Traefik配置自签名证书后HTTPS访问出现404问题排查
Traefik HTTPS Dashboard 404问题排查与修复
你的配置存在几个关键问题,导致HTTPS访问Dashboard返回404、重定向失效,以下是具体问题和修正方案:
1. 关闭API insecure模式
静态配置traefik.yml中的api.insecure: true会直接在8080端口暴露Dashboard,完全绕过你定义的Traefik路由规则,这就导致动态配置里的HTTPS路由根本无法匹配到Dashboard服务,自然返回404。
修正后的traefik.yml(静态配置):
api: dashboard: true insecure: false # 改为false,让Dashboard走Traefik路由系统 accessLog: true entryPoints: http: address: ":80" http: redirections: entrypoint: to: https scheme: https https: address: ":443" providers: docker: endpoint: "unix:///var/run/docker.sock" exposedByDefault: false file: fileName: /dynamic-conf/traefik-dynamic.yml
2. 给Dashboard路由启用TLS
动态配置里的Dashboard路由器未声明处理TLS流量,即便加载了证书,Traefik也不会将HTTPS请求转发到该路由,导致匹配失败。需在路由器配置中添加tls: true。
同时你配置了entrypoint级别的HTTP转HTTPS重定向,又添加了中间件重定向,两者重复会引发冲突,建议保留entrypoint重定向(效率更高),移除中间件引用。
修正后的traefik-dynamic.yml(动态配置):
http: routers: dashboard: entryPoints: - http - https service: api@internal rule: "Host(`localhost`)" tls: true # 启用TLS,让该路由处理HTTPS请求 # 移除重复的重定向中间件,使用entrypoint级重定向即可 tls: certificates: - certFile: /opt/certs/cert.crt keyFile: /opt/certs/cert.key
3. 验证步骤
- 停止并重启Traefik容器:
docker-compose down && docker-compose up -d - 访问
http://localhost,会自动重定向到https://localhost - 此时HTTPS访问Dashboard可正常加载,证书也能被浏览器正确识别
内容的提问来源于stack exchange,提问作者Krst0
相关产品推荐
相关产品推荐

