You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

在AWS EKS上用Traefik2配置HTTPS(ACM证书)遇404问题求助

问题排查与解决

你的HTTPS访问404、HTTP正常的问题,主要出在两个地方:Traefik没正确识别LB转发的HTTPS请求,以及IngressRoute配置没适配LB终止SSL的场景,同时还缺了HTTP转HTTPS的重定向配置。下面是具体的解决步骤:

1. 补全Traefik Service的端口映射和证书ARN

你的Service配置漏了端口映射,而且ACM证书ARN不完整,这会导致LB无法正确转发流量。修改Helm values里的service部分:

service:
  enabled: true
  type: LoadBalancer
  annotations: {
    service.beta.kubernetes.io/aws-load-balancer-internal: "true",
    service.beta.kubernetes.io/aws-load-balancer-ssl-ports: "443",
    service.beta.kubernetes.io/aws-load-balancer-backend-protocol: "http",
    # 务必补全证书ARN的最后一段证书ID,比如arn:aws:acm:us-east-1:xxxxxxx:certificate/abc123
    service.beta.kubernetes.io/aws-load-balancer-ssl-cert: "arn:aws:acm:us-east-1:xxxxxxxxx:certificate/完整证书ID"
  }
  ports:
    web:
      port: 80
      targetPort: 80
    websecure:
      port: 443
      targetPort: 443

2. 让Traefik信任AWS LB的转发头

因为LB已经终止了SSL,转发给Traefik的是HTTP请求,但会带上X-Forwarded-Proto: https头。Traefik默认不信任外部的转发头,所以需要配置它信任LB的IP段(换成你的VPC CIDR,测试时可以用0.0.0.0/0):

additionalArguments:
  - "--entrypoints.web.forwardedHeaders.trustedIPs=10.0.0.0/8" # 替换为你的VPC CIDR
  - "--entrypoints.websecure.forwardedHeaders.trustedIPs=10.0.0.0/8"

3. 配置重定向中间件和适配IngressRoute

首先创建一个HTTP转HTTPS的重定向中间件:

---
apiVersion: traefik.containo.us/v1alpha1
kind: Middleware
metadata:
  name: redirect-to-https
  namespace: traefik
spec:
  redirectScheme:
    scheme: https
    permanent: true

然后拆分IngressRoute,分别处理HTTP和HTTPS请求:

---
# 处理HTTP请求,自动重定向到HTTPS
apiVersion: traefik.containo.us/v1alpha1
kind: IngressRoute
metadata:
  name: dashboard-http
  namespace: traefik
spec:
  entryPoints:
    - web
  routes:
    - match: Host(`traefik.example.com`)
      kind: Rule
      middlewares:
        - name: redirect-to-https
          namespace: traefik
      services:
        - name: api@internal
          kind: TraefikService
---
# 处理HTTPS请求
apiVersion: traefik.containo.us/v1alpha1
kind: IngressRoute
metadata:
  name: dashboard-https
  namespace: traefik
spec:
  entryPoints:
    - websecure
  routes:
    - match: Host(`traefik.example.com`)
      kind: Rule
      services:
        - name: api@internal
          kind: TraefikService
  tls: {} # 因为SSL在LB层终止,这里不需要配置证书

4. 重新部署配置

执行Helm升级更新Traefik:

helm upgrade traefik traefik/traefik -n traefik -f 你的values文件.yaml

然后应用中间件和新的IngressRoute:

kubectl apply -f middleware.yaml -f ingressroute.yaml -n traefik

验证

现在访问http://traefik.example.com会自动跳转到HTTPS,直接访问https://traefik.example.com也能正常打开仪表盘了。

内容的提问来源于stack exchange,提问作者DeliveryMan5

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.17 15:35:36