Traefik plugin

Traefik plugin that blocks bots and VPNs

Bots, Tor, VPNs and proxies, checked per router with one label. It starts in monitor mode and blocks nothing until you switch.

Free, MIT licenseTested with Traefik v3.7

Traffic classes

What it checks

Each visitor gets one class. Your service receives it as X-IPScanner-Class.

  • Human
  • Verified bot
  • VPN
  • Private relay
  • Hosting
  • Proxy
  • Tor
  • AI agent
  • Malicious automation

Setup

Four steps, monitor mode first

  1. 1

    Create an API key

    Put it in the Traefik container's environment. Every ipscanner middleware reads it.

    Create a free API key
    docker-compose.yml
    environment:
      IPSCANNER_API_KEY: pk_live_...
  2. 2

    Declare the plugin

    In the static configuration, or as two CLI flags. Restart Traefik.

    traefik.yml
    experimental:
      plugins:
        ipscanner:
          moduleName: github.com/ipscanner/ipscanner-traefik
          version: v0.1.0
  3. 3

    Add a site and set siteId

    Mode and policy then come from the dashboard, without a reload.

    Add a site in the dashboard
    labels
    traefik.http.middlewares.ipscanner.plugin.ipscanner.siteId=site_...
  4. 4

    Attach it to a router

    Other routers reuse it as ipscanner@docker.

    labels
    traefik.http.routers.app.middlewares=ipscanner

Your stack

Coolify, Compose or Kubernetes

Same plugin, wherever Traefik reads its config.

Servers › your server › Proxy
command:
  # ...the flags Coolify set
  - '--experimental.plugins.ipscanner.modulename=github.com/ipscanner/ipscanner-traefik'
  - '--experimental.plugins.ipscanner.version=v0.1.0'
environment:
  - IPSCANNER_API_KEY=pk_live_...
Your app › Configuration › Container Labels
traefik.http.middlewares.ipscanner-myapp.plugin.ipscanner.siteId=site_...
traefik.http.routers.https-0-<uuid>.middlewares=gzip,ipscanner-myapp

One middleware name per app, appended to each router Coolify generated. Behind Cloudflare, also set trustedProxies=cloudflare and ipHeaders=CF-Connecting-IP.

Sites dashboard

Change the policy without touching Traefik

Allow, flag or block each class from the dashboard. The middleware picks up a change within 30 seconds.

  • Verified search and AI crawlers always pass.
  • Monitor mode blocks nothing and shows what it would have blocked.
  • If IPScanner does not answer within 1.5 seconds, the request goes through.

Options

Middleware options

Set them on the middleware: as labels, in YAML or on the CRD.

OptionDefault
siteIdYour dashboard site; mode and policy come from itEmpty
modemonitor or enforce, when there is no siteIdmonitor
blockClassesClasses blocked in enforce mode without siteIdmalicious_automation
trustedProxiesProxies whose IP headers are trusted: CIDRs, private, cloudflareEmpty
ipHeadersHeaders read from a trusted proxy, in orderX-Forwarded-For
timeoutBudget for one check, then the request passes1500ms
cacheTTLVerdict cache per visitor10m
cacheSizeVisitors kept in the cache10000
policyTTLHow long a fetched policy stays fresh30s
skipPathsPath regex that skips the checkStatic assets
apiKeyFileFile holding the API key, for secretsEmpty
debugAdds the headers to responses and logs each decisionfalse

Questions

Traefik plugin FAQ

Each visitor is checked once every 10 minutes and the verdict is cached in memory, so repeat requests skip the API. A check has 1.5 seconds; after that the request goes through.

Start in monitor mode

Add the middleware, read a week of traffic in the dashboard, then block.