Distinguish between HTTP error code generated by Traefik itself or by service

Viewed 392

We are using Traefik v2.4.7 on Docker Swarm provider. We are also using custom error middleware which routes the request to nginx server (error-pages@docker service). We have the following code in traefik.yml:

http:
  middlewares:
    error-pages:
      errors:
        status:
          - "400-599"
        service: error-pages@docker
        query: "/{status}.html"

entrypoints:
  web-secure:
    address: ":443"
    http:
      middlewares:
        - error-pages@file

Our application, which is deployed behind Traefik, has some IPs whitelisted with ipwhitelist.sourcerange=... label. If it is accessed from an IP which is not allowed, error-pages middleware routes the request to /403.html in nginx service. This is expected behavior.

However, we have some cases where our application purposely returns 403 HTTP status code and displays its own "forbidden" page with support contact form, debug information and other useful info. We don't want Traefik middleware to route the request to nginx.

Is it possible to distinguish between HTTP error codes generated by Traefik and services themselves? If the error code is generated by Traefik, then it should go through error-pages middleware. If the error code is generated by service, the page should be returned as-is, without going through middleware. How can we achieve this?

1 Answers

Hmm I don't think that is possible (using the built in errorpages middleware) ...

  1. The only solution I can think of is to have the client application send back a 200 (Status Code) to every request but show the 403 (Html) page.
  2. Use a custom plugin (middleware) eg. https://github.com/pierre-verhaeghe/traefik-replace-response-code to change the status code eg return 493 from your application and change it to 403 before it goes to the client.

Both solutions don't look good to me as the application behavior needs to be changed ... but maybe its good enough for your needs.

Related