在AWS EKS上用Traefik2配置HTTPS(ACM证书)遇404问题求助
问题排查与解决
你的HTTPS访问404、HTTP正常的问题,主要出在两个地方:Traefik没正确识别LB转发的HTTPS请求,以及IngressRoute配置没适配LB终止SSL的场景,同时还缺了HTTP转HTTPS的重定向配置。下面是具体的解决步骤:
1. 补全Traefik Service的端口映射和证书ARN
你的Service配置漏了端口映射,而且ACM证书ARN不完整,这会导致LB无法正确转发流量。修改Helm values里的service部分:
service: enabled: true type: LoadBalancer annotations: { service.beta.kubernetes.io/aws-load-balancer-internal: "true", service.beta.kubernetes.io/aws-load-balancer-ssl-ports: "443", service.beta.kubernetes.io/aws-load-balancer-backend-protocol: "http", # 务必补全证书ARN的最后一段证书ID,比如arn:aws:acm:us-east-1:xxxxxxx:certificate/abc123 service.beta.kubernetes.io/aws-load-balancer-ssl-cert: "arn:aws:acm:us-east-1:xxxxxxxxx:certificate/完整证书ID" } ports: web: port: 80 targetPort: 80 websecure: port: 443 targetPort: 443
2. 让Traefik信任AWS LB的转发头
因为LB已经终止了SSL,转发给Traefik的是HTTP请求,但会带上X-Forwarded-Proto: https头。Traefik默认不信任外部的转发头,所以需要配置它信任LB的IP段(换成你的VPC CIDR,测试时可以用0.0.0.0/0):
additionalArguments: - "--entrypoints.web.forwardedHeaders.trustedIPs=10.0.0.0/8" # 替换为你的VPC CIDR - "--entrypoints.websecure.forwardedHeaders.trustedIPs=10.0.0.0/8"
3. 配置重定向中间件和适配IngressRoute
首先创建一个HTTP转HTTPS的重定向中间件:
--- apiVersion: traefik.containo.us/v1alpha1 kind: Middleware metadata: name: redirect-to-https namespace: traefik spec: redirectScheme: scheme: https permanent: true
然后拆分IngressRoute,分别处理HTTP和HTTPS请求:
--- # 处理HTTP请求,自动重定向到HTTPS apiVersion: traefik.containo.us/v1alpha1 kind: IngressRoute metadata: name: dashboard-http namespace: traefik spec: entryPoints: - web routes: - match: Host(`traefik.example.com`) kind: Rule middlewares: - name: redirect-to-https namespace: traefik services: - name: api@internal kind: TraefikService --- # 处理HTTPS请求 apiVersion: traefik.containo.us/v1alpha1 kind: IngressRoute metadata: name: dashboard-https namespace: traefik spec: entryPoints: - websecure routes: - match: Host(`traefik.example.com`) kind: Rule services: - name: api@internal kind: TraefikService tls: {} # 因为SSL在LB层终止,这里不需要配置证书
4. 重新部署配置
执行Helm升级更新Traefik:
helm upgrade traefik traefik/traefik -n traefik -f 你的values文件.yaml
然后应用中间件和新的IngressRoute:
kubectl apply -f middleware.yaml -f ingressroute.yaml -n traefik
验证
现在访问http://traefik.example.com会自动跳转到HTTPS,直接访问https://traefik.example.com也能正常打开仪表盘了。
内容的提问来源于stack exchange,提问作者DeliveryMan5
相关产品推荐
相关产品推荐

