{"id":527,"date":"2026-10-05T08:40:00","date_gmt":"2026-10-05T06:40:00","guid":{"rendered":"https:\/\/www.lukaswojcik.com\/?page_id=527"},"modified":"2026-09-25T10:49:12","modified_gmt":"2026-09-25T08:49:12","slug":"autonomous-docker-compose-home-server-with-traefik-ssl-and-watchtower","status":"publish","type":"post","link":"https:\/\/www.lukaswojcik.com\/blog\/en\/raspberry-pi\/tutorials-en-raspberry-pi\/autonomous-docker-compose-home-server-with-traefik-ssl-and-watchtower\/","title":{"rendered":"Autonomous Docker-Compose Home Server with Traefik, SSL, and Watchtower"},"content":{"rendered":"<h2>Architectural Overview: Autonomous Home Server Design on Raspberry Pi<\/h2>\n<p>Deploying a self-hosted home laboratory on a Raspberry Pi requires a resilient, low-maintenance orchestration architecture. Exposing internal Docker containers to local or public networks without centralized SSL\/TLS termination introduces administrative complexity and severe security vulnerabilities. Manual certificate renewals, static reverse proxy configurations, and manual container updates inevitably lead to downtime and expired cryptographic certificates.<\/p>\n<p>An autonomous home server architecture combines three core technologies within a single declarative Docker Compose stack: <strong>Traefik v3<\/strong> acts as a dynamic edge router that monitors the Docker socket and routes incoming HTTP\/HTTPS requests based on container labels. <strong>Let&#8217;s Encrypt ACME<\/strong> integration automates SSL certificate generation and renewal via HTTP-01 or DNS-01 challenges; and <strong>Watchtower<\/strong> provides automated lifecycle management by periodically checking container registries and gracefully rolling over outdated container images without manual intervention.<\/p>\n<figure class=\"lw-diagram\">\n<img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.lukaswojcik.com\/blog\/wp-content\/uploads\/diagrams\/traefik-docker-home-server-en.png\" width=\"1120\" height=\"560\" alt=\"Request path from the internet through the Traefik edge router to containers on the proxy network, with Let&apos;s Encrypt and Watchtower\"><figcaption>Request path of the home server: Traefik terminates TLS on port 443, renews the Let&#8217;s Encrypt certificate itself and finds its routing targets purely through Docker labels. Watchtower keeps the images current in the background.<\/figcaption><\/figure>\n<h2>Step-by-Step Implementation Guide<\/h2>\n<h3>Step 1: System Preparation and File Hierarchy Architecture<\/h3>\n<p>To ensure persistent data storage and clean separation of concerns on the Raspberry Pi host, a standardized filesystem directory tree must be established under <code>\/opt\/containers\/<\/code>:<\/p>\n<pre><code>mkdir -p \/opt\/containers\/traefik\/data\nmkdir -p \/opt\/containers\/watchtower\ntouch \/opt\/containers\/traefik\/data\/acme.json\nchmod 600 \/opt\/containers\/traefik\/data\/acme.json<\/code><\/pre>\n<p><em>Critical Security Note:<\/em> The <code>acme.json<\/code> file storing private Let&#8217;s Encrypt cryptographic keys must be restricted to file permissions <code>600<\/code>. Traefik will refuse to start if read\/write permissions are excessively permissive.<\/p>\n<h3>Step 2: Designing the Traefik v3 Dynamic Edge Router Stack<\/h3>\n<p>The routing infrastructure is defined within a root <code>docker-compose.yml<\/code> file located in <code>\/opt\/containers\/traefik\/<\/code>. This configuration specifies entrypoints for port 80 (HTTP) with mandatory redirects to port 443 (HTTPS), enables automated Let&#8217;s Encrypt HTTP-01 challenges, and mounts the Docker Unix socket read-only:<\/p>\n<pre><code>services:\n  traefik:\n    image: traefik:v3.1\n    container_name: traefik\n    restart: unless-stopped\n    security_opt:\n      - no-new-privileges:true\n    networks:\n      - proxy\n    ports:\n      - \"80:80\"\n      - \"443:443\"\n    