树莓派Docker Swarm集群Traefik配置HTTPS及证书问题求助
Hey there! Let's break down your Traefik + Docker Swarm issues step by step—you're super close to getting this working with your No-IP dynamic domain.
1. What should you set for docker.domain?
This parameter tells Traefik to automatically append a domain suffix to your container services. You should absolutely use your full No-IP dynamic domain here. For example, if your No-IP domain is myhomeserver.ddns.net, set:
docker.domain = "myhomeserver.ddns.net"
This way, Traefik will generate default domains like portainer.myhomeserver.ddns.net for your containers, so you don't have to specify the full domain in every service's labels.
2. Fixing HTTP-only access & missing HTTPS on the Traefik dashboard
Right now, your setup is serving HTTP because a few key config pieces are missing:
- Enable HTTPS entrypoint & HTTP-to-HTTPS redirect: Add these to your
traefik.tomlto force all HTTP traffic to HTTPS:[entryPoints.web] address = ":80" # Redirect all HTTP to HTTPS [entryPoints.web.http.redirections.entryPoint] to = "websecure" scheme = "https" [entryPoints.websecure] address = ":443" - Publish both 80 and 443 ports in your Swarm stack: In your
docker-compose.yml, make sure the Traefik service exposes both ports to the host:services: traefik: image: traefik:v2.10 # Use a stable recent version ports: - "80:80" - "443:443" # ... rest of your config - Secure the Traefik dashboard with HTTPS: Disable insecure HTTP access to the dashboard, and assign it a HTTPS-enabled router via labels:
Intraefik.toml:
In your Traefik service labels:[api] dashboard = true insecure = false # Don't allow HTTP access to the dashboard
Now you can access the dashboard atlabels: - "traefik.http.routers.traefik.rule=Host(`traefik.myhomeserver.ddns.net`)" - "traefik.http.routers.traefik.service=api@internal" - "traefik.http.routers.traefik.tls.certresolver=myacmeresolver"https://traefik.myhomeserver.ddns.netinstead of the local IP.
3. Fixing the ACME 403 Error (Failed to get certificates)
A 403 from Let's Encrypt almost always means it can't verify you own the domain. Here's what to check:
- Port forwarding is working: Your router must forward ports 80 and 443 from your public IP to the private IP of your Traefik node (192.168.11.100). Let's Encrypt needs to reach your server on port 80 to complete the HTTP-01 challenge.
- No-IP domain points to your public IP: Run
nslookup your-noip-domain.ddns.neton a device outside your home network (or use an online DNS checker) to confirm it resolves to your current public IP. If not, make sure your No-IP dynamic DNS client is running on one of your Pi's and updating correctly. - ACME resolver config is correct: Double-check your
traefik.tomlhas a valid HTTP challenge setup (DNS challenge requires No-IP API access, which is more complex—stick with HTTP first):[certificatesResolvers.myacmeresolver.acme] email = "your-real-email@example.com" # Required for certificate renewal alerts storage = "/acme.json" # Stores certificates [certificatesResolvers.myacmeresolver.acme.httpChallenge] entryPoint = "web" # Uses port 80 for domain verification - Fix permissions on
acme.json: Traefik needs read/write access to this file, and it must have strict permissions (600). On your Traefik node, run:
Then make sure this file is mounted as a volume in yourtouch acme.json && chmod 600 acme.jsondocker-compose.yml:volumes: - "/var/run/docker.sock:/var/run/docker.sock" - "./acme.json:/acme.json"
Quick Verification Checklist
Before redeploying, tick these off:
-
docker.domainis set to your full No-IP domain - EntryPoints 80 and 443 are configured, with HTTP redirecting to HTTPS
- Traefik service publishes both 80 and 443 ports in Swarm
- ACME resolver has your email set, uses HTTP challenge, and
acme.jsonhas 600 permissions - Router forwards 80/443 to your Traefik node's private IP
- No-IP domain resolves to your public IP
Once you've updated these configs, redeploy your Traefik stack with docker stack deploy -c docker-compose.yml traefik and check the logs with docker service logs traefik_traefik to confirm certificates are being issued.
内容的提问来源于stack exchange,提问作者nano

