HNHacker News
TopNewBestAskShowJobs

emilevauge

290 karma · joined May 29, 2015

Founder traefik.io

[ my public key: https://keybase.io/emilevauge; my proof: https://keybase.io/emilevauge/sigs/UFCRdVUwDTmdUwilbRqqTp9f_t949Zz8IwBT18bcFDQ ]

submissionscomments
emilevauge··on Kubernetes Ingress Nginx is retiring
We have been building an ingress Nginx compatibility layer in Traefik that supports the most used ingress Nginx annotations. You should definitely give it a try as it makes Traefik a drop-in replacement to ingress Nginx, without touching your existing ingress resources. Your feedback will be super useful to make it better

https://traefik.io/blog/transition-from-ingress-nginx-to-tra...

emilevauge··on Ingress Nginx Retirement: What You Need to Know
We have been building an ingress Nginx compatibility layer in Traefik that supports the most used ingress Nginx annotations. You should definitely give it a try as it makes Traefik a drop-in replacement to ingress Nginx, without touching your existing ingress resources. Your feedback will be super useful to make it better

https://doc.traefik.io/traefik/master/reference/routing-conf...

emilevauge··on Traefik, Now With Native Go Plugins
Indeed, go plugins were our initial choice (https://github.com/traefik/traefik/pull/1865). But you said everything about how bad/impossible the workflow would have been for users. Building from scratch a go interpreter was not the easiest way, but this was the best solution regarding the UX.
emilevauge··on Traefik, Now With Native Go Plugins
This security issue is not that simple to manage as you probably know. It's mainly due to the fact that there is now way to have authorization on the the docker API. This is not the case on Kubernetes for example where you have RBAC to prevent this kind of issue. We have described this in detail in our documentation, and you have many solutions/workarounds to address this: https://doc.traefik.io/traefik/providers/docker/#docker-api-...
emilevauge··on Maesh, a Lightweight and Simpler Service Mesh
We think that it is interesting to have an alternative with a simpler design bringing almost all features. So yes, mTLS between pods is not supported. But it's a decent tradeoff for many users. Finally, mTLS could be supported in the future between nodes :)
emilevauge··on Maesh, a Lightweight and Simpler Service Mesh
Whæt's wröng?
emilevauge··on Maesh, a Lightweight and Simpler Service Mesh
Thanks! We deeply believe that the best infrastructure products are open and free from vendor lock-in. Being compliant to SMI will make both Maesh and the specifications stronger.
emilevauge··on HashiCorp Consul 1.2: Service Mesh
Traefik creator here. Wow, that's harsh!

You may encountered issues while using Traefik so giving your opinion is totally fine, but I don't think that's fair to overreact.

Many users (and I mean big companies) have been using Traefik in production for years without issue. I'm not saying there is not bug, which software can claim this, I'm just saying that many users have a good opinion on Traefik stability.

We follow semver, there shouldn't be any breaking change between 2 minor versions. But, yes, it can happen, sometimes, we may have forgot to check a specific use case. But hey, again, let's be fair, we don't want it. We are just human. And no, this does not happen at every minor version and this is pretty uncommon...

Finally, on Traefik size. You are including Traefik dependencies, in vendor/, which is a bit weird. In go, the convention is to push the dependencies in your repository to get reproducible builds, so that's not a good way to count. If you exclude vendor/:

golocc --no-vendor ./...

Lines of Code: 58532 (2987 CLOC, 55545 NCLOC)

Which is rather tiny.

So all in all, I regret you had such a bad experience with Traefik, but I just wanted to express the fact that many users are using it without any issue :) I would be happy to discuss further on this.

emilevauge··on HashiCorp Consul 1.2: Service Mesh
Could you elaborate? I would never say that the code is perfect, like any other "big" open source project, but we follow a pretty strict review process on each PR (3 LGTM from maintainers). I'm curious to know why you are so negative.
emilevauge··on Let's Encrypt and Nginx – State of the art secure web deployment
https://github.com/containous/traefik now has native Let's Encrypt support ;)
emilevauge··on Træfik, a modern reverse-proxy
You're absolutely right :) It should be better now.
emilevauge··on Træfik, a modern reverse-proxy
Ops, my bad. The release was in draft mode, not public... It should be better now :)
emilevauge··on Træfik, a modern reverse-proxy
The project on Github is simply traefik without the æ, so it should be ok :)
emilevauge··on Træfik, a modern reverse-proxy
I have made some tests, but as Træfɪk is still in developpement, I will publish some serious benchmarks later.

Besides, Træfɪk is not in the race of pure performance. It is fast and will be fast, but it's not my top priority.

emilevauge··on Træfik, a modern reverse-proxy
Binaries are here, I can see them :)
emilevauge··on Træfik, a modern reverse-proxy
It comes from http://phonemicchart.com/transcribe/?w=TRAFFIC ;)
emilevauge··on Træfik, a modern reverse-proxy
Hi! 1/ TLS 2/ Not for now, but definitely the roadmap 3/ Not in a near futur sorry :)
emilevauge··on Træfik, a modern reverse-proxy
In fact, I'm using https://github.com/mailgun/oxy, the reverse proxy Engine made by Mailgun to build Vulcand :) Vulcand is awsome. But I wanted to build something simpler, that would work not only with etcd, but also with Docker, Mesos, Consul, etc.