You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Traefik默认证书覆盖自定义LCN证书问题求助

Traefik 2.5 自定义SSL证书不生效排查

问题说明

使用Traefik 2.5版本,已在traefik.toml和docker-compose.yml中配置自定义SSL证书,DNS记录已正确指向服务器IP且解析正常,但SSL检测显示仍在使用Traefik默认证书,需排查原因。

相关配置文件

Traefik.toml

# Entry Points Configuration
[entryPoints]
  [entryPoints.web]
    address = ":80"
  [entryPoints.websecure]
    address = ":443"
    [entryPoints.websecure.http.tls]

# Providers Configuration
[providers]
  [providers.docker]
    endpoint = "unix:///var/run/docker.sock"
    exposedByDefault = false

# TLS Certificates Configuration
[tls]
  [[tls.certificates]]
    certFile = "/certs/certificate.crt"
    keyFile = "/certs/private.key"
    stores = ["default"]

# TLS Stores Configuration
[tls.stores]
  [tls.stores.default]
    [tls.stores.default.defaultCertificate]
      certFile = "/certs/certificate.crt"
      keyFile  = "/certs/private.key"

# TLS Options Configuration
[tls.options]
  [tls.options.default]
    minVersion = "VersionTLS12"
    maxVersion = "VersionTLS13"
    cipherSuites = [
      "TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256"
    ]
    curvePreferences = ["CurveP521", "CurveP384"]
    sniStrict = true

# API Configuration
[api]
  dashboard = true
  insecure = true

docker-compose.yml

version: '3.3'

services:
  traefik:
    image: traefik:v2.5
    command:
      - --configFile=/traefik.toml
    ports:
      - "80:80"
      - "443:443"
      - "8080:8080"
    volumes:
      - "/var/run/docker.sock:/var/run/docker.sock"
      - "/certs:/certs"
      - "./traefik.toml:/traefik.toml"
    labels:
      - "traefik.enable=true"
      - "traefik.http.routers.api.rule=Host(`example`)"
      - "traefik.http.routers.api.service=api@internal"
      - "traefik.http.routers.api.entrypoints=websecure"

  backend:
    build: ./backend
    labels:
      - "traefik.enable=true"
      - "traefik.http.routers.backend.rule=Host(`example`)"
      - "traefik.http.services.backend.loadbalancer.server.port=4000"
      - "traefik.http.routers.backend.entrypoints=websecure"
    env_file:
      - ./backend/.env
    volumes:
      - ./backend/upload/images:/app/backend/upload/images

  frontend:
    build: ./frontend
    labels:
      - "traefik.enable=true"
      - "traefik.http.routers.frontend.rule=Host(`example`, `example`)"
      - "traefik.http.services.frontend.loadbalancer.server.port=3000"
      - "traefik.http.routers.frontend.entrypoints=websecure"
    env_file:
      - ./frontend/.env

  admin:
    build: ./admin
    labels:
      - "traefik.enable=true"
      - "traefik.http.routers.admin.rule=Host(`example`)"
      - "traefik.http.services.admin.loadbalancer.server.port=5173"
      - "traefik.http.routers.admin.entrypoints=websecure"
    env_file:
      - ./admin/.env

已验证信息

root@ubuntu-s-2vcpu-4gb-amd-lon1-01:/home/root/example# docker exec -it $(docker ps -qf "name=example_traefik_1") sh -c 'ls -l /certs; cat /traefik.toml'
total 8
-rw-r--r--    1 root     root          2244 Jun 24 10:53 certificate.crt
-rw-------    1 root     root          1704 Jun 20 14:49 private.key
# Entry Points Configuration
[entryPoints]
  [entryPoints.web]
    address = ":80"
  [entryPoints.websecure]
    address = ":443"
    [entryPoints.websecure.http.tls]

# Providers Configuration
[providers]
  [providers.docker]
    endpoint = "unix:///var/run/docker.sock"
    exposedByDefault = false

# TLS Certificates Configuration
[tls]
  [[tls.certificates]]
    certFile = "/certs/certificate.crt"
    keyFile = "/certs/private.key"
    stores = ["default"]

# TLS Stores Configuration
[tls.stores]
  [tls.stores.default]
    [tls.stores.default.defaultCertificate]
      certFile = "/certs/certificate.crt"
      keyFile  = "/certs/private.key"

# TLS Options Configuration
[tls.options]
  [tls.options.default]
    minVersion = "VersionTLS12"
    maxVersion = "VersionTLS13"
    cipherSuites = [
      "TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256"
    ]
    curvePreferences = ["CurveP521", "CurveP384"]
    sniStrict = true

# API Configuration
[api]
  dashboard = true
  insecure = true

排查步骤

  • 验证证书域名覆盖范围:用命令openssl x509 -in /certs/certificate.crt -text -noout查看证书的Subject Alternative Names字段,确认所有路由规则中Host()指定的域名都包含在内。如果证书不匹配请求的域名,Traefik会自动使用默认证书。
  • 给路由显式启用TLS:当前所有路由的Docker标签里都缺少traefik.http.routers.xxx.tls=true配置,Traefik需要明确指定路由使用TLS才能加载自定义证书。比如给api路由添加标签:- "traefik.http.routers.api.tls=true",其他路由同理。
  • 确认证书与密钥配对:执行以下两个命令对比输出,确保结果一致:
    openssl x509 -noout -modulus -in /certs/certificate.crt | openssl md5
    openssl rsa -noout -modulus -in /certs/private.key | openssl md5
    
    如果输出不同,说明证书和密钥不匹配,Traefik无法加载自定义证书。
  • 检查Traefik启动日志:运行docker logs example_traefik_1查看日志,查找证书加载相关的错误信息,比如证书格式错误、权限不足等,日志会直接指出问题根源。
  • 确认默认证书配置有效性:虽然配置了tls.stores.default.defaultCertificate,但如果证书加载失败或者路由未关联到默认store,Traefik会 fallback 到内置默认证书。同时确保[entryPoints.websecure.http.tls]配置没有干扰证书的加载逻辑。

内容的提问来源于stack exchange,提问作者Nugget

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.21 23:44:54