Files
crowdsec-bouncer-traefik-pl…/examples/kubernetes
2026-07-05 19:56:15 +02:00
..
2026-07-05 19:56:15 +02:00
2026-07-05 19:56:15 +02:00
2023-09-24 13:31:29 +02:00

Kubernetes Example

Official docs

Install Kubernetes on Docker Desktop

Install Docker Desktop

https://www.docker.com/products/docker-desktop/

In settings, click on Kubernetes menu, and click Enable Kubernetes, then Apply and Restart.
In case of any issue, you can reset the cluster from this menu and the button Reset Kubernetes Cluster.

Install Kubernetes on Minikube

Install Minikube

curl -Lo minikube https://storage.googleapis.com/minikube/releases/latest/minikube-linux-amd64 \
  && chmod +x minikube
sudo mkdir -p /usr/local/bin/
sudo install minikube /usr/local/bin/
minikube start
Install Traefik

getting-started/install-traefik/#use-the-helm-chart

helm repo add traefik https://traefik.github.io/charts
helm repo update
kubectl create ns traefik
helm upgrade --version v28.0.0 --install --namespace=traefik \
    --values=./traefik/values.yml \
    traefik traefik/traefik

A bug has been fixed in chart 26.1.0 that could prevent plugin to be loaded

v28.0.0 of the Traefik helm chart is only compatible with v3 of Traefik

View the Traefik dashboard

Port forward the dashboard:

kubectl --namespace=traefik port-forward $(kubectl get pods --namespace=traefik --selector "app.kubernetes.io/name=traefik" --output=name) 9000:9000

Access the dashboard with: localhost:9000/dashboard/#/

Install the plugin

kubectl apply -f traefik/plugin.yml

Install Whoami

kubectl apply -f whoami/whoami.yml
kubectl apply -f whoami/whoami-services.yml
kubectl apply -f whoami/whoami-ingress.yml

Access Whoami

Port forward web port of Traefik

kubectl --namespace=traefik port-forward $(kubectl get pods --namespace=traefik --selector "app.kubernetes.io/name=traefik" --output=name) 8000:8000

Access the whoami with: localhost:8000/

Install Crowdsec

helm/crowdsec/crowdsec

helm repo add crowdsec https://crowdsecurity.github.io/helm-charts
helm repo update
kubectl create ns crowdsec
helm upgrade --install --namespace=crowdsec \
    --values=./crowdsec/values.yml \
    crowdsec crowdsec/crowdsec

Read Traefik Logs

kubectl get pod --namespace traefik
kubectl logs $(kubectl get pods --namespace=traefik --selector "app.kubernetes.io/name=traefik" --output=name) --namespace traefik -f

Use CSCLI in Crowdsec container

kubectl -n crowdsec exec -it $(kubectl get pods -n crowdsec --selector "k8s-app=crowdsec,type=lapi" --output=name) bash

Shell in Traefik container

kubectl -n traefik exec -it $(kubectl get pods -n traefik --selector "app.kubernetes.io/name=traefik" --output=name) sh