You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何让Traefik通过动态配置为多子域名使用通配符证书

问题描述

我们持有Siteground提供的通配符SSL证书,可覆盖以下子域名:

test.example.com
apis.example.com
dev.example.com
stg.example.com
...

已为test.example.com配置*.test.example.com的A记录,指向目标服务器,用于Traefik代理创建动态路由:

类型   名称                值
  A    *.test.example.com  xxx.xxx.xx.xx

当前动态路由、HTTP转HTTPS重定向及基础认证功能均正常,但whoami.test.example.com这类动态子域名的SSL无法正常工作——Traefik会生成/使用自签名证书,而非我们提供的通配符证书(该证书在静态子域名test.example.com上可正常生效)。由于域名服务商不在Traefik支持的自动证书签发服务商列表(如Cloudflare、GoDaddy等)中,需通过Traefik的动态文件配置,让*.test.example.com下所有动态子域名都使用该通配符证书。

现有配置文件

docker-compose.yml

version: "3.3"

services:
  traefik:
    image: "traefik:v2.6"
    command:
      - --entrypoints.web.address=:80
      - --entrypoints.websecure.address=:443
      - --providers.docker
      - --api
      - --providers.file.directory=/configuration/
      - --providers.file.watch=true

    ports:
      - "80:80"
      - "443:443"
    volumes:
      - "/var/run/docker.sock:/var/run/docker.sock:ro"
      - "/apps/test2/configuration/:/configuration/"
      - "/apps/test2/certs/:/etc/certs/"
    labels:
      # Dashboard
      - "traefik.http.routers.traefik.rule=Host(`traefik.test.example.com`)"
      - "traefik.http.routers.traefik.service=api@internal"
      - "traefik.http.routers.traefik.entrypoints=websecure"
      - "traefik.http.routers.traefik.middlewares=authtraefik"
      - "traefik.http.middlewares.authtraefik.basicauth.users=user:$$apr1$$q8eZFHjF$$Fvmkk//V6Btlaf2i/ju5n/" # user/password
      - "traefik.http.routers.traefik.tls.domains[0].main=test.example.com"
      - "traefik.http.routers.traefik.tls.domains[0].sans=*.test.example.com"
      
      # global redirect to https
      - "traefik.http.routers.http-catchall.rule=hostregexp(`{host:.+}`)"
      - "traefik.http.routers.http-catchall.entrypoints=web"
      - "traefik.http.routers.http-catchall.middlewares=redirect-to-https"

      # middleware redirect
      - "traefik.http.middlewares.redirect-to-https.redirectscheme.scheme=https"

  my-app:
    image: traefik/whoami:v1.7.1
    labels:
      - "traefik.http.routers.my-app.rule=Host(`whoami.test.example.com`)"
      - "traefik.http.routers.my-app.middlewares=auth"
      - "traefik.http.routers.my-app.entrypoints=websecure"
      - "traefik.http.routers.my-app.tls=true"
      - "traefik.http.middlewares.auth.basicauth.users=user:$$apr1$$q8eZFHjF$$Fvmkk//V6Btlaf2i/ju5n/" # user/password

configuration/config.yml(动态配置)

# Dynamic configuration
tls:
  stores:
    default:
      defaultCertificate:
        certFile: /etc/certs/cert.cert
        keyFile: /etc/certs/cert.key
解决方案

要让Traefik为*.test.example.com下所有动态子域名使用指定的通配符证书,需在动态配置文件中添加TLS证书解析规则,明确匹配该通配符域名并关联证书。

步骤1:修改动态配置文件

更新configuration/config.yml,添加证书加载和域名匹配规则:

# Dynamic configuration
tls:
  stores:
    default:
      defaultCertificate:
        certFile: /etc/certs/cert.cert
        keyFile: /etc/certs/cert.key
  # 加载通配符证书到默认存储
  certificates:
    - certFile: /etc/certs/cert.cert
      keyFile: /etc/certs/cert.key
      stores:
        - default
  # 指定证书覆盖的域名范围
  domains:
    - main: test.example.com
      sans:
        - "*.test.example.com"

步骤2:调整Docker服务路由的TLS配置

修改my-app服务的标签,将原tls=true替换为指定使用默认证书存储的配置,避免Traefik自动生成自签证书:

labels:
  - "traefik.http.routers.my-app.rule=Host(`whoami.test.example.com`)"
  - "traefik.http.routers.my-app.middlewares=auth"
  - "traefik.http.routers.my-app.entrypoints=websecure"
  # 指定使用默认证书存储中的证书
  - "traefik.http.routers.my-app.tls.store=default"
  - "traefik.http.middlewares.auth.basicauth.users=user:$$apr1$$q8eZFHjF$$Fvmkk//V6Btlaf2i/ju5n/" # user/password

配置说明

  1. tls.certificates:将通配符证书加载到Traefik的默认证书存储,确保Traefik能识别并调用该证书。
  2. tls.domains:明确证书覆盖的主域名和通配符子域名,让Traefik在匹配到这些域名时自动选用对应证书。
  3. tls.store=default:告诉路由使用默认存储中的证书,而非触发自动生成自签证书的逻辑。

修改完成后,Traefik会因开启--providers.file.watch=true自动重载配置,此时访问whoami.test.example.com即可使用指定的通配符证书。

内容的提问来源于stack exchange,提问作者devops-admin

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.15 04:16:06