Traefik+Docker Swarm部署SSL证书配置问题求助
Hey there, let's work through the Traefik + Docker Swarm + wildcard SSL issues you're hitting on DigitalOcean. I've debugged similar setups before, so let's break down the possible fixes step by step:
1. First, Validate Your ACME (Let's Encrypt) Configuration
Wildcard certificates require DNS challenges (HTTP challenges won't work), so this is the most common point of failure. Let's check your traefik.toml or stack config:
- Ensure you've configured the DigitalOcean DNS provider correctly. You need to pass your DO API key as an environment variable, and set up the DNS challenge resolver with a delay to account for DNS propagation.
- Double-check the ACME storage path (
/acme.json)—Traefik needs read/write access to this file, and it should be stored in a persistent volume (not an ephemeral one) so certificates survive service restarts. - For testing, switch to Let's Encrypt's staging environment first to avoid hitting rate limits. Add this to your ACME config:
[acme] email = "your-admin-email@mouv.com" storage = "/acme.json" entryPoint = "https" caServer = "https://acme-staging-v02.api.letsencrypt.org/directory" # Staging for testing [acme.dnsChallenge] provider = "digitalocean" delayBeforeCheck = 60 # Wait 60s for DNS changes to propagate
2. Fix Docker Stack Traefik Service Config
Your docker-stack.yml needs to properly expose ports, mount volumes, and pass environment variables for the DO API. Here's a corrected snippet:
services: traefik: image: traefik:v2.9 # Use a stable, supported version command: - "--api.insecure=true" # Disable in production; use dashboard auth instead - "--providers.docker=true" - "--providers.docker.swarmMode=true" - "--providers.docker.exposedbydefault=false" - "--entrypoints.web.address=:80" - "--entrypoints.websecure.address=:443" # Configure DNS resolver for wildcard certs - "--certificatesresolvers.dnsresolver.acme.dnschallenge=true" - "--certificatesresolvers.dnsresolver.acme.dnschallenge.provider=digitalocean" - "--certificatesresolvers.dnsresolver.acme.email=your-admin-email@mouv.com" - "--certificatesresolvers.dnsresolver.acme.storage=/acme.json" - "--certificatesresolvers.dnsresolver.acme.caserver=https://acme-staging-v02.api.letsencrypt.org/directory" environment: - DO_API_KEY=your-digitalocean-api-key-here # Must have DNS edit permissions ports: - "80:80" - "443:443" - "8080:8080" # Traefik dashboard volumes: - "/var/run/docker.sock:/var/run/docker.sock:ro" # Read-only access to Docker socket - "traefik-acme:/acme.json" # Persistent volume for certificates deploy: placement: constraints: - node.role == manager # Run Traefik on a manager node replicas: 1 volumes: traefik-acme: # Create a persistent volume for ACME storage
3. Adjust Service Labels for Wildcard Certificates
For your subdomain services, make sure the Traefik labels explicitly reference the wildcard domain and use the DNS resolver:
services: your-service: image: your-service-image deploy: labels: - "traefik.enable=true" - "traefik.http.routers.your-service.rule=Host(`service.mouv.com`)" - "traefik.http.routers.your-service.entrypoints=websecure" - "traefik.http.routers.your-service.tls=true" - "traefik.http.routers.your-service.tls.certresolver=dnsresolver" # Define the wildcard domain set - "traefik.http.routers.your-service.tls.domains[0].main=mouv.com" - "traefik.http.routers.your-service.tls.domains[0].sans=*.mouv.com" - "traefik.http.services.your-service.loadbalancer.server.port=80" # Match your service's port
4. Debug DNS & Certificate Issues
- Verify DNS Propagation: Run
dig @8.8.8.8 *.mouv.com Aanddig @8.8.8.8 mouv.com Ato confirm both point to your manager node's public IP. Wait 5-10 minutes after updating DNS records before testing. - Check Traefik Logs: Run
docker service logs -f traefikto see detailed ACME challenge logs. Look for errors like invalid API keys, failed DNS record creation/deletion, or propagation timeouts. - Reset ACME Storage: If your
acme.jsonhas corrupted certificates, delete the volume and restart Traefik to force a fresh certificate request:docker volume rm traefik-acme docker service update traefik --force
5. Fix "tls: unknown certificate authority" Error
This usually means Traefik couldn't fetch a valid Let's Encrypt certificate, so it fell back to a self-signed one. Ensure:
- Your DO API key has write permissions for DNS records (check in the DigitalOcean control panel under API > Tokens/Keys).
- The
acme.jsonfile has correct permissions (Traefik needs read/write access—using a persistent volume as shown above avoids permission issues in Swarm).
内容的提问来源于stack exchange,提问作者Henry Ollarves

