You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Docker部署Traefik后访问仪表盘持续出现404错误求助

Traefik v3.0 仪表盘404错误排查请求

我在Docker上部署了Traefik v3.0,已成功获取Let's Encrypt测试证书,其他功能正常,但访问traefik-dashboard.lab.mydomain.com时持续出现404页面未找到错误。使用Cloudflare域名,lab.mydomain.com是指向动态IP的CNAME,所有Docker容器均使用该子域名(带端口)访问。已尝试在域名后加端口访问,但问题依旧。以下是我的配置文件:

docker-compose.yml

version: "3.8"

services:
  traefik:
    image: traefik:v3.0
    container_name: traefik
    restart: unless-stopped
    security_opt:
      - no-new-privileges:true
    networks:
      - proxy
    ports:
      - 80:80
      - 443:443
      # - 443:443/tcp 
      # - 443:443/udp 
    environment:
      CF_DNS_API_TOKEN_FILE: /run/secrets/cf_api_token # note using _FILE for docker secrets
      # CF_DNS_API_TOKEN: ${CF_DNS_API_TOKEN} # if using .env
      TRAEFIK_DASHBOARD_CREDENTIALS: ${TRAEFIK_DASHBOARD_CREDENTIALS}
    secrets:
      - cf_api_token
    env_file: .env # use .env
    volumes:
      - /etc/localtime:/etc/localtime:ro
      - /var/run/docker.sock:/var/run/docker.sock:ro
      - ./data/traefik.yml:/traefik.yml:ro
      - ./data/acme.json:/acme.json
      # - ./data/config.yml:/config.yml:ro
    labels:
      - "traefik.enable=true"
      - "traefik.http.routers.traefik.entrypoints=http"
      - "traefik.http.routers.traefik.rule=Host(`traefik-dashboard.lab.mydomain.com`)"
      - "traefik.http.middlewares.traefik-auth.basicauth.users=${TRAEFIK_DASHBOARD_CREDENTIALS}"
      - "traefik.http.middlewares.traefik-https-redirect.redirectscheme.scheme=https"
      - "traefik.http.middlewares.sslheader.headers.customrequestheaders.X-Forwarded-Proto=https"
      - "traefik.http.routers.traefik.middlewares=traefik-https-redirect"
      - "traefik.http.routers.traefik-secure.entrypoints=https"
      - "traefik.http.routers.traefik-secure.rule=Host(`traefik-dashboard.lab.mydomain.com`)"
      - "traefik.http.routers.traefik-secure.middlewares=traefik-auth"
      - "traefik.http.routers.traefik-secure.tls=true"
      - "traefik.http.routers.traefik-secure.tls.certresolver=cloudflare"
      - "traefik.http.routers.traefik-secure.tls.domains[0].main=lab.mydomain.com"
      - "traefik.http.routers.traefik-secure.tls.domains[0].sans=*.lab.mydomain.com"
      - "traefik.http.routers.traefik-secure.service=api@internal"

secrets:
  cf_api_token:
    file: ./cf_api_token.txt

networks:
  proxy:
    external: true

traefik.yml

api:
  dashboard: true
  debug: true
entryPoints:
  http:
    address: ":80"
    http:
      redirections:
        entryPoint:
          to: https
          scheme: https
  https:
    address: ":443"
serversTransport:
  insecureSkipVerify: true
providers:
  docker:
    endpoint: "unix:///var/run/docker.sock"
    exposedByDefault: false
  # file:
  #   filename: /config.yml
certificatesResolvers:
  cloudflare:
    acme:
      email: mail@mydomain.com
      storage: acme.json
      # caServer: https://acme-v02.api.letsencrypt.org/directory # prod (default)
      caServer: https://acme-staging-v02.api.letsencrypt.org/directory # staging
      dnsChallenge:
        provider: cloudflare
        #disablePropagationCheck: true # uncomment this if you have issues pulling certificates through cloudflare, By setting this flag to true disables the need to wait for the propagation of the TXT record to all authoritative name servers.
        #delayBeforeCheck: 60s # uncomment along with disablePropagationCheck if needed to ensure the TXT record is ready before verification is attempted 
        resolvers:
          - "1.1.1.1:53"
          - "1.0.0.1:53"

排查与修复方案

1. 移除重复的HTTP重定向配置

traefik.yml中已经配置了全局HTTP到HTTPS的重定向,但docker-compose的Traefik容器标签里又重复定义了traefik-https-redirect中间件,这会导致路由规则冲突。

  • 操作:删除docker-compose中traefik.http.routers.traefik.middlewares=traefik-https-redirect这一行,保留全局重定向即可。

2. 验证API服务指向

确认traefik.http.routers.traefik-secure.service=api@internal拼写正确,Traefik v3.0中内置API服务名称未变更,大小写敏感,需确保完全匹配。

3. 检查Cloudflare配置

  • 确认traefik-dashboard.lab.mydomain.com的DNS记录解析正常,可通过nslookup traefik-dashboard.lab.mydomain.com验证。
  • 若Cloudflare开启了代理模式(Proxied),需确保Cloudflare未拦截443端口的请求,可暂时切换为DNS only测试是否恢复正常。
  • 动态IP的CNAME需确保指向的记录实时更新,避免IP过期导致解析错误。

4. 查看Traefik调试日志

利用已开启的debug模式,通过docker logs traefik查看日志,搜索traefik-dashboard相关的路由匹配记录,确认请求是否被正确路由到api@internal服务,排查是否有规则匹配失败的情况。

5. 清除浏览器缓存

如果之前尝试过加端口访问,浏览器可能缓存了旧的请求记录,需清除缓存后重新访问traefik-dashboard.lab.mydomain.com(无需加端口)。


内容的提问来源于stack exchange,提问作者Krystian Ignaczak

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.21 08:35:07