如何让Traefik通过动态配置为多子域名使用通配符证书
问题描述
我们持有Siteground提供的通配符SSL证书,可覆盖以下子域名:
test.example.com apis.example.com dev.example.com stg.example.com ...
已为test.example.com配置*.test.example.com的A记录,指向目标服务器,用于Traefik代理创建动态路由:
类型 名称 值 A *.test.example.com xxx.xxx.xx.xx
当前动态路由、HTTP转HTTPS重定向及基础认证功能均正常,但whoami.test.example.com这类动态子域名的SSL无法正常工作——Traefik会生成/使用自签名证书,而非我们提供的通配符证书(该证书在静态子域名test.example.com上可正常生效)。由于域名服务商不在Traefik支持的自动证书签发服务商列表(如Cloudflare、GoDaddy等)中,需通过Traefik的动态文件配置,让*.test.example.com下所有动态子域名都使用该通配符证书。
现有配置文件
docker-compose.yml
version: "3.3" services: traefik: image: "traefik:v2.6" command: - --entrypoints.web.address=:80 - --entrypoints.websecure.address=:443 - --providers.docker - --api - --providers.file.directory=/configuration/ - --providers.file.watch=true ports: - "80:80" - "443:443" volumes: - "/var/run/docker.sock:/var/run/docker.sock:ro" - "/apps/test2/configuration/:/configuration/" - "/apps/test2/certs/:/etc/certs/" labels: # Dashboard - "traefik.http.routers.traefik.rule=Host(`traefik.test.example.com`)" - "traefik.http.routers.traefik.service=api@internal" - "traefik.http.routers.traefik.entrypoints=websecure" - "traefik.http.routers.traefik.middlewares=authtraefik" - "traefik.http.middlewares.authtraefik.basicauth.users=user:$$apr1$$q8eZFHjF$$Fvmkk//V6Btlaf2i/ju5n/" # user/password - "traefik.http.routers.traefik.tls.domains[0].main=test.example.com" - "traefik.http.routers.traefik.tls.domains[0].sans=*.test.example.com" # global redirect to https - "traefik.http.routers.http-catchall.rule=hostregexp(`{host:.+}`)" - "traefik.http.routers.http-catchall.entrypoints=web" - "traefik.http.routers.http-catchall.middlewares=redirect-to-https" # middleware redirect - "traefik.http.middlewares.redirect-to-https.redirectscheme.scheme=https" my-app: image: traefik/whoami:v1.7.1 labels: - "traefik.http.routers.my-app.rule=Host(`whoami.test.example.com`)" - "traefik.http.routers.my-app.middlewares=auth" - "traefik.http.routers.my-app.entrypoints=websecure" - "traefik.http.routers.my-app.tls=true" - "traefik.http.middlewares.auth.basicauth.users=user:$$apr1$$q8eZFHjF$$Fvmkk//V6Btlaf2i/ju5n/" # user/password
configuration/config.yml(动态配置)
# Dynamic configuration tls: stores: default: defaultCertificate: certFile: /etc/certs/cert.cert keyFile: /etc/certs/cert.key
解决方案
要让Traefik为*.test.example.com下所有动态子域名使用指定的通配符证书,需在动态配置文件中添加TLS证书解析规则,明确匹配该通配符域名并关联证书。
步骤1:修改动态配置文件
更新configuration/config.yml,添加证书加载和域名匹配规则:
# Dynamic configuration tls: stores: default: defaultCertificate: certFile: /etc/certs/cert.cert keyFile: /etc/certs/cert.key # 加载通配符证书到默认存储 certificates: - certFile: /etc/certs/cert.cert keyFile: /etc/certs/cert.key stores: - default # 指定证书覆盖的域名范围 domains: - main: test.example.com sans: - "*.test.example.com"
步骤2:调整Docker服务路由的TLS配置
修改my-app服务的标签,将原tls=true替换为指定使用默认证书存储的配置,避免Traefik自动生成自签证书:
labels: - "traefik.http.routers.my-app.rule=Host(`whoami.test.example.com`)" - "traefik.http.routers.my-app.middlewares=auth" - "traefik.http.routers.my-app.entrypoints=websecure" # 指定使用默认证书存储中的证书 - "traefik.http.routers.my-app.tls.store=default" - "traefik.http.middlewares.auth.basicauth.users=user:$$apr1$$q8eZFHjF$$Fvmkk//V6Btlaf2i/ju5n/" # user/password
配置说明
tls.certificates:将通配符证书加载到Traefik的默认证书存储,确保Traefik能识别并调用该证书。tls.domains:明确证书覆盖的主域名和通配符子域名,让Traefik在匹配到这些域名时自动选用对应证书。tls.store=default:告诉路由使用默认存储中的证书,而非触发自动生成自签证书的逻辑。
修改完成后,Traefik会因开启--providers.file.watch=true自动重载配置,此时访问whoami.test.example.com即可使用指定的通配符证书。
内容的提问来源于stack exchange,提问作者devops-admin
相关产品推荐
相关产品推荐

