# Crowdsec add Bouncer to Traefik in Docker container

**URL:** <https://discourse.crowdsec.net/t/crowdsec-add-bouncer-to-traefik-in-docker-container/1627>\
**Category:** Uncategorized\
**Created:** [January 31, 2024, 2:17pm UTC](https://discourse.crowdsec.net/t/crowdsec-add-bouncer-to-traefik-in-docker-container/1627 "2024-01-31T14:17:48Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Tbs](https://avatars.discourse-cdn.com/v4/letter/t/5f9b8f/32.png) [@Tbs](https://discourse.crowdsec.net/u/Tbs)\
**Post date:** [January 31, 2024, 2:17pm UTC](https://discourse.crowdsec.net/t/crowdsec-add-bouncer-to-traefik-in-docker-container/1627/1 "2024-01-31T14:17:48Z")

</div>

Hello,  
i try since many hours to get the crowdsec bouncer for https to work - but I failed. With that configuration below, whoami doesnt work anymore.

Can anybody tell me, what I should do different?

Traefik static yml

```auto
experimental:
  plugins:
    bouncer:
      moduleName: github.com/maxlerebourg/crowdsec-bouncer-traefik-plugin
      version: v1.2.0-rc1

```

Traefik dynamic yml:

```auto
http:
    middlewares:
        crowdsec:
            plugin:
                bouncer:
                    enabled: true
                    logLevel: DEBUG
                    CrowdsecMode: live
                    CrowdsecAppsecEnabled: true
                    CrowdsecAppsecHost: crowdsec:7422
                    CrowdsecLapiScheme: https
                    CrowdsecLapiTLSInsecureVerify: true
                    CrowdsecLapiHost: crowdsec:8080
                    CrowdsecLapiKey: xxx
                    CrowdsecAppsecFailureBlock: true

    services:
      service-whoami:
        loadBalancer:
          servers:
            - url: http://whoami:80

    routers:
      # Define the router for the whoami service
      router-whoami:
        rule: "Host(`url.net`) && PathPrefix(`/whoami`)"
        service: service-whoami
        entryPoints:
          - websecure
        middlewares:
          - crowdsec
        tls:
          certResolver: myresolver

```

Whoami compose:

```auto
version: "3.9"

services:
  whoami:
    image: "traefik/whoami"
    container_name: "whoami"

    labels:
      traefik.enable: true
      traefik.http.routers.router-whoami.rule: Host(`url.net`) && PathPrefix(`/whoami`)
      traefik.http.routers.router-whoami.entrypoints: websecure
      traefik.http.routers.router-whoami.tls.certresolver: myresolver
      traefik.http.routers.router-whoami.middlewares: crowdsec

    networks:
      - traefik_ingress
networks:
  traefik_ingress:
    external: true

```

Thanks a lot  
Tbs

---

<div class="post-metadata">

**Author:** ![iiAmLoz](https://dub1.discourse-cdn.com/flex013/user_avatar/discourse.crowdsec.net/iiamloz/32/386_2.png) [@iiAmLoz](https://discourse.crowdsec.net/u/iiAmLoz)\
**Post date:** [January 31, 2024, 2:22pm UTC](https://discourse.crowdsec.net/t/crowdsec-add-bouncer-to-traefik-in-docker-container/1627/2 "2024-01-31T14:22:38Z")

</div>

Have you setup TLS within crowdsec?

Also including the logs that traefik spits out might help us dig down

---

<div class="post-metadata">

**Author:** ![Tbs](https://avatars.discourse-cdn.com/v4/letter/t/5f9b8f/32.png) [@Tbs](https://discourse.crowdsec.net/u/Tbs)\
**Post date:** [January 31, 2024, 3:14pm UTC](https://discourse.crowdsec.net/t/crowdsec-add-bouncer-to-traefik-in-docker-container/1627/4 "2024-01-31T15:14:49Z")

</div>

Sorry for missing that.

In the dashboard it shows one http error: middleware “crowdsec@docker” does not exist

The full traefik.log will come in the next post as soon as a staff member checked that.

The crowdsec compose file from crowdsec is:

```auto
version: "3.4"

services:
  crowdsec:
    image: crowdsecurity/crowdsec:latest
    container_name: crowdsec
    ports:
    - "8080:8080"
    - "7422:7422"
    environment:
      PGID: "1000"
      GID: "1000"
      TZ: "Europe/Berlin"
      COLLECTIONS: "crowdsecurity/traefik crowdsecurity/http-cve crowdsecurity/http-dos crowdsecurity/base-http-scenarios crowdsecurity/iptables crowdsecurity/linux crowdsecurity/pgsql crowdsecurity/nextcloud crowdsecurity/sshd crowdsecurity/sshd-impossible-travel crowdsecurity/whitelist-good-actors"
      BOUNCER_KEY_TRAEFIK: "key"
    volumes:
      - ./crowdsec/data:/var/lib/crowdsec/data
      - ./crowdsec:/etc/crowdsec  
      - ./crowdsec/logs/web:/logs/web:ro
      - /var/log/:/var/log/:ro 

    restart: always
    network_mode: host

```

To your question, if I have setup TLS within crowdsec. I dont think so ☹ How can I do that?

