Upgrade Path

Traefik 3.3.0 → 3.4.0

8 versions, 5 migration-guide sections in 4 versions, 0 required stops

Version by version, oldest first

3.3.1 – 3.3.3: no action items (3 versions)

3.3.4 2025-02-25

Migration

OpenTelemetry Request Duration Metric

In v3.3.4, the OpenTelemetry Request Duration metric unit has been standardized to match other providers and naming conventions.

Change Details:

  • Metric: traefik_(entrypoint|router|service)_request_duration_seconds
  • Old Unit: Milliseconds
  • New Unit: Seconds

This change ensures consistency across all metrics providers and follows standard naming conventions.

From doc.traefik.io/traefik/migrate/v3/#opentelemetry-request-duration-metric

Full release notes for 3.3.4

3.3.5 2025-03-31

Migration

Compress Middleware Default Encodings

In v3.3.5, the default compression algorithms have been reordered to favor gzip compression.

New Default: gzip, br, zstd

This change affects requests that either:

  • Don't specify preferred algorithms in the Accept-Encoding header
  • Have no order preference in their Accept-Encoding header

The reordering helps ensure better compatibility with older clients that may not support newer compression algorithms.

From doc.traefik.io/traefik/migrate/v3/#compress-middleware-default-encodings

Full release notes for 3.3.5

3.3.6 2025-04-18

Migration

Request Path Sanitization

Starting with v3.3.6, incoming request paths are now automatically cleaned before processing for security and consistency.

What's Changed:

The following path segments are now interpreted and collapsed:

  • /../ (parent directory references)
  • /./ (current directory references)
  • Duplicate slash segments (//)

Disabling Sanitization:

# EntryPoint HTTP configuration
entryPoints:
  web:
    address: ":80"
    http:
      sanitizePath: false  # Not recommended

Security Warning

Setting sanitizePath: false is not safe. This option should only be used with legacy clients that don't properly URL-encode data. Always ensure requests are properly URL-encoded instead of disabling this security feature.

Example Risk: Base64 data containing "/" characters can lead to unsafe routing when path sanitization is disabled and the data isn't URL-encoded.

From doc.traefik.io/traefik/migrate/v3/#request-path-sanitization

Full release notes for 3.3.6

3.3.7: no action items (1 version)

3.4.0 2025-05-05

Migration

Kubernetes CRD Provider

Load-Balancing Strategy Updates

Starting with v3.4, HTTP service definitions now support additional load-balancing strategies for better traffic distribution.

Apply Updated CRDs:

kubectl apply -f https://raw.githubusercontent.com/traefik/traefik/v3.4/docs/content/reference/dynamic-configuration/kubernetes-crd-definition-v1.yml

New Strategy Values:

  • wrr (Weighted Round Robin)
  • p2c (Power of Two Choices)

Deprecation

The RoundRobin strategy is deprecated but still supported (equivalent to wrr). It will be removed in the next major release.

Refer to the HTTP Services Load Balancing documentation for detailed information.

ServersTransport CA Certificate Configuration

A new rootCAs option has been added to the ServersTransport and ServersTransportTCP CRDs. It supports both ConfigMaps and Secrets for CA certificates and replaces the rootCAsSecrets option.

Apply Updates:

# Update CRDs
kubectl apply -f https://raw.githubusercontent.com/traefik/traefik/v3.4/docs/content/reference/dynamic-configuration/kubernetes-crd-definition-v1.yml

# Update RBACs
kubectl apply -f https://raw.githubusercontent.com/traefik/traefik/v3.4/docs/content/reference/dynamic-configuration/kubernetes-crd-rbac.yml

New Configuration Format:

---
apiVersion: traefik.io/v1alpha1
kind: ServersTransport
metadata:
  name: foo
  namespace: bar
spec:
  rootCAs:
    - configMap: ca-config-map
    - secret: ca-secret
      
---      
apiVersion: traefik.io/v1alpha1
kind: ServersTransportTCP
metadata:
  name: foo
  namespace: bar
spec:
  rootCAs:
    - configMap: ca-config-map
    - secret: ca-secret

Deprecation

The rootCAsSecrets option (Secrets only) is still supported but deprecated. It will be removed in the next major release.

From doc.traefik.io/traefik/migrate/v3/#v33-to-v34

Migration

Rule Syntax Configuration

In v3.4, rule syntax configuration options will be removed in the next major version.

Deprecated Options:

  • core.defaultRuleSyntax (static configuration)
  • ruleSyntax (router option)

These options were transitional helpers for migrating from v2 to v3 syntax. Please ensure all router rules use v3 syntax before the next major release.

From doc.traefik.io/traefik/migrate/v3/#rule-syntax-configuration

Full release notes for 3.4.0

Release notes from github.com/traefik/traefik/blob/master/CHANGELOG.md, and Migration: Steps needed between the versions, checked 17 hours ago. Only text the vendor marks as breaking, or puts in a warning/caution/important note, is shown; read the full notes for anything else. Traefik's release notes (CHANGELOG.md, GitHub releases) are lists of merged pull requests and mark nothing as breaking. What is quoted instead is Traefik's migration documentation on doc.traefik.io: “Migration: Steps needed between the versions” (v3), the same page of the v2.11 documentation (v2), and “Configuration Details for Migrating from Traefik v2 to v3” (on 3.0.0). Each section of those pages is labelled “Migration” and shown on the release its heading names (“v3.3 to v3.4” on 3.4.0). A section naming a canceled release (v2.4.10, v2.9.0) is shown on the next release of that line. Versions are covered from 2.0.0. No required stop is documented.