Skip to content

Traefik and EspoCRM

Traefik is an open-source HTTP reverse proxy (and load balancer) that integrates well with containerized environments. It can automatically configure routing and manage TLS certificates through Let's Encrypt, simplifying deployment of web applications.

To integrate Traefik with EspoCRM, you can use the Docker Compose environment. You must also have a domain name.

1. Create a directory.

2. Create docker-compose.yml file in that directory:

docker-compose.yml

services:

  traefik:
    image: traefik:latest
    container_name: traefik
    command:
      - --api.insecure=true
      - --providers.docker=true
      - --providers.docker.exposedbydefault=false
      - --entrypoints.websecure.address=:443
      - --entrypoints.web.address=:80
      - --entrypoints.web.http.redirections.entryPoint.to=websecure
      - --entrypoints.web.http.redirections.entryPoint.scheme=https
      - --entrypoints.web.http.redirections.entrypoint.permanent=true
      - --certificatesresolvers.esporesolver.acme.tlschallenge=true
      - --certificatesresolvers.esporesolver.acme.email={EMAIL_ADDRESS}
      - --certificatesresolvers.esporesolver.acme.storage=/letsencrypt/acme.json
    ports:
      - "80:80"
      - "8080:8080"
      - "443:443"
    volumes:
      - ./letsencrypt:/letsencrypt
      - /var/run/docker.sock:/var/run/docker.sock:ro

  espocrm-db:
    image: mariadb:latest
    container_name: espocrm-db
    environment:
      MARIADB_ROOT_PASSWORD: your_root_password
      MARIADB_DATABASE: espocrm
      MARIADB_USER: espocrm
      MARIADB_PASSWORD: your_database_password
    volumes:
      - espocrm-db:/var/lib/mysql
    restart: unless-stopped
    healthcheck:
      test: ["CMD", "healthcheck.sh", "--connect", "--innodb_initialized"]
      interval: 20s
      start_period: 10s
      timeout: 10s
      retries: 3

  espocrm:
    image: espocrm/espocrm:latest
    container_name: espocrm
    environment:
      ESPOCRM_DATABASE_HOST: espocrm-db
      ESPOCRM_DATABASE_USER: espocrm
      ESPOCRM_DATABASE_PASSWORD: your_database_password
      ESPOCRM_ADMIN_USERNAME: admin
      ESPOCRM_ADMIN_PASSWORD: your_admin_password
      ESPOCRM_SITE_URL: "https://{ESPOCRM_DOMAIN}"
    volumes:
      - espocrm-data:/var/www/html/data
      - espocrm-custom:/var/www/html/custom
      - espocrm-custom-client:/var/www/html/client/custom
    restart: unless-stopped
    depends_on:
      espocrm-db:
        condition: service_healthy
    healthcheck:
      test: ["CMD", "bin/command", "app-check"]
      start_period: 20s
      interval: 60s
      timeout: 20s
      retries: 3
    labels:
      - traefik.enable=true
      - traefik.http.routers.espocrm-app.rule=Host(`{ESPOCRM_DOMAIN}`)
      - traefik.http.routers.espocrm-app.entrypoints=websecure
      - traefik.http.routers.espocrm-app.tls=true
      - traefik.http.routers.espocrm-app.tls.certresolver=esporesolver

  espocrm-daemon:
    image: espocrm/espocrm:latest
    container_name: espocrm-daemon
    volumes_from:
      - espocrm
    restart: unless-stopped
    entrypoint: docker-daemon.sh
    depends_on:
      espocrm:
        condition: service_healthy
    healthcheck:
      test: ["CMD", "bin/command", "app-check"]
      start_period: 20s
      interval: 180s
      timeout: 20s
      retries: 3

  espocrm-websocket:
    image: espocrm/espocrm:latest
    container_name: espocrm-websocket
    environment:
      ESPOCRM_CONFIG_USE_WEB_SOCKET: "true"
      ESPOCRM_CONFIG_WEB_SOCKET_ZERO_M_Q_SUBSCRIBER_DSN: "tcp://*:7777"
      ESPOCRM_CONFIG_WEB_SOCKET_ZERO_M_Q_SUBMISSION_DSN: "tcp://espocrm-websocket:7777"
    volumes_from:
      - espocrm
    restart: unless-stopped
    entrypoint: docker-websocket.sh
    depends_on:
      espocrm:
        condition: service_healthy
    healthcheck:
      test: ["CMD", "bin/command", "app-check"]
      start_period: 20s
      interval: 180s
      timeout: 20s
      retries: 3
    labels:
      - traefik.enable=true
      - traefik.http.routers.espocrm-ws.rule=Host(`{ESPOCRM_DOMAIN}`) && PathPrefix(`/ws`)
      - traefik.http.routers.espocrm-ws.entrypoints=websecure
      - traefik.http.routers.espocrm-ws.tls=true
      - traefik.http.routers.espocrm-ws.tls.certresolver=esporesolver
      - traefik.http.services.espocrm-ws.loadbalancer.server.port=8080

volumes:
  espocrm-db:
  espocrm-data:
  espocrm-custom:
  espocrm-custom-client:

Traefik container commands explanation:

  • api.insecure=trueEnable the API in insecure mode. You can access Traefik Dashboard at your_server_IP:8080
  • providers.docker=trueEnable Docker as the provider for Traefik
  • providers.docker.exposedbydefault=falseDon't expose every container to Traefik, only expose enabled ones
  • entrypoints.websecure.address=:443Define an entrypoint for HTTPS on port :443 named websecure
  • entrypoints.web.address=:80Define an entrypoint for port :80 named web
  • entrypoints.web.http.redirections.entryPoint.to=websecureRedirect all incoming requests to entrypoint websecure
  • entrypoints.web.http.redirections.entryPoint.scheme=httpsRedirection target scheme
  • entrypoints.web.http.redirections.entrypoint.permanent=trueApply a permanent redirection
  • certificatesresolvers.esporesolver.acme.tlschallenge=trueEnable TLS-ALPN-01 to generate and renew ACME certificates
  • certificatesresolvers.esporesolver.acme.email={EMAIL_ADDRESS}Setting email for certificates
  • certificatesresolvers.esporesolver.acme.storage=/letsencrypt/acme.jsonDefining acme.json file to store certificates information

EspoCRM container commands explanation:

  • traefik.enable=trueEnable Traefik to proxy main EspoCRM container
  • traefik.http.routers.espocrm-app.rule=Host({ESPOCRM_DOMAIN})Your domain name goes here for the HTTP rule
  • traefik.http.routers.espocrm-app.entrypoints=websecureDefine entrypoint for HTTPS
  • traefik.http.routers.espocrm-app.tls=trueMake sure all routers tied to this entrypoint are using HTTPS by default
  • traefik.http.routers.espocrm-app.tls.certresolver=esporesolverDefine certificates resolvers for HTTPS

The labels in the EspoCRM container for WebSocket works in exactly the same way, we only add a prefix to the host and open port 8080 for container.


3. Now, spin up the containers with the CLI command:

docker compose up -d

You can track the work of Traefik on the Dashboard at your_server_IP:8080.

EspoCRM will work with both HTTP and HTTPS on your domain.