata:
name: test-auth
spec:
digestAuth:
secret: authsecret
---
apiVersion: v1
kind: Secret
metadata:
name: authsecret
namespace: default
data:
users: |2
dGVzdDokYXByMSRINnVza2trVyRJZ1hMUDZld1RyU3VCa1RycUU4d2ovCnRlc3QyOiRhcHIxJGQ5
aHI5SEJCJDRIeHdnVWlyM0hQNEVzZ2dQL1FObzAK
```
2019-10-15 18:34:08 +03:00
```yaml tab="Consul Catalog"
- "traefik.http.middlewares.test-auth.digestauth.usersfile=/path/to/my/usersfile"
```
2019-09-05 13:42:04 +02:00
```yaml tab="File (YAML)"
http:
middlewares:
test-auth:
digestAuth:
usersFile: "/path/to/my/usersfile"
```
2021-06-19 00:08:08 +02:00
```toml tab="File (TOML)"
[http.middlewares]
[http.middlewares.test-auth.digestAuth]
usersFile = "/path/to/my/usersfile"
```
2019-02-26 05:50:07 -08:00
??? example "A file containing test/test and test2/test2"
2019-04-24 17:44:04 +02:00
```txt
2019-02-26 05:50:07 -08:00
test:traefik:a2688e031edb4be6a3797f3882655c05
test2:traefik:518845800f9e2bfb1f1f740ec24f074e
```
2019-07-01 11:30:05 +02:00
### `realm`
2019-02-26 05:50:07 -08:00
2021-02-11 14:34:04 +01:00
You can customize the realm for the authentication with the `realm` option. The default value is `traefik` .
2019-02-26 05:50:07 -08:00
2023-05-10 15:28:05 +02:00
```yaml tab="Docker & Swarm"
2019-09-05 13:42:04 +02:00
labels:
2019-09-23 17:00:06 +02:00
- "traefik.http.middlewares.test-auth.digestauth.realm=MyRealm"
2019-09-05 13:42:04 +02:00
```
```yaml tab="Kubernetes"
2023-03-20 15:38:08 +01:00
apiVersion: traefik.io/v1alpha1
2019-09-05 13:42:04 +02:00
kind: Middleware
metadata:
name: test-auth
spec:
digestAuth:
realm: MyRealm
```
2019-10-15 18:34:08 +03:00
```yaml tab="Consul Catalog"
- "traefik.http.middlewares.test-auth.digestauth.realm=MyRealm"
```
2019-09-05 13:42:04 +02:00
```yaml tab="File (YAML)"
http:
middlewares:
test-auth:
digestAuth:
realm: "MyRealm"
```
2021-06-19 00:08:08 +02:00
```toml tab="File (TOML)"
[http.middlewares]
[http.middlewares.test-auth.digestAuth]
realm = "MyRealm"
```
2019-07-01 11:30:05 +02:00
### `headerField`
2019-02-26 05:50:07 -08:00
You can customize the header field for the authenticated user using the `headerField` option.
2023-05-10 15:28:05 +02:00
```yaml tab="Docker & Swarm"
2019-04-03 14:32:04 +02:00
labels:
- "traefik.http.middlewares.my-auth.digestauth.headerField=X-WebAuth-User"
```
```yaml tab="Kubernetes"
2023-03-20 15:38:08 +01:00
apiVersion: traefik.io/v1alpha1
2019-04-03 14:32:04 +02:00
kind: Middleware
metadata:
name: my-auth
spec:
digestAuth:
# ...
headerField: X-WebAuth-User
```
2019-10-15 18:34:08 +03:00
```yaml tab="Consul Catalog"
- "traefik.http.middlewares.my-auth.digestauth.headerField=X-WebAuth-User"
2019-04-08 17:14:08 +02:00
```
2019-07-22 09:58:04 +02:00
```yaml tab="File (YAML)"
http:
middlewares:
my-auth:
digestAuth:
# ...
headerField: "X-WebAuth-User"
```
2021-06-19 00:08:08 +02:00
```toml tab="File (TOML)"
[http.middlewares.my-auth.digestAuth]
# ...
headerField = "X-WebAuth-User"
```
2019-07-01 11:30:05 +02:00
### `removeHeader`
2019-02-26 05:50:07 -08:00
Set the `removeHeader` option to `true` to remove the authorization header before forwarding the request to your service. (Default value is `false` .)
2019-09-05 13:42:04 +02:00
2023-05-10 15:28:05 +02:00
```yaml tab="Docker & Swarm"
2019-09-05 13:42:04 +02:00
labels:
2019-09-23 17:00:06 +02:00
- "traefik.http.middlewares.test-auth.digestauth.removeheader=true"
2019-09-05 13:42:04 +02:00
```
```yaml tab="Kubernetes"
2023-03-20 15:38:08 +01:00
apiVersion: traefik.io/v1alpha1
2019-09-05 13:42:04 +02:00
kind: Middleware
metadata:
name: test-auth
spec:
digestAuth:
removeHeader: true
```
2019-10-15 18:34:08 +03:00
```yaml tab="Consul Catalog"
- "traefik.http.middlewares.test-auth.digestauth.removeheader=true"
```
2019-09-05 13:42:04 +02:00
```yaml tab="File (YAML)"
http:
middlewares:
test-auth:
digestAuth:
removeHeader: true
```
2021-06-19 00:08:08 +02:00
```toml tab="File (TOML)"
[http.middlewares]
[http.middlewares.test-auth.digestAuth]
removeHeader = true
```