Docker Traefik配置SSL后首个服务出现404页面未找到错误
Traefik启用SSL后首个服务404问题解决
问题场景
用Traefik代理两个Node.js应用,未启用SSL时两个服务均可正常访问;开启SSL后,first.ibhaskar.com返回404错误,second.ibhaskar.com及Traefik仪表盘dash.ibhaskar.com可正常通过HTTPS访问,且两个应用本地测试无异常。
相关配置文件
Traefik配置文件(docker.traefik.yml)
services: traefik: image: traefik:latest ports: - 80:80 - 443:443 restart: always labels: - traefik.enable=true - traefik.http.services.traefik-dashboard.loadbalancer.server.port=8080 ## configure http - traefik.http.routers.traefik-dashboard-http.entrypoints=http - traefik.http.routers.traefik-dashboard-http.rule=Host(`dash.ibhaskar.com`) ## configure https - traefik.http.routers.traefik-dashboard-https.entrypoints=https - traefik.http.routers.traefik-dashboard-https.tls.certresolver=le - traefik.http.routers.traefik-dashboard-https.rule=Host(`dash.ibhaskar.com`) - traefik.http.routers.traefik-dashboard-https.service=api@internal - traefik.http.routers.traefik-dashboard-https.tls=true - traefik.http.middlewares.https-redirect.redirectscheme.scheme=https - traefik.http.routers.traefik-dashboard-http.middlewares=https-redirect - traefik.http.middlewares.https-redirect.redirectscheme.permanent=true # define common network for traefik and apps - traefik.docker.network=towapp volumes: - traefik-public-certificates:/certificates - /var/run/docker.sock:/var/run/docker.sock:ro command: - --providers.docker - --api.insecure - --providers.docker.exposedbydefault=false - --entrypoints.http.address=:80 - --entrypoints.https.address=:443 # https - --certificatesresolvers.le.acme.email=imbhaskaran@gmail.com # https - --certificatesresolvers.le.acme.storage=/certificates/acme.json #ssl - --certificatesresolvers.le.acme.tlschallenge=true - --accesslog - --log - --api networks: - towapp volumes: traefik-public-certificates: networks: towapp: external: true
应用服务配置文件
services: first: restart: always container_name: first build: context: ./first dockerfile: Dockerfile labels: # Enable Traefik for this specific "backend" service - traefik.enable=true # Define the port inside of the Docker service to use - traefik.http.services.first.loadbalancer.server.port=8081 # Make Traefik use this domain in HTTP - traefik.http.routers.first-http.entrypoints=http - traefik.http.routers.first-http.rule=Host(`first.ibhaskar.com`) # Use the traefik-public network (declared below) - traefik.docker.network=traefik-public # Make Traefik use this domain in HTTPS - traefik.http.routers.first-https.entrypoints=https - traefik.http.routers.first-https.rule=Host(`first.ibhaskar.com`) - traefik.http.routers.first-https.tls=true # Use the "le" (Let's Encrypt) resolver - traefik.http.routers.first-https.tls.certresolver=le # https-redirect middleware to redirect HTTP to HTTPS - traefik.http.middlewares.first-https-redirect.redirectscheme.scheme=https - traefik.http.middlewares.first-https-redirect.redirectscheme.permanent=true # Middleware to redirect HTTP to HTTPS - traefik.http.routers.first-http.middlewares=https-redirect #- traefik.http.routers.app-https.middlewares=admin-auth - traefik.docker.network=towapp command: [ "node", "app.js" ] networks: - towapp second: restart: always container_name: second build: context: ./second dockerfile: Dockerfile labels: # Enable Traefik for this specific "backend" service - traefik.enable=true # Define the port inside of the Docker service to use - traefik.http.services.second.loadbalancer.server.port=8082 # Make Traefik use this domain in HTTP - traefik.http.routers.second-http.entrypoints=http - traefik.http.routers.second-http.rule=Host(`second.ibhaskar.com`) # Use the traefik-public network (declared below) - traefik.docker.network=traefik-public # Make Traefik use this domain in HTTPS - traefik.http.routers.second-https.entrypoints=https - traefik.http.routers.second-https.rule=Host(`second.ibhaskar.com`) - traefik.http.routers.second-https.tls=true # Use the "le" (Let's Encrypt) resolver - traefik.http.routers.second-https.tls.certresolver=le # https-redirect middleware to redirect HTTP to HTTPS - traefik.http.middlewares.second-https-redirect.redirectscheme.scheme=https - traefik.http.middlewares.second-https-redirect.redirectscheme.permanent=true # Middleware to redirect HTTP to HTTPS - traefik.http.routers.second-http.middlewares=https-redirect #- traefik.http.routers.app-https.middlewares=admin-auth - traefik.docker.network=towapp command: [ "node", "server.js" ] networks: - towapp networks: towapp: external: true
问题排查与修复
1. HTTPS路由未关联后端服务
first服务的HTTPS路由first-https未指定对应的后端服务,导致Traefik无法将请求转发到正确的容器,直接返回404。需添加以下标签:
- traefik.http.routers.first-https.service=first@docker
2. 重复的网络标签配置
两个服务的labels中重复定义了traefik.docker.network,虽然最后生效的是正确的towapp,但冗余配置易引发混淆,建议删除错误的traefik.docker.network=traefik-public行。
3. 中间件引用不匹配
first-http路由引用的https-redirect是Traefik服务中定义的全局中间件,而服务自身已定义了专属的first-https-redirect中间件,建议改为引用自身中间件,避免依赖全局配置的潜在问题:
- traefik.http.routers.first-http.middlewares=first-https-redirect
修正后的first服务标签示例
labels: - traefik.enable=true - traefik.http.services.first.loadbalancer.server.port=8081 # HTTP路由配置 - traefik.http.routers.first-http.entrypoints=http - traefik.http.routers.first-http.rule=Host(`first.ibhaskar.com`) - traefik.http.routers.first-http.middlewares=first-https-redirect # HTTPS路由配置 - traefik.http.routers.first-https.entrypoints=https - traefik.http.routers.first-https.rule=Host(`first.ibhaskar.com`) - traefik.http.routers.first-https.tls=true - traefik.http.routers.first-https.tls.certresolver=le - traefik.http.routers.first-https.service=first@docker # 自定义HTTPS重定向中间件 - traefik.http.middlewares.first-https-redirect.redirectscheme.scheme=https - traefik.http.middlewares.first-https-redirect.redirectscheme.permanent=true # 网络配置 - traefik.docker.network=towapp
验证步骤
- 重启Traefik及
first服务:docker-compose -f docker.traefik.yml restart docker-compose restart first - 访问
https://first.ibhaskar.com验证是否正常响应。
内容的提问来源于stack exchange,提问作者Bhaskar
相关产品推荐
相关产品推荐

