Upgrade Path

Traefik 3.4.0 → 3.5.0

6 versions, 5 migration-guide sections in 3 versions, 0 required stops

Version by version, oldest first

3.4.1 2025-05-27

Migration

Request Path Normalization

Starting with v3.4.1, request paths are now normalized according to RFC 3986 standards for better consistency and security.

Normalization Process:

  1. Unreserved Character Decoding: Characters like %2E (.) are decoded to their literal form
  2. Case Normalization: Percent-encoded characters are uppercased (%2e becomes %2E)

This follows RFC 3986 percent-encoding normalization and case normalization standards.

Processing Order:

  1. Path normalization (cannot be disabled)
  2. Path sanitization (if enabled)

From doc.traefik.io/traefik/migrate/v3/#request-path-normalization

Migration

Reserved Character Handling in Routing

Starting with v3.4.1, reserved characters (per RFC 3986) remain encoded during router rule matching to prevent routing ambiguity.

Why This Matters: Reserved characters change the meaning of request paths when decoded. Keeping them encoded during routing prevents security vulnerabilities and ensures predictable routing behavior.

From doc.traefik.io/traefik/migrate/v3/#reserved-character-handling-in-routing

Migration

Request Path Matching Examples

The following table illustrates how path matching behavior has changed:

Request PathRouter RuleTraefik v3.4.0Traefik v3.4.1Explanation
/foo%2FbarPathPrefix(`/foo/bar`)MatchNo match%2F (/) stays encoded, preventing false matches
/foo/../barPathPrefix(`/foo`)No matchNo matchPath traversal is sanitized away
/foo/../barPathPrefix(`/bar`)MatchMatchResolves to /bar after sanitization
/foo/%2E%2E/barPathPrefix(`/foo`)MatchNo matchEncoded dots normalized then sanitized
/foo/%2E%2E/barPathPrefix(`/bar`)No matchMatchResolves to /bar after normalization + sanitization

From doc.traefik.io/traefik/migrate/v3/#request-path-matching-examples

Full release notes for 3.4.1

3.4.2 – 3.4.4: no action items (3 versions)

3.4.5 2025-07-23

Migration

MultiPath TCP

Since v3.4.5, the MultiPath TCP support introduced with v3.4.2 has been removed. It appears that enabling MPTCP on some platforms can cause Traefik to stop with the following error logs message:

  • set tcp X.X.X.X:X->X.X.X.X:X: setsockopt: operation not supported

However, it can be re-enabled by setting the multipathtcp variable in the GODEBUG environment variable, see the related go documentation.

From doc.traefik.io/traefik/migrate/v3/#multipath-tcp

Full release notes for 3.4.5

3.5.0 2025-07-23

Migration

Observability

TraceVerbosity on Routers and Entrypoints

Starting with v3.5.0, a new traceVerbosity option is available for both entrypoints and routers. This option allows you to control the level of detail for tracing spans. Routers can override the value inherited from their entrypoint.

Impact:

  • If you rely on tracing, review your configuration to explicitly set the desired verbosity level.
  • Existing configurations will default to minimal unless overridden, which will result in fewer spans being generated than before.

Possible values are:

  • minimal: produces a single server span and one client span for each request processed by a router.
  • detailed: enables the creation of additional spans for each middleware executed for each request processed by a router.

See the updated documentation for entrypoints and dynamic routers.

K8s Resource Attributes

Since v3.5.0, the semconv attributes k8s.pod.name and k8s.pod.uid are injected automatically in OTel resource attributes when OTel tracing/logs/metrics are enabled.

For that purpose, the following right has to be added to the Traefik Kubernetes RBACs:

  ...
  - apiGroups:
      - ""
    resources:
      - pods
    verbs:
      - get
  ...

From doc.traefik.io/traefik/migrate/v3/#observability

Full release notes for 3.5.0

Release notes from github.com/traefik/traefik/blob/master/CHANGELOG.md, and Migration: Steps needed between the versions, checked 17 hours ago. Only text the vendor marks as breaking, or puts in a warning/caution/important note, is shown; read the full notes for anything else. Traefik's release notes (CHANGELOG.md, GitHub releases) are lists of merged pull requests and mark nothing as breaking. What is quoted instead is Traefik's migration documentation on doc.traefik.io: “Migration: Steps needed between the versions” (v3), the same page of the v2.11 documentation (v2), and “Configuration Details for Migrating from Traefik v2 to v3” (on 3.0.0). Each section of those pages is labelled “Migration” and shown on the release its heading names (“v3.3 to v3.4” on 3.4.0). A section naming a canceled release (v2.4.10, v2.9.0) is shown on the next release of that line. Versions are covered from 2.0.0. No required stop is documented.