Traefik TCP路由配置报错:field not found, node: passthrough
Traefik 2.8.3配置TLS直通到Apache2报错的解决方法
问题场景
个人网站部署在家中Apache2服务器,自带SSL证书;外网通过独立的私有云代理提供服务,本地可直接访问Apache IP打开网站。因家中还有其他通过Traefik访问的本地Web应用,希望通过Traefik路由到本地Apache以访问该网站,编写了如下动态配置:
# As YAML Configuration File tcp: routers: router-apache2: entrypoints: - "https" rule: "Host(`access.website.com`)" service: web-service tls: passthrough: true services: web-service: loadBalancer: servers: - url: "http://192.168.1.10:80"
配置后出现报错,日志如下:
{"level":"debug","msg":"Serving default certificate for request: \"access.website.com\"","time":"2022-09-02T12:15:13Z"} {"level":"debug","msg":"http: TLS handshake error from 192.168.1.35:54474: remote error: tls: bad certificate","time":"2022-09-02T12:15:13Z"} {"level":"debug","msg":"Serving default certificate for request: \"access.website.com\"","time":"2022-09-02T12:15:13Z"} {"level":"debug","msg":"http: TLS handshake error from 192.168.1.35:54478: remote error: tls: bad certificate","time":"2022-09-02T12:15:13Z"} {"level":"debug","msg":"Serving default certificate for request: \"\"","time":"2022-09-02T12:15:20Z"} {"level":"debug","msg":"Serving default certificate for request: \"\"","time":"2022-09-02T12:15:47Z"} {"level":"debug","msg":"Serving default certificate for request: \"\"","time":"2022-09-02T12:15:49Z"} {"level":"debug","msg":"Serving default certificate for request: \"\"","time":"2022-09-02T12:15:49Z"} {"level":"error","msg":"Error occurred during watcher callback: /config/apache2.yml: field not found, node: passthrough","providerName":"file","time":"2022-09-02T12:16:51Z"} {"level":"debug","msg":"Serving default certificate for request: \"access.website.com\"","time":"2022-09-02T12:18:41Z"}
错误原因分析
- TCP路由规则错误:TCP层的TLS路由需基于SNI(Server Name Indication)匹配域名,不能使用HTTP层的
Host规则,这会导致Traefik无法正确识别TCP路由配置,进而引发字段识别错误。 - 后端服务地址错误:TLS直通模式下,Traefik会直接转发加密的TLS流量到后端,因此后端Apache需监听443端口处理SSL请求,而配置中指向的是80端口(HTTP),无法处理加密流量,导致证书错误。
- 配置结构匹配问题:错误日志中的
field not found, node: passthrough本质是路由规则错误导致Traefik对TCP路由配置解析失败。
解决方案
1. 修正TCP路由规则
将Host替换为HostSNI,这是TCP层TLS路由的正确匹配规则。
2. 调整后端服务地址
将服务地址改为Apache的443端口(TCP协议),确保转发加密流量到正确的端口。
3. 修正后的完整配置
# As YAML Configuration File tcp: routers: router-apache2: entrypoints: - "https" rule: "HostSNI(`access.website.com`)" service: web-service tls: passthrough: true services: web-service: loadBalancer: servers: - url: "tcp://192.168.1.10:443"
4. 验证Apache配置
确保Apache已正确配置access.website.com的SSL证书,且443端口正常监听,可直接访问https://192.168.1.10测试证书有效性。
5. 重启Traefik
应用修正后的配置,重启Traefik服务,观察日志是否消除错误。
补充说明
- TLS直通模式下,Traefik不对流量解密,所有TLS处理由后端Apache完成,需保证后端证书与域名匹配且有效。
- 若无需保留Apache原有证书,也可改为让Traefik终止TLS(使用Traefik管理证书),再转发HTTP流量到Apache的80端口,但此方案不符合使用原有证书的需求。
内容的提问来源于stack exchange,提问作者Ciasto piekarz
相关产品推荐
相关产品推荐

