You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

解决Cookiecutter-Django部署DigitalOcean时ACME证书连接拒绝错误

Troubleshooting ACME Certificate Failure with Cookiecutter-Django on DigitalOcean

Let's break down what's going wrong and fix it step by step:

1. First, Check DigitalOcean Droplet Firewall Rules

The "Connection refused" error for the ACME challenge almost always means port 80 isn't accessible from the internet. DigitalOcean's default firewall might not have 80/443 open by default:

  • Head to your Droplet's page in the DigitalOcean dashboard
  • Navigate to the Firewalls tab
  • Add inbound rules allowing:
    • TCP port 80 (HTTP) from 0.0.0.0/0 and ::/0
    • TCP port 443 (HTTPS) from 0.0.0.0/0 and ::/0

Your netstat output shows no processes listening on 80 or 443, which confirms external traffic can't reach the required ports.

2. Verify Docker Compose Port Mapping for Traefik

Check your production.yml file to ensure Traefik is correctly exposing ports 80 and 443 to the host machine. Look for the Traefik service section—it should include these port mappings:

services:
  traefik:
    ports:
      - "80:80"
      - "443:443"

If these lines are missing or misconfigured, Traefik won't listen on the public ports, leading to connection refusals.

3. Fix Docker Machine Environment Context

When you run eval "$(docker-machine env instancename)", you're telling your local Docker client to connect to the remote Droplet's Docker daemon. But using sudo with docker-compose can bypass this environment variable (since sudo uses a separate shell context).

Try running your commands without sudo:

docker-compose -f production.yml build
docker-compose -f production.yml up -d

If you hit permission errors, add your user to the Docker group on the Droplet instead of relying on sudo:

# SSH into your Droplet first
sudo usermod -aG docker $USER
# Log out and back in for changes to take effect

4. Confirm Traefik and Django Are on the Same Network

Cookiecutter-Django uses a custom Docker network by default. Make sure both the Traefik and Django services are attached to the same network in production.yml:

networks:
  default:
    external:
      name: your_project_network_name

If they're on separate networks, Traefik can't route traffic to Django—this would break the ACME challenge and prevent your site from loading.

5. Double-Check Domain and DNS Settings

  • Wait 10-15 minutes for DNS changes to propagate (local DNS might show the A record, but global propagation takes time)
  • Verify your domain's A record points directly to your Droplet's public IP (avoid proxies like Cloudflare until you've confirmed basic connectivity)
  • Ensure DJANGO_ALLOWED_HOSTS in .envs/.production/.django includes your full domain (e.g., DJANGO_ALLOWED_HOSTS=example.com,www.example.com)

6. Test the ACME Challenge Manually

After fixing the above, restart your containers with docker-compose -f production.yml up. If you still get errors, test if the ACME challenge path is reachable:

curl http://your-droplet-ip/.well-known/acme-challenge/test

If you get a connection refused, loop back to steps 1-3—your ports still aren't open or mapped correctly.


内容的提问来源于stack exchange,提问作者marcu1000s

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.12 04:53:54