You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Traefik+Docker Swarm部署SSL证书配置问题求助

Hey there, let's work through the Traefik + Docker Swarm + wildcard SSL issues you're hitting on DigitalOcean. I've debugged similar setups before, so let's break down the possible fixes step by step:

1. First, Validate Your ACME (Let's Encrypt) Configuration

Wildcard certificates require DNS challenges (HTTP challenges won't work), so this is the most common point of failure. Let's check your traefik.toml or stack config:

  • Ensure you've configured the DigitalOcean DNS provider correctly. You need to pass your DO API key as an environment variable, and set up the DNS challenge resolver with a delay to account for DNS propagation.
  • Double-check the ACME storage path (/acme.json)—Traefik needs read/write access to this file, and it should be stored in a persistent volume (not an ephemeral one) so certificates survive service restarts.
  • For testing, switch to Let's Encrypt's staging environment first to avoid hitting rate limits. Add this to your ACME config:
    [acme]
    email = "your-admin-email@mouv.com"
    storage = "/acme.json"
    entryPoint = "https"
    caServer = "https://acme-staging-v02.api.letsencrypt.org/directory" # Staging for testing
    [acme.dnsChallenge]
    provider = "digitalocean"
    delayBeforeCheck = 60 # Wait 60s for DNS changes to propagate
    

2. Fix Docker Stack Traefik Service Config

Your docker-stack.yml needs to properly expose ports, mount volumes, and pass environment variables for the DO API. Here's a corrected snippet:

services:
  traefik:
    image: traefik:v2.9 # Use a stable, supported version
    command:
      - "--api.insecure=true" # Disable in production; use dashboard auth instead
      - "--providers.docker=true"
      - "--providers.docker.swarmMode=true"
      - "--providers.docker.exposedbydefault=false"
      - "--entrypoints.web.address=:80"
      - "--entrypoints.websecure.address=:443"
      # Configure DNS resolver for wildcard certs
      - "--certificatesresolvers.dnsresolver.acme.dnschallenge=true"
      - "--certificatesresolvers.dnsresolver.acme.dnschallenge.provider=digitalocean"
      - "--certificatesresolvers.dnsresolver.acme.email=your-admin-email@mouv.com"
      - "--certificatesresolvers.dnsresolver.acme.storage=/acme.json"
      - "--certificatesresolvers.dnsresolver.acme.caserver=https://acme-staging-v02.api.letsencrypt.org/directory"
    environment:
      - DO_API_KEY=your-digitalocean-api-key-here # Must have DNS edit permissions
    ports:
      - "80:80"
      - "443:443"
      - "8080:8080" # Traefik dashboard
    volumes:
      - "/var/run/docker.sock:/var/run/docker.sock:ro" # Read-only access to Docker socket
      - "traefik-acme:/acme.json" # Persistent volume for certificates
    deploy:
      placement:
        constraints:
          - node.role == manager # Run Traefik on a manager node
      replicas: 1

volumes:
  traefik-acme: # Create a persistent volume for ACME storage

3. Adjust Service Labels for Wildcard Certificates

For your subdomain services, make sure the Traefik labels explicitly reference the wildcard domain and use the DNS resolver:

services:
  your-service:
    image: your-service-image
    deploy:
      labels:
        - "traefik.enable=true"
        - "traefik.http.routers.your-service.rule=Host(`service.mouv.com`)"
        - "traefik.http.routers.your-service.entrypoints=websecure"
        - "traefik.http.routers.your-service.tls=true"
        - "traefik.http.routers.your-service.tls.certresolver=dnsresolver"
        # Define the wildcard domain set
        - "traefik.http.routers.your-service.tls.domains[0].main=mouv.com"
        - "traefik.http.routers.your-service.tls.domains[0].sans=*.mouv.com"
        - "traefik.http.services.your-service.loadbalancer.server.port=80" # Match your service's port

4. Debug DNS & Certificate Issues

  • Verify DNS Propagation: Run dig @8.8.8.8 *.mouv.com A and dig @8.8.8.8 mouv.com A to confirm both point to your manager node's public IP. Wait 5-10 minutes after updating DNS records before testing.
  • Check Traefik Logs: Run docker service logs -f traefik to see detailed ACME challenge logs. Look for errors like invalid API keys, failed DNS record creation/deletion, or propagation timeouts.
  • Reset ACME Storage: If your acme.json has corrupted certificates, delete the volume and restart Traefik to force a fresh certificate request:
    docker volume rm traefik-acme
    docker service update traefik --force
    

5. Fix "tls: unknown certificate authority" Error

This usually means Traefik couldn't fetch a valid Let's Encrypt certificate, so it fell back to a self-signed one. Ensure:

  • Your DO API key has write permissions for DNS records (check in the DigitalOcean control panel under API > Tokens/Keys).
  • The acme.json file has correct permissions (Traefik needs read/write access—using a persistent volume as shown above avoids permission issues in Swarm).

内容的提问来源于stack exchange,提问作者Henry Ollarves

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.12 03:51:09