All Tools View Categories About Contact Privacy

Traefik to Nginx Converter

Translate Traefik routers, services and load-balancer URLs into Nginx server blocks.

Runs entirely in your browser - nothing is uploaded and no cloud connection is made.
Your nginx config from Traefik will appear here.
-
servers
-
backends

About Traefik to Nginx Converter

Teams that outgrow Traefik or want to standardise on nginx often face the painful job of rewriting every router rule, service reference and load-balancer URL into nginx server and location blocks. The Traefik to Nginx Converter parses the familiar traefik.http.routers.* and traefik.http.services.* labels, pulls the Host and PathPrefix from each rule, resolves the backend from a load-balancer url or port, and emits a clean nginx server block with proxy_pass and forwarded headers.

At the heart of the configuration are a handful of directives. server the nginx context emitted per Traefik router, listening on port 80 for the router host. server_name derived from the Traefik Host() rule so nginx answers for the same domain. location derived from the Traefik PathPrefix() rule and wraps the proxying for that path. proxy_pass forwards to the resolved backend, using the scheme and host:port taken from the Traefik service. proxy_set_header rewrites Host and the X-Forwarded-* chain so the backend sees the original request metadata. listen declares the nginx port; 80 is used as a baseline you can later extend with TLS. Together they shape how the server behaves, and the tool assembles them in the right context so the result is valid on the first try.

Common mistakes are easy to make. A router without a Host() rule cannot become a server_name, so the converter rejects it instead of guessing a domain. Traefik middlewares such as basic auth or rate limiting are not translated, so you must add the matching nginx directives yourself. If a service has neither a url nor a port the tool assumes port 80, which may not match your real backend. PathPrefix becomes a prefix location; for exact or regex matching you must edit the generated location afterwards. The generator anticipates each of these and either sets a safe default or rejects the input with a clear message before anything is written to your clipboard.

Validation is strict because small configuration errors fail in subtle ways. Every input is checked for plausibility, and after the block is assembled it is re-parsed by a built-in tokenizer so unbalanced braces, missing semicolons or stray characters cannot reach your clipboard. Stat cards report line and block counts, and copy, download and print exports are one click away. Everything runs in your browser; nothing you type is transmitted to any server.

In practice this block drops into any standard nginx install. Save the output as a file under /etc/nginx/conf.d/ (or sites-available with a symlink), run nginx -t to confirm the syntax, then reload with nginx -s reload. Because the generator emits a single, self-contained server block with no hidden dependencies, it composes cleanly with your existing caching, logging and security configuration without directive collisions.

Beyond producing correct config, the tool is a reference you can read back and learn from. Each control maps to a real nginx directive, the sample button shows a complete working block in seconds, and clearing the form resets every field to its safe default. Standardising on a generator like this removes per-developer variation, keeps your configuration readable, and gives you a repeatable, auditable setup that passes nginx -t on the first try.

When something looks wrong in production, the first move is always to re-run nginx -t and inspect /var/log/nginx/error.log; most failures surface there with a line number. The access log records every request, so a sudden spike or a wall of 499 responses points straight at backend or timeout problems the generator helps you avoid in the first place.

This server block is designed to sit alongside - not fight - your other configuration. Because it declares its own server_name and a single, self-contained set of directives, you can drop it into conf.d without worrying about collisions with global caching, logging or security snippets that live elsewhere in the nginx tree.

For a production site, pair this block with TLS termination: serve on 80 for the redirect or health checks, and place the encrypted listener (or a front-end load balancer / CDN) in front so clients always speak HTTPS. The generator keeps that boundary clean so the two layers compose instead of overlapping.

If a change ever needs to be undone, the output is plain text you control: delete the file from conf.d, re-run nginx -t, and reload. There is no database and no hidden state, so rolling back is as simple as restoring the previous version from version control or your own backup.

Performance and correctness both benefit from explicit configuration. Defaults baked into the generator reflect current best practice rather than decades-old forum snippets, so the block you ship today will not surprise you with deprecated directives or insecure fallbacks six months from now.

Features

  • server - the nginx context emitted per Traefik router, listening on port 80 for the router host.
  • server_name - derived from the Traefik Host() rule so nginx answers for the same domain.
  • location - derived from the Traefik PathPrefix() rule and wraps the proxying for that path.
  • proxy_pass - forwards to the resolved backend, using the scheme and host:port taken from the Traefik service.
  • proxy_set_header - rewrites Host and the X-Forwarded-* chain so the backend sees the original request metadata.
  • listen - declares the nginx port; 80 is used as a baseline you can later extend with TLS.
  • Self-verifying output re-parsed before display.
  • Copy, Download and Print exports.
  • Load-sample button fills realistic values.
  • Statistics cards for quick checks.
  • Runs entirely in your browser - nothing uploaded.

How to Use

  1. Paste your Traefik labels or static router/service lines into the source box.
  2. Set the default upstream scheme (http or https).
  3. Click Convert to Nginx (or Load sample) and review the server blocks.
  4. Confirm each server_name matches the expected Host() value.
  5. Confirm each location maps the right PathPrefix() and proxy_pass backend.
  6. Copy or download the config and drop it into conf.d, then run nginx -t.
  7. Reload nginx and verify routing against the original Traefik behaviour.

Examples

Example 1 - Host and PathPrefix a router with Host and PathPrefix yields one server and one location proxying to the service url.

Example 2 - Service port only a service with just a loadbalancer port becomes service:port as the proxy_pass target.

Example 3 - Custom scheme setting scheme to https flips the proxy_pass protocol for the backend.

Example 4 - Missing Host rejected a router whose rule has only PathPrefix is reported as an error before generation.

Example 5 - No routers rejected a paste with only middleware lines is reported as having no routers.

Benefits

  • Automatic router-to-server translation.
  • Backend resolved from url or port with a safe default.
  • Forwarded headers emitted for correct proxying.
  • Validation of the generated nginx before display.
  • Copy, Download and JSON export of the output.
  • Private: everything runs in your browser.

Frequently Asked Questions

Which Traefik format is supported?
Docker labels of the form traefik.http.routers.* and traefik.http.services.*, including loadbalancer server port and server url, are parsed.
How is the backend chosen?
If a service has a loadbalancer server url it is used directly; otherwise the service name and port are combined into an upstream address.
What about Traefik middlewares?
Middleware chains (auth, rate-limit) are not auto-translated; emit the equivalent nginx directives manually after conversion.
Does it handle PathPrefix vs Path?
Both are read from the rule; the captured path becomes an nginx location. Adjust the matcher if you need exact or regex matching.
Why only one server per router?
A Traefik router already binds one host and path set, so it maps cleanly to a single nginx server and location.
Is the generated nginx valid?
The emitted config is re-parsed by a built-in tokenizer before display, so unbalanced braces or bad directives are caught.
What about TLS in Traefik?
Certificate termination is dropped; add your own listen 443 ssl block or a front controller as needed.
Is anything uploaded?
No. All parsing and conversion happen locally in your browser.