You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Traefik TCP路由配置报错:field not found, node: passthrough

Traefik 2.8.3配置TLS直通到Apache2报错的解决方法

问题场景

个人网站部署在家中Apache2服务器,自带SSL证书;外网通过独立的私有云代理提供服务,本地可直接访问Apache IP打开网站。因家中还有其他通过Traefik访问的本地Web应用,希望通过Traefik路由到本地Apache以访问该网站,编写了如下动态配置:

# As YAML Configuration File
tcp:
  routers:
    router-apache2:
      entrypoints:
        - "https"
      rule: "Host(`access.website.com`)"
      service: web-service
      tls:
        passthrough: true

  services:
    web-service:
      loadBalancer:
        servers:
          - url: "http://192.168.1.10:80"

配置后出现报错,日志如下:

{"level":"debug","msg":"Serving default certificate for request: \"access.website.com\"","time":"2022-09-02T12:15:13Z"}
{"level":"debug","msg":"http: TLS handshake error from 192.168.1.35:54474: remote error: tls: bad certificate","time":"2022-09-02T12:15:13Z"}
{"level":"debug","msg":"Serving default certificate for request: \"access.website.com\"","time":"2022-09-02T12:15:13Z"}
{"level":"debug","msg":"http: TLS handshake error from 192.168.1.35:54478: remote error: tls: bad certificate","time":"2022-09-02T12:15:13Z"}
{"level":"debug","msg":"Serving default certificate for request: \"\"","time":"2022-09-02T12:15:20Z"}
{"level":"debug","msg":"Serving default certificate for request: \"\"","time":"2022-09-02T12:15:47Z"}
{"level":"debug","msg":"Serving default certificate for request: \"\"","time":"2022-09-02T12:15:49Z"}
{"level":"debug","msg":"Serving default certificate for request: \"\"","time":"2022-09-02T12:15:49Z"}
{"level":"error","msg":"Error occurred during watcher callback: /config/apache2.yml: field not found, node: passthrough","providerName":"file","time":"2022-09-02T12:16:51Z"}
{"level":"debug","msg":"Serving default certificate for request: \"access.website.com\"","time":"2022-09-02T12:18:41Z"}

错误原因分析

  1. TCP路由规则错误:TCP层的TLS路由需基于SNI(Server Name Indication)匹配域名,不能使用HTTP层的Host规则,这会导致Traefik无法正确识别TCP路由配置,进而引发字段识别错误。
  2. 后端服务地址错误:TLS直通模式下,Traefik会直接转发加密的TLS流量到后端,因此后端Apache需监听443端口处理SSL请求,而配置中指向的是80端口(HTTP),无法处理加密流量,导致证书错误。
  3. 配置结构匹配问题:错误日志中的field not found, node: passthrough本质是路由规则错误导致Traefik对TCP路由配置解析失败。

解决方案

1. 修正TCP路由规则

将Host替换为HostSNI,这是TCP层TLS路由的正确匹配规则。

2. 调整后端服务地址

将服务地址改为Apache的443端口(TCP协议),确保转发加密流量到正确的端口。

3. 修正后的完整配置

# As YAML Configuration File
tcp:
  routers:
    router-apache2:
      entrypoints:
        - "https"
      rule: "HostSNI(`access.website.com`)"
      service: web-service
      tls:
        passthrough: true

  services:
    web-service:
      loadBalancer:
        servers:
          - url: "tcp://192.168.1.10:443"

4. 验证Apache配置

确保Apache已正确配置access.website.com的SSL证书,且443端口正常监听,可直接访问https://192.168.1.10测试证书有效性。

5. 重启Traefik

应用修正后的配置,重启Traefik服务,观察日志是否消除错误。

补充说明

  • TLS直通模式下,Traefik不对流量解密,所有TLS处理由后端Apache完成,需保证后端证书与域名匹配且有效。
  • 若无需保留Apache原有证书,也可改为让Traefik终止TLS(使用Traefik管理证书),再转发HTTP流量到Apache的80端口,但此方案不符合使用原有证书的需求。

内容的提问来源于stack exchange,提问作者Ciasto piekarz

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.20 08:21:57