command:\n      - \"--api.dashboard=true\"\n      - \"--providers.docker=true\"\n      - \"--providers.docker.exposedbydefault=false\"\n      - \"--providers.docker.network=proxy\"\n      - \"--entrypoints.web.address=:80\"\n      - \"--entrypoints.web.http.redirections.entryPoint.to=websecure\"\n      - \"--entrypoints.web.http.redirections.entryPoint.scheme=https\"\n      - \"--entrypoints.websecure.address=:443\"\n      - \"--certificatesresolvers.myresolver.acme.httpchallenge=true\"\n      - \"--certificatesresolvers.myresolver.acme.httpchallenge.entrypoint=web\"\n      - \"--certificatesresolvers.myresolver.acme.email=admin@lukaswojcik.com\"\n      - \"--certificatesresolvers.myresolver.acme.storage=\/data\/acme.json\"\n    volumes:\n      - \"\/var\/run\/docker.sock:\/var\/run\/docker.sock:ro\"\n      - \"\/opt\/containers\/traefik\/data:\/data\"\n    labels:\n      - \"traefik.enable=true\"\n      - \"traefik.http.routers.dashboard.rule=Host(`proxy.lukaswojcik.com`)\"\n      - \"traefik.http.routers.dashboard.service=api@internal\"\n      - \"traefik.http.routers.dashboard.entrypoints=websecure\"\n      - \"traefik.http.routers.dashboard.tls.certresolver=myresolver\"\n      - \"traefik.http.routers.dashboard.middlewares=dashboard-ip\"\n      - \"traefik.http.middlewares.dashboard-ip.ipallowlist.sourcerange=192.168.0.0\/16, 10.0.0.0\/8\"\n\nnetworks:\n  proxy:\n    external: true<\/code><\/pre>\n<h3>Step 3: Creating the External Proxy Docker Network<\/h3>\n<p>Before executing the compose stack, an isolated bridge network must be initialized on the host system to allow Traefik to communicate securely with downstream application containers:<\/p>\n<pre><code>docker network create proxy<\/code><\/pre>\n<h3>Step 4: Integrating Watchtower for Automated Lifecycle Management<\/h3>\n<p>To eliminate manual container update maintenance, Watchtower is added as an autonomous background service. Since the original <code>containrrr\/watchtower<\/code> repository was archived on 17 December 2025 and receives no further fixes or security updates, the actively maintained fork <code>nickfedor\/watchtower<\/code> is used here as a drop-in replacement. It checks configured registries every 24 hours (86400 seconds), pulls updated images matching current tags, gracefully terminates old container instances, and removes orphaned images automatically:<\/p>\n<pre><code>services:\n  watchtower:\n    image: nickfedor\/watchtower:latest\n    container_name: watchtower\n    restart: unless-stopped\n    volumes:\n      - \"\/var\/run\/docker.sock:\/var\/run\/docker.sock\"\n    environment:\n      - WATCHTOWER_CLEANUP=true\n      - WATCHTOWER_POLL_INTERVAL=86400\n      - WATCHTOWER_INCLUDE_RESTARTING=true\n      - WATCHTOWER_ROLLING_RESTART=true<\/code><\/pre>\n<h3>Step 5: Deploying a Secure Downstream Microservice via Labels<\/h3>\n<p>To attach any self-hosted application to the Traefik edge router without modifying central proxy files, dynamic Traefik routing labels are declared directly within the target service&#8217;s compose definition:<\/p>\n<pre><code>services:\n  whoami:\n    image: traefik\/whoami:latest\n    container_name: whoami\n    restart: unless-stopped\n    networks:\n      - proxy\n    labels:\n      - \"traefik.enable=true\"\n      - \"traefik.http.routers.whoami.rule=Host(`whoami.lukaswojcik.com`)\"\n      - \"traefik.http.routers.whoami.entrypoints=websecure\"\n      - \"traefik.http.routers.whoami.tls.certresolver=myresolver\"\n      - \"traefik.http.services.whoami.loadbalancer.server.port=80\"\n\nnetworks:\n  proxy:\n    external: true<\/code><\/pre>\n<h3>Step 6: Quality Assurance and System Auditing<\/h3>\n<p>After bringing up the services with <code>docker compose up -d<\/code>, the infrastructure must be systematically verified:<\/p>\n<ol>\n<li><strong>Certificate Issuance Verification:<\/strong> Inspect container log output via <code>docker logs -f traefik<\/code> to confirm successful Let&#8217;s Encrypt ACME challenges and verify that <code>acme.json<\/code> is populated with valid RSA\/ECDSA certificates.