Skip to content

Infrastructure

Goodbye Docker Traefik, Hello k3s: Migrating 24 DuckDNS Routes to cert-manager TLS

When your home lab outgrows Docker Compose, the reverse proxy becomes the first casualty. I ran Traefik as a Docker container with its own ACME resolver — issuing per-domain TLS certificates via DuckDNS DNS challenges. It worked for a year. Then k3s entered the picture, and everything broke.

This post documents the real, messy, iterative migration of 24 DuckDNS domains from Docker Traefik to k3s IngressRoutes backed by a single cert-manager Certificate with HTTP-01 challenges. Including the disk pressure evictions, corrupted Traefik images, and ACME email misconfigurations that happened along the way.