---

<div class="post-metadata">

**Author:** ![iiAmLoz](https://dub1.discourse-cdn.com/flex013/user_avatar/discourse.crowdsec.net/iiamloz/32/386_2.png) [@iiAmLoz](https://discourse.crowdsec.net/u/iiAmLoz)\
**Post date:** [January 31, 2024, 4:07pm UTC](https://discourse.crowdsec.net/t/crowdsec-add-bouncer-to-traefik-in-docker-container/1627/5 "2024-01-31T16:07:05Z")

</div>

> [@Tbs](#):
>
> To your question, if I have setup TLS within crowdsec. I dont think so ☹ How can I do that?

You need to configure the [tls section of the config](https://docs.crowdsec.net/docs/next/configuration/crowdsec_configuration#tls)

And I am staff so I will review the post, however, if you havent setup TLS in the first place that is most likely the first issue

---

<div class="post-metadata">

**Author:** ![Tbs](https://avatars.discourse-cdn.com/v4/letter/t/5f9b8f/32.png) [@Tbs](https://discourse.crowdsec.net/u/Tbs)\
**Post date:** [February 1, 2024, 3:19pm UTC](https://discourse.crowdsec.net/t/crowdsec-add-bouncer-to-traefik-in-docker-container/1627/6 "2024-02-01T15:19:11Z")

</div>

Thanks for that hint. I updated the config.yaml but I am not sure if that is correct (sorry, I am here a totally beginner):

```auto
cscli:
  output: human
db_config:
  log_level: info
  type: sqlite
  db_path: /var/lib/crowdsec/data/crowdsec.db
  flush:
    max_items: 5000
    max_age: 7d
  use_wal: false
api:
  client:
    insecure_skip_verify: false
    credentials_path: /etc/crowdsec/local_api_credentials.yaml
  server:
    log_level: info
    listen_uri: 0.0.0.0:8080
    profiles_path: /etc/crowdsec/profiles.yaml
    trusted_ips: # IP ranges, or IPs which can have admin API access
      - 127.0.0.1
      - ::1
    online_client: # Central API credentials (to push signals and receive bad IPs)
      credentials_path: /etc/crowdsec/online_api_credentials.yaml
    enable: true
    tls:
       cert_file: /var/lib/crowdsec/data/crowdsec-cert.pem
       key_file: /var/lib/crowdsec/data/crowdsec-key.pem
       client_verification: "NoClientCert"
prometheus:
  enabled: true
  level: full
  listen_addr: 0.0.0.0
  listen_port: 6060

```

Br  
Tbs

---

<div class="post-metadata">

**Author:** ![iiAmLoz](https://dub1.discourse-cdn.com/flex013/user_avatar/discourse.crowdsec.net/iiamloz/32/386_2.png) [@iiAmLoz](https://discourse.crowdsec.net/u/iiAmLoz)\
**Post date:** [February 1, 2024, 3:49pm UTC](https://discourse.crowdsec.net/t/crowdsec-add-bouncer-to-traefik-in-docker-container/1627/7 "2024-02-01T15:49:40Z")

</div>

> [@Tbs](#):
>
> ```auto
> tls:
> cert_file: /var/lib/crowdsec/data/crowdsec-cert.pem
> key_file: /var/lib/crowdsec/data/crowdsec-key.pem
> client_verification: "NoClientCert"
> 
> ```

So these files are mounted into the container?

---

<div class="post-metadata">

**Author:** ![Tbs](https://avatars.discourse-cdn.com/v4/letter/t/5f9b8f/32.png) [@Tbs](https://discourse.crowdsec.net/u/Tbs)\
**Post date:** [February 1, 2024, 4:00pm UTC](https://discourse.crowdsec.net/t/crowdsec-add-bouncer-to-traefik-in-docker-container/1627/8 "2024-02-01T16:00:47Z")

</div>

Yes correct, I mounted them via compose file to the container.

The error in the dashboard is still: middleware “crowdsec@docker” does not exist

---

<div class="post-metadata">

**Author:** ![iiAmLoz](https://dub1.discourse-cdn.com/flex013/user_avatar/discourse.crowdsec.net/iiamloz/32/386_2.png) [@iiAmLoz](https://discourse.crowdsec.net/u/iiAmLoz)\
**Post date:** [February 1, 2024, 7:30pm UTC](https://discourse.crowdsec.net/t/crowdsec-add-bouncer-to-traefik-in-docker-container/1627/9 "2024-02-01T19:30:37Z")

</div>

> [@Tbs](#):
>
> The error in the dashboard is still: middleware “crowdsec@docker” does not exist

Then I advise to debug and see if traefik is actually loading the middlewares. I dont use traefik so I dont know how to debug that specific error