<\/li>\n<li><strong>Automated Redirection Audit:<\/strong> Execute a plain HTTP cURL query against the domain (<code>curl -I http:\/\/whoami.lukaswojcik.com<\/code>) to confirm an immediate <code>308 Permanent Redirect<\/code> or <code>301 Moved Permanently<\/code> header pointing to HTTPS.<\/li>\n<li><strong>Update Trigger Simulation:<\/strong> Execute a single non-invasive Watchtower check via <code>docker exec -it watchtower \/watchtower --run-once --monitor-only<\/code> to verify that access permissions to the Docker socket are functioning correctly. The flag <code>--no-pull<\/code> is no substitute here: it only suppresses registry pulls, while a newer image already present locally still causes the container to be stopped and recreated.<\/li>\n<\/ol>\n<h2>Summary and Measurable Added Value<\/h2>\n<p><strong>What is achieved:<\/strong> Replacement of manual reverse proxy routing, fragile SSL script cron jobs, and manual container updates with an autonomous, declarative Docker Compose infrastructure powered by Traefik v3 and Watchtower.<\/p>\n<p><strong>Resulting added value:<\/strong><\/p>\n<ul>\n<li><strong>Zero-Touch SSL\/TLS Maintenance:<\/strong> Cryptographic certificates are requested, provisioned, and renewed automatically by Let&#8217;s Encrypt, preventing browser certificate warnings and service outages.<\/li>\n<li><strong>Dynamic Service Discovery:<\/strong> New home server applications are routed and encrypted instantly by appending Docker labels, eliminating manual Nginx\/Apache configuration file edits and server reloads.<\/li>\n<li><strong>Continuous Automated Patching:<\/strong> Security patches and application updates are automatically applied within 24 hours of upstream registry releases, hardening the Raspberry Pi against known vulnerabilities. This guarantee only holds as long as the update tool itself is maintained, which is why the actively developed fork <code>nickfedor\/watchtower<\/code> takes the place of the archived original.<\/li>\n<\/ul>\n<div class=\"lw-faq\">\n<h2>Questions and answers<\/h2>\n<h3>Does the :ro on the Docker socket make Traefik&#8217;s access harmless?<\/h3>\n<p>No. The :ro only prevents the container from modifying the socket file itself. Through the socket, however, Traefik talks to the Docker API, and the API does not distinguish between read and write calls just because the file is mounted read-only. Whoever reaches the socket can start containers through it, including ones with the host&#8217;s root directory mounted, and thereby effectively holds root privileges on the Raspberry Pi.<\/p>\n<p>The risk therefore lies in Traefik&#8217;s attack surface: it is the only service that accepts connections directly from the internet. A vulnerability in Traefik would not stop at the container. Watchtower needs write access to the socket anyway in order to replace containers, but it accepts no connections from outside.<\/p>\n<p>A socket proxy mitigates this: a small container that holds the socket and forwards only the read-only API endpoints Traefik needs for container discovery. Traefik then receives the network address of this proxy instead of the socket, and the Docker provider can be pointed at it through its endpoint parameter.<\/p>\n<h3>Which updates does Watchtower install, and how can jumps to a new major version be avoided?<\/h3>\n<p>Watchtower follows the tag an image is listed with, not a version number. A container on latest therefore also receives the jump to a new major version as soon as one is published under latest, including changed configuration or data formats. There is no way back built in: after cleanup with WATCHTOWER_CLEANUP=true, the old image is not even left on disk.