You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

树莓派Docker Swarm集群Traefik配置HTTPS及证书问题求助

Hey there! Let's break down your Traefik + Docker Swarm issues step by step—you're super close to getting this working with your No-IP dynamic domain.

1. What should you set for docker.domain?

This parameter tells Traefik to automatically append a domain suffix to your container services. You should absolutely use your full No-IP dynamic domain here. For example, if your No-IP domain is myhomeserver.ddns.net, set:

docker.domain = "myhomeserver.ddns.net"

This way, Traefik will generate default domains like portainer.myhomeserver.ddns.net for your containers, so you don't have to specify the full domain in every service's labels.

2. Fixing HTTP-only access & missing HTTPS on the Traefik dashboard

Right now, your setup is serving HTTP because a few key config pieces are missing:

  • Enable HTTPS entrypoint & HTTP-to-HTTPS redirect: Add these to your traefik.toml to force all HTTP traffic to HTTPS:
    [entryPoints.web]
      address = ":80"
      # Redirect all HTTP to HTTPS
      [entryPoints.web.http.redirections.entryPoint]
        to = "websecure"
        scheme = "https"
    
    [entryPoints.websecure]
      address = ":443"
    
  • Publish both 80 and 443 ports in your Swarm stack: In your docker-compose.yml, make sure the Traefik service exposes both ports to the host:
    services:
      traefik:
        image: traefik:v2.10  # Use a stable recent version
        ports:
          - "80:80"
          - "443:443"
        # ... rest of your config
    
  • Secure the Traefik dashboard with HTTPS: Disable insecure HTTP access to the dashboard, and assign it a HTTPS-enabled router via labels:
    In traefik.toml:
    [api]
      dashboard = true
      insecure = false  # Don't allow HTTP access to the dashboard
    
    In your Traefik service labels:
    labels:
      - "traefik.http.routers.traefik.rule=Host(`traefik.myhomeserver.ddns.net`)"
      - "traefik.http.routers.traefik.service=api@internal"
      - "traefik.http.routers.traefik.tls.certresolver=myacmeresolver"
    
    Now you can access the dashboard at https://traefik.myhomeserver.ddns.net instead of the local IP.

3. Fixing the ACME 403 Error (Failed to get certificates)

A 403 from Let's Encrypt almost always means it can't verify you own the domain. Here's what to check:

  • Port forwarding is working: Your router must forward ports 80 and 443 from your public IP to the private IP of your Traefik node (192.168.11.100). Let's Encrypt needs to reach your server on port 80 to complete the HTTP-01 challenge.
  • No-IP domain points to your public IP: Run nslookup your-noip-domain.ddns.net on a device outside your home network (or use an online DNS checker) to confirm it resolves to your current public IP. If not, make sure your No-IP dynamic DNS client is running on one of your Pi's and updating correctly.
  • ACME resolver config is correct: Double-check your traefik.toml has a valid HTTP challenge setup (DNS challenge requires No-IP API access, which is more complex—stick with HTTP first):
    [certificatesResolvers.myacmeresolver.acme]
      email = "your-real-email@example.com"  # Required for certificate renewal alerts
      storage = "/acme.json"  # Stores certificates
      [certificatesResolvers.myacmeresolver.acme.httpChallenge]
        entryPoint = "web"  # Uses port 80 for domain verification
    
  • Fix permissions on acme.json: Traefik needs read/write access to this file, and it must have strict permissions (600). On your Traefik node, run:
    touch acme.json && chmod 600 acme.json
    
    Then make sure this file is mounted as a volume in your docker-compose.yml:
    volumes:
      - "/var/run/docker.sock:/var/run/docker.sock"
      - "./acme.json:/acme.json"
    

Quick Verification Checklist

Before redeploying, tick these off:

  • docker.domain is set to your full No-IP domain
  • EntryPoints 80 and 443 are configured, with HTTP redirecting to HTTPS
  • Traefik service publishes both 80 and 443 ports in Swarm
  • ACME resolver has your email set, uses HTTP challenge, and acme.json has 600 permissions
  • Router forwards 80/443 to your Traefik node's private IP
  • No-IP domain resolves to your public IP

Once you've updated these configs, redeploy your Traefik stack with docker stack deploy -c docker-compose.yml traefik and check the logs with docker service logs traefik_traefik to confirm certificates are being issued.

内容的提问来源于stack exchange,提问作者nano

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.12 03:53:53