Docker部署Traefik后访问仪表盘持续出现404错误求助
Traefik v3.0 仪表盘404错误排查请求
我在Docker上部署了Traefik v3.0,已成功获取Let's Encrypt测试证书,其他功能正常,但访问traefik-dashboard.lab.mydomain.com时持续出现404页面未找到错误。使用Cloudflare域名,lab.mydomain.com是指向动态IP的CNAME,所有Docker容器均使用该子域名(带端口)访问。已尝试在域名后加端口访问,但问题依旧。以下是我的配置文件:
docker-compose.yml
version: "3.8" services: traefik: image: traefik:v3.0 container_name: traefik restart: unless-stopped security_opt: - no-new-privileges:true networks: - proxy ports: - 80:80 - 443:443 # - 443:443/tcp # - 443:443/udp environment: CF_DNS_API_TOKEN_FILE: /run/secrets/cf_api_token # note using _FILE for docker secrets # CF_DNS_API_TOKEN: ${CF_DNS_API_TOKEN} # if using .env TRAEFIK_DASHBOARD_CREDENTIALS: ${TRAEFIK_DASHBOARD_CREDENTIALS} secrets: - cf_api_token env_file: .env # use .env volumes: - /etc/localtime:/etc/localtime:ro - /var/run/docker.sock:/var/run/docker.sock:ro - ./data/traefik.yml:/traefik.yml:ro - ./data/acme.json:/acme.json # - ./data/config.yml:/config.yml:ro labels: - "traefik.enable=true" - "traefik.http.routers.traefik.entrypoints=http" - "traefik.http.routers.traefik.rule=Host(`traefik-dashboard.lab.mydomain.com`)" - "traefik.http.middlewares.traefik-auth.basicauth.users=${TRAEFIK_DASHBOARD_CREDENTIALS}" - "traefik.http.middlewares.traefik-https-redirect.redirectscheme.scheme=https" - "traefik.http.middlewares.sslheader.headers.customrequestheaders.X-Forwarded-Proto=https" - "traefik.http.routers.traefik.middlewares=traefik-https-redirect" - "traefik.http.routers.traefik-secure.entrypoints=https" - "traefik.http.routers.traefik-secure.rule=Host(`traefik-dashboard.lab.mydomain.com`)" - "traefik.http.routers.traefik-secure.middlewares=traefik-auth" - "traefik.http.routers.traefik-secure.tls=true" - "traefik.http.routers.traefik-secure.tls.certresolver=cloudflare" - "traefik.http.routers.traefik-secure.tls.domains[0].main=lab.mydomain.com" - "traefik.http.routers.traefik-secure.tls.domains[0].sans=*.lab.mydomain.com" - "traefik.http.routers.traefik-secure.service=api@internal" secrets: cf_api_token: file: ./cf_api_token.txt networks: proxy: external: true
traefik.yml
api: dashboard: true debug: true entryPoints: http: address: ":80" http: redirections: entryPoint: to: https scheme: https https: address: ":443" serversTransport: insecureSkipVerify: true providers: docker: endpoint: "unix:///var/run/docker.sock" exposedByDefault: false # file: # filename: /config.yml certificatesResolvers: cloudflare: acme: email: mail@mydomain.com storage: acme.json # caServer: https://acme-v02.api.letsencrypt.org/directory # prod (default) caServer: https://acme-staging-v02.api.letsencrypt.org/directory # staging dnsChallenge: provider: cloudflare #disablePropagationCheck: true # uncomment this if you have issues pulling certificates through cloudflare, By setting this flag to true disables the need to wait for the propagation of the TXT record to all authoritative name servers. #delayBeforeCheck: 60s # uncomment along with disablePropagationCheck if needed to ensure the TXT record is ready before verification is attempted resolvers: - "1.1.1.1:53" - "1.0.0.1:53"
排查与修复方案
1. 移除重复的HTTP重定向配置
traefik.yml中已经配置了全局HTTP到HTTPS的重定向,但docker-compose的Traefik容器标签里又重复定义了traefik-https-redirect中间件,这会导致路由规则冲突。
- 操作:删除docker-compose中
traefik.http.routers.traefik.middlewares=traefik-https-redirect这一行,保留全局重定向即可。
2. 验证API服务指向
确认traefik.http.routers.traefik-secure.service=api@internal拼写正确,Traefik v3.0中内置API服务名称未变更,大小写敏感,需确保完全匹配。
3. 检查Cloudflare配置
- 确认
traefik-dashboard.lab.mydomain.com的DNS记录解析正常,可通过nslookup traefik-dashboard.lab.mydomain.com验证。 - 若Cloudflare开启了代理模式(Proxied),需确保Cloudflare未拦截443端口的请求,可暂时切换为DNS only测试是否恢复正常。
- 动态IP的CNAME需确保指向的记录实时更新,避免IP过期导致解析错误。
4. 查看Traefik调试日志
利用已开启的debug模式,通过docker logs traefik查看日志,搜索traefik-dashboard相关的路由匹配记录,确认请求是否被正确路由到api@internal服务,排查是否有规则匹配失败的情况。
5. 清除浏览器缓存
如果之前尝试过加端口访问,浏览器可能缓存了旧的请求记录,需清除缓存后重新访问traefik-dashboard.lab.mydomain.com(无需加端口)。
内容的提问来源于stack exchange,提问作者Krystian Ignaczak
相关产品推荐
相关产品推荐