<\/p>\n<p>The setup in the article already shows the countermeasure: Traefik is pinned to traefik:v3.1 and so only receives new images under that tag, meaning fixes within 3.1 but no jump to another version. The same is worthwhile for every service that keeps its own data, such as a database. For the services on latest, whoami and Watchtower itself in the article, the risk is lower because they hold no data.<\/p>\n<h3>Is the Traefik dashboard at proxy.lukaswojcik.com protected?<\/h3>\n<p>Yes, limited to the home network: besides TLS, the dashboard router has the dashboard-ip middleware, an IP allow list (ipAllowList) that only lets through addresses from 192.168.0.0\/16 and 10.0.0.0\/8. Without it, anyone who knows the hostname could see every router, service and hostname of the home server. If the dashboard should also be reachable from outside, a basic auth middleware is added.<\/p>\n<h3>Does the HTTP-01 challenge work on every home internet connection?<\/h3>\n<p>Only if Let&#8217;s Encrypt can reach the Raspberry Pi from the internet on port 80: the hostname has to point publicly to the connection, and the router has to forward port 80 to the Pi. On connections without a public IPv4 address of their own, behind carrier-grade NAT or DS-Lite for example, this fails over IPv4; it then only works if the hostname has an AAAA record and the Pi is reachable over IPv6. The same limitation applies to services meant to be reachable only on the home network.<\/p>\n<p>The DNS-01 challenge mentioned in the article is intended for these cases. It proves control over the domain with a TXT record in DNS, needs no open port and also allows wildcard certificates. In return, Traefik needs credentials for the DNS provider&#8217;s API, and those credentials then deserve the same protection as acme.json.<\/p>\n<\/div>\n<div class=\"lw-quellen\">\n<h2>Sources<\/h2>\n<ul>\n<li><a href=\"https:\/\/docs.docker.com\/compose\/\" target=\"_blank\" rel=\"noopener noreferrer\">Docker Compose documentation<\/a><\/li>\n<li><a href=\"https:\/\/doc.traefik.io\/traefik\/\" target=\"_blank\" rel=\"noopener noreferrer\">Traefik documentation<\/a><\/li>\n<li><a href=\"https:\/\/letsencrypt.org\/docs\/\" target=\"_blank\" rel=\"noopener noreferrer\">Let&#8217;s Encrypt documentation<\/a><\/li>\n<\/ul>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Technical tutorial on deploying a fully automated, self-hosted Raspberry Pi home laboratory with Traefik v3 reverse proxy, zero-touch SSL, and Watchtower image automation.<\/p>\n","protected":false},"author":1,"featured_media":14079,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[92630],"tags":[91106,91145,91113,91181,91237,91219],"class_list":["post-527","post","type-post","status-publish","format-standard","hentry","category-tutorials-en-raspberry-pi","tag-automation","tag-docker","tag-homelab","tag-raspberry-pi","tag-self-hosting","tag-tutorial"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Autonomous Docker-Compose Home Server with Traefik, SSL, and Watchtower | Lukas Wojcik<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.lukaswojcik.com\/blog\/en\/raspberry-pi\/tutorials-en-raspberry-pi\/autonomous-docker-compose-home-server-with-traefik-ssl-and-watchtower\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Autonomous Docker-Compose Home Server with Traefik, SSL, and Watchtower | Lukas Wojcik\" \/>\n<meta property=\"og:description\" content=\"Technical tutorial on deploying a fully automated, self-hosted Raspberry Pi home laboratory with Traefik v3 reverse proxy, zero-touch SSL, and Watchtower image automation.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.lukaswojcik.com\/blog\/en\/raspberry-pi\/tutorials-en-raspberry-pi\/autonomous-docker-compose-home-server-with-traefik-ssl-and-watchtower\/\" \/>\n<meta property=\"og:site_name\" content=\"Lukas Wojcik - Blog\" \/>\n<meta property=\"article:published_time\" content=\"2026-10-05T06:40:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.lukaswojcik.com\/blog\/wp-content\/uploads\/2026\/09\/hero-527-autonomous-docker-compose-home-serve-g.