You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Docker Traefik配置SSL后首个服务出现404页面未找到错误

Traefik启用SSL后首个服务404问题解决

问题场景

用Traefik代理两个Node.js应用,未启用SSL时两个服务均可正常访问;开启SSL后,first.ibhaskar.com返回404错误,second.ibhaskar.com及Traefik仪表盘dash.ibhaskar.com可正常通过HTTPS访问,且两个应用本地测试无异常。

相关配置文件

Traefik配置文件(docker.traefik.yml)

services:
  traefik:
    image: traefik:latest
    ports:
      - 80:80
      - 443:443
    restart: always
    labels:
      - traefik.enable=true
      - traefik.http.services.traefik-dashboard.loadbalancer.server.port=8080
      ## configure http
      - traefik.http.routers.traefik-dashboard-http.entrypoints=http
      - traefik.http.routers.traefik-dashboard-http.rule=Host(`dash.ibhaskar.com`)
      ## configure https
      - traefik.http.routers.traefik-dashboard-https.entrypoints=https
      - traefik.http.routers.traefik-dashboard-https.tls.certresolver=le
      - traefik.http.routers.traefik-dashboard-https.rule=Host(`dash.ibhaskar.com`)
      - traefik.http.routers.traefik-dashboard-https.service=api@internal
      - traefik.http.routers.traefik-dashboard-https.tls=true
      - traefik.http.middlewares.https-redirect.redirectscheme.scheme=https
      - traefik.http.routers.traefik-dashboard-http.middlewares=https-redirect
      - traefik.http.middlewares.https-redirect.redirectscheme.permanent=true
      # define common network for traefik and apps
      - traefik.docker.network=towapp
    volumes:
      - traefik-public-certificates:/certificates
      - /var/run/docker.sock:/var/run/docker.sock:ro
    command:
      - --providers.docker
      - --api.insecure
      - --providers.docker.exposedbydefault=false
      - --entrypoints.http.address=:80
      - --entrypoints.https.address=:443 # https
      - --certificatesresolvers.le.acme.email=imbhaskaran@gmail.com # https
      - --certificatesresolvers.le.acme.storage=/certificates/acme.json #ssl
      - --certificatesresolvers.le.acme.tlschallenge=true
      
      - --accesslog
      - --log
      - --api
    networks:
      - towapp
volumes:
  traefik-public-certificates:


networks:
towapp:
  external: true

应用服务配置文件

services:

  first:
    restart: always
    container_name: first
    build:
      context: ./first
      dockerfile: Dockerfile
    labels:
      # Enable Traefik for this specific "backend" service
      - traefik.enable=true
      # Define the port inside of the Docker service to use
      - traefik.http.services.first.loadbalancer.server.port=8081
      # Make Traefik use this domain in HTTP
      - traefik.http.routers.first-http.entrypoints=http
      - traefik.http.routers.first-http.rule=Host(`first.ibhaskar.com`)
      # Use the traefik-public network (declared below)
      - traefik.docker.network=traefik-public
      # Make Traefik use this domain in HTTPS
      - traefik.http.routers.first-https.entrypoints=https
      - traefik.http.routers.first-https.rule=Host(`first.ibhaskar.com`)
      - traefik.http.routers.first-https.tls=true
      # Use the "le" (Let's Encrypt) resolver
      - traefik.http.routers.first-https.tls.certresolver=le
      # https-redirect middleware to redirect HTTP to HTTPS
      - traefik.http.middlewares.first-https-redirect.redirectscheme.scheme=https
      - traefik.http.middlewares.first-https-redirect.redirectscheme.permanent=true
      # Middleware to redirect HTTP to HTTPS
      - traefik.http.routers.first-http.middlewares=https-redirect
      #- traefik.http.routers.app-https.middlewares=admin-auth
      - traefik.docker.network=towapp
    command: [ "node", "app.js" ]
    networks:
      - towapp

  second:
    restart: always
    container_name: second
    build:
      context: ./second
      dockerfile: Dockerfile
    labels:
      # Enable Traefik for this specific "backend" service
      - traefik.enable=true
      # Define the port inside of the Docker service to use
      - traefik.http.services.second.loadbalancer.server.port=8082
      # Make Traefik use this domain in HTTP
      - traefik.http.routers.second-http.entrypoints=http
      - traefik.http.routers.second-http.rule=Host(`second.ibhaskar.com`)
      # Use the traefik-public network (declared below)
      - traefik.docker.network=traefik-public
      # Make Traefik use this domain in HTTPS
      - traefik.http.routers.second-https.entrypoints=https
      - traefik.http.routers.second-https.rule=Host(`second.ibhaskar.com`)
      - traefik.http.routers.second-https.tls=true
      # Use the "le" (Let's Encrypt) resolver
      - traefik.http.routers.second-https.tls.certresolver=le
      # https-redirect middleware to redirect HTTP to HTTPS
      - traefik.http.middlewares.second-https-redirect.redirectscheme.scheme=https
      - traefik.http.middlewares.second-https-redirect.redirectscheme.permanent=true
      # Middleware to redirect HTTP to HTTPS
      - traefik.http.routers.second-http.middlewares=https-redirect
      #- traefik.http.routers.app-https.middlewares=admin-auth
      - traefik.docker.network=towapp
    command: [ "node", "server.js" ]
    networks:
      - towapp

networks:
  towapp:
    external: true

问题排查与修复

1. HTTPS路由未关联后端服务

first服务的HTTPS路由first-https未指定对应的后端服务,导致Traefik无法将请求转发到正确的容器,直接返回404。需添加以下标签:

- traefik.http.routers.first-https.service=first@docker

2. 重复的网络标签配置

两个服务的labels中重复定义了traefik.docker.network,虽然最后生效的是正确的towapp,但冗余配置易引发混淆,建议删除错误的traefik.docker.network=traefik-public行。

3. 中间件引用不匹配

first-http路由引用的https-redirect是Traefik服务中定义的全局中间件,而服务自身已定义了专属的first-https-redirect中间件,建议改为引用自身中间件,避免依赖全局配置的潜在问题:

- traefik.http.routers.first-http.middlewares=first-https-redirect

修正后的first服务标签示例

labels:
  - traefik.enable=true
  - traefik.http.services.first.loadbalancer.server.port=8081
  # HTTP路由配置
  - traefik.http.routers.first-http.entrypoints=http
  - traefik.http.routers.first-http.rule=Host(`first.ibhaskar.com`)
  - traefik.http.routers.first-http.middlewares=first-https-redirect
  # HTTPS路由配置
  - traefik.http.routers.first-https.entrypoints=https
  - traefik.http.routers.first-https.rule=Host(`first.ibhaskar.com`)
  - traefik.http.routers.first-https.tls=true
  - traefik.http.routers.first-https.tls.certresolver=le
  - traefik.http.routers.first-https.service=first@docker
  # 自定义HTTPS重定向中间件
  - traefik.http.middlewares.first-https-redirect.redirectscheme.scheme=https
  - traefik.http.middlewares.first-https-redirect.redirectscheme.permanent=true
  # 网络配置
  - traefik.docker.network=towapp

验证步骤

  1. 重启Traefik及first服务:
    docker-compose -f docker.traefik.yml restart
    docker-compose restart first
    
  2. 访问https://first.ibhaskar.com验证是否正常响应。

内容的提问来源于stack exchange,提问作者Bhaskar

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.03 01:00:59