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"630\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Lukas Wojcik\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Lukas Wojcik\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/raspberry-pi\\\/tutorials-en-raspberry-pi\\\/autonomous-docker-compose-home-server-with-traefik-ssl-and-watchtower\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/raspberry-pi\\\/tutorials-en-raspberry-pi\\\/autonomous-docker-compose-home-server-with-traefik-ssl-and-watchtower\\\/\"},\"author\":{\"name\":\"Lukas Wojcik\",\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/#\\\/schema\\\/person\\\/895f7604f9b6b71aad9bba33af28d0f9\"},\"headline\":\"Autonomous Docker-Compose Home Server with Traefik, SSL, and Watchtower\",\"datePublished\":\"2026-10-05T06:40:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/raspberry-pi\\\/tutorials-en-raspberry-pi\\\/autonomous-docker-compose-home-server-with-traefik-ssl-and-watchtower\\\/\"},\"wordCount\":1255,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/#\\\/schema\\\/person\\\/895f7604f9b6b71aad9bba33af28d0f9\"},\"image\":{\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/raspberry-pi\\\/tutorials-en-raspberry-pi\\\/autonomous-docker-compose-home-server-with-traefik-ssl-and-watchtower\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/hero-527-autonomous-docker-compose-home-serve-g.png\",\"keywords\":[\"Automation\",\"Docker\",\"Homelab\",\"Raspberry Pi\",\"Self-Hosting\",\"Tutorial\"],\"articleSection\":[\"Tutorials\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/raspberry-pi\\\/tutorials-en-raspberry-pi\\\/autonomous-docker-compose-home-server-with-traefik-ssl-and-watchtower\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/raspberry-pi\\\/tutorials-en-raspberry-pi\\\/autonomous-docker-compose-home-server-with-traefik-ssl-and-watchtower\\\/\",\"url\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/raspberry-pi\\\/tutorials-en-raspberry-pi\\\/autonomous-docker-compose-home-server-with-traefik-ssl-and-watchtower\\\/\",\"name\":\"Autonomous Docker-Compose Home Server with Traefik, SSL, and Watchtower | Lukas Wojcik\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/raspberry-pi\\\/tutorials-en-raspberry-pi\\\/autonomous-docker-compose-home-server-with-traefik-ssl-and-watchtower\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/raspberry-pi\\\/tutorials-en-raspberry-pi\\\/autonomous-docker-compose-home-server-with-traefik-ssl-and-watchtower\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/hero-527-autonomous-docker-compose-home-serve-g.png\",\"datePublished\":\"2026-10-05T06:40:00+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/raspberry-pi\\\/tutorials-en-raspberry-pi\\\/autonomous-docker-compose-home-server-with-traefik-ssl-and-watchtower\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/raspberry-pi\\\/tutorials-en-raspberry-pi\\\/autonomous-docker-compose-home-server-with-traefik-ssl-and-watchtower\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/raspberry-pi\\\/tutorials-en-raspberry-pi\\\/autonomous-docker-compose-home-server-with-traefik-ssl-and-watchtower\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/hero-527-autonomous-docker-compose-home-serve-g.png\",\"contentUrl\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/hero-527-autonomous-docker-compose-home-serve-g.png\",\"width\":1200,\"height\":630,\"caption\":\"Autonomous Docker-Compose Home Server with Traefik, SSL, and Watchtower\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/raspberry-pi\\\/tutorials-en-raspberry-pi\\\/autonomous-docker-compose-home-server-with-traefik-ssl-and-watchtower\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Autonomous Docker-Compose Home Server with Traefik, SSL, and Watchtower\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/\",\"name\":\"Lukas Wojcik - Blog\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/#\\\/schema\\\/person\\\/895f7604f9b6b71aad9bba33af28d0f9\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":[\"Person\",\"Organization\"],\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/#\\\/schema\\\/person\\\/895f7604f9b6b71aad9bba33af28d0f9\",\"name\":\"Lukas Wojcik\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/lw-x2.jpg\",\"url\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/lw-x2.jpg\",\"contentUrl\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/lw-x2.jpg\",\"width\":424,\"height\":636,\"caption\":\"Lukas Wojcik\"},\"logo\":{\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/lw-x2.jpg\"},\"sameAs\":[\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Autonomous Docker-Compose Home Server with Traefik, SSL, and Watchtower | Lukas Wojcik","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.lukaswojcik.com\/blog\/en\/raspberry-pi\/tutorials-en-raspberry-pi\/autonomous-docker-compose-home-server-with-traefik-ssl-and-watchtower\/","og_locale":"en_US","og_type":"article","og_title":"Autonomous Docker-Compose Home Server with Traefik, SSL, and Watchtower | Lukas Wojcik","og_description":"Technical tutorial on deploying a fully automated, self-hosted Raspberry Pi home laboratory with Traefik v3 reverse proxy, zero-touch SSL, and Watchtower image automation.","og_url":"https:\/\/www.lukaswojcik.com\/blog\/en\/raspberry-pi\/tutorials-en-raspberry-pi\/autonomous-docker-compose-home-server-with-traefik-ssl-and-watchtower\/","og_site_name":"Lukas Wojcik - Blog","article_published_time":"2026-10-05T06:40:00+00:00","og_image":[{"width":1200,"height":630,"url":"https:\/\/www.lukaswojcik.com\/blog\/wp-content\/uploads\/2026\/09\/hero-527-autonomous-docker-compose-home-serve-g.png","type":"image\/png"}],"author":"Lukas Wojcik","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Lukas Wojcik","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.lukaswojcik.com\/blog\/en\/raspberry-pi\/tutorials-en-raspberry-pi\/autonomous-docker-compose-home-server-with-traefik-ssl-and-watchtower\/#article","isPartOf":{"@id":"https:\/\/www.lukaswojcik.com\/blog\/en\/raspberry-pi\/tutorials-en-raspberry-pi\/autonomous-docker-compose-home-server-with-traefik-ssl-and-watchtower\/"},"author":{"name":"Lukas Wojcik","@id":"https:\/\/www.lukaswojcik.com\/blog\/#\/schema\/person\/895f7604f9b6b71aad9bba33af28d0f9"},"headline":"Autonomous Docker-Compose Home Server with Traefik, SSL, and Watchtower","datePublished":"2026-10-05T06:40:00+00:00","mainEntityOfPage":{"@id":"https:\/\/www.lukaswojcik.com\/blog\/en\/raspberry-pi\/tutorials-en-raspberry-pi\/autonomous-docker-compose-home-server-with-traefik-ssl-and-watchtower\/"},"wordCount":1255,"commentCount":0,"publisher":{"@id":"https:\/\/www.lukaswojcik.com\/blog\/#\/schema\/person\/895f7604f9b6b71aad9bba33af28d0f9"},"image":{"@id":"https:\/\/www.lukaswojcik.com\/blog\/en\/raspberry-pi\/tutorials-en-raspberry-pi\/autonomous-docker-compose-home-server-with-traefik-ssl-and-watchtower\/#primaryimage"},"thumbnailUrl":"https:\/\/www.lukaswojcik.com\/blog\/wp-content\/uploads\/2026\/09\/hero-527-autonomous-docker-compose-home-serve-g.png","keywords":["Automation","Docker","Homelab","Raspberry Pi","Self-Hosting","Tutorial"],"articleSection":["Tutorials"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.lukaswojcik.com\/blog\/en\/raspberry-pi\/tutorials-en-raspberry-pi\/autonomous-docker-compose-home-server-with-traefik-ssl-and-watchtower\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.lukaswojcik.com\/blog\/en\/raspberry-pi\/tutorials-en-raspberry-pi\/autonomous-docker-compose-home-server-with-traefik-ssl-and-watchtower\/","url":"https:\/\/www.lukaswojcik.com\/blog\/en\/raspberry-pi\/tutorials-en-raspberry-pi\/autonomous-docker-compose-home-server-with-traefik-ssl-and-watchtower\/","name":"Autonomous Docker-Compose Home Server with Traefik, SSL, and Watchtower | Lukas Wojcik","isPartOf":{"@id":"https:\/\/www.lukaswojcik.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.lukaswojcik.com\/blog\/en\/raspberry-pi\/tutorials-en-raspberry-pi\/autonomous-docker-compose-home-server-with-traefik-ssl-and-watchtower\/#primaryimage"},"image":{"@id":"https:\/\/www.lukaswojcik.com\/blog\/en\/raspberry-pi\/tutorials-en-raspberry-pi\/autonomous-docker-compose-home-server-with-traefik-ssl-and-watchtower\/#primaryimage"},"thumbnailUrl":"https:\/\/www.lukaswojcik.com\/blog\/wp-content\/uploads\/2026\/09\/hero-527-autonomous-docker-compose-home-serve-g.png","datePublished":"2026-10-05T06:40:00+00:00","breadcrumb":{"@id":"https:\/\/www.lukaswojcik.com\/blog\/en\/raspberry-pi\/tutorials-en-raspberry-pi\/autonomous-docker-compose-home-server-with-traefik-ssl-and-watchtower\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.lukaswojcik.com\/blog\/en\/raspberry-pi\/tutorials-en-raspberry-pi\/autonomous-docker-compose-home-server-with-traefik-ssl-and-watchtower\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.lukaswojcik.com\/blog\/en\/raspberry-pi\/tutorials-en-raspberry-pi\/autonomous-docker-compose-home-server-with-traefik-ssl-and-watchtower\/#primaryimage","url":"https:\/\/www.lukaswojcik.com\/blog\/wp-content\/uploads\/2026\/09\/hero-527-autonomous-docker-compose-home-serve-g.png","contentUrl":"https:\/\/www.lukaswojcik.com\/blog\/wp-content\/uploads\/2026\/09\/hero-527-autonomous-docker-compose-home-serve-g.png","width":1200,"height":630,"caption":"Autonomous Docker-Compose Home Server with Traefik, SSL, and Watchtower"},{"@type":"BreadcrumbList","@id":"https:\/\/www.lukaswojcik.com\/blog\/en\/raspberry-pi\/tutorials-en-raspberry-pi\/autonomous-docker-compose-home-server-with-traefik-ssl-and-watchtower\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.lukaswojcik.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Autonomous Docker-Compose Home Server with Traefik, SSL, and Watchtower"}]},{"@type":"WebSite","@id":"https:\/\/www.lukaswojcik.com\/blog\/#website","url":"https:\/\/www.lukaswojcik.com\/blog\/","name":"Lukas Wojcik - Blog","description":"","publisher":{"@id":"https:\/\/www.lukaswojcik.com\/blog\/#\/schema\/person\/895f7604f9b6b71aad9bba33af28d0f9"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.lukaswojcik.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":["Person","Organization"],"@id":"https:\/\/www.lukaswojcik.com\/blog\/#\/schema\/person\/895f7604f9b6b71aad9bba33af28d0f9","name":"Lukas Wojcik","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.lukaswojcik.com\/blog\/wp-content\/uploads\/2026\/07\/lw-x2.jpg","url":"https:\/\/www.lukaswojcik.com\/blog\/wp-content\/uploads\/2026\/07\/lw-x2.jpg","contentUrl":"https:\/\/www.lukaswojcik.com\/blog\/wp-content\/uploads\/2026\/07\/lw-x2.jpg","width":424,"height":636,"caption":"Lukas Wojcik"},"logo":{"@id":"https:\/\/www.lukaswojcik.com\/blog\/wp-content\/uploads\/2026\/07\/lw-x2.jpg"},"sameAs":["https:\/\/www.lukaswojcik.com\/blog"]}]}},"_links":{"self":[{"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/posts\/527","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/comments?post=527"}],"version-history":[{"count":6,"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/posts\/527\/revisions"}],"predecessor-version":[{"id":21078,"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/posts\/527\/revisions\/21078"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/media\/14079"}],"wp:attachment":[{"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/media?parent=527"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/categories?post=527"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/tags?post=527"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}