解决Cookiecutter-Django部署DigitalOcean时ACME证书连接拒绝错误
Let's break down what's going wrong and fix it step by step:
1. First, Check DigitalOcean Droplet Firewall Rules
The "Connection refused" error for the ACME challenge almost always means port 80 isn't accessible from the internet. DigitalOcean's default firewall might not have 80/443 open by default:
- Head to your Droplet's page in the DigitalOcean dashboard
- Navigate to the Firewalls tab
- Add inbound rules allowing:
- TCP port 80 (HTTP) from
0.0.0.0/0and::/0 - TCP port 443 (HTTPS) from
0.0.0.0/0and::/0
- TCP port 80 (HTTP) from
Your netstat output shows no processes listening on 80 or 443, which confirms external traffic can't reach the required ports.
2. Verify Docker Compose Port Mapping for Traefik
Check your production.yml file to ensure Traefik is correctly exposing ports 80 and 443 to the host machine. Look for the Traefik service section—it should include these port mappings:
services: traefik: ports: - "80:80" - "443:443"
If these lines are missing or misconfigured, Traefik won't listen on the public ports, leading to connection refusals.
3. Fix Docker Machine Environment Context
When you run eval "$(docker-machine env instancename)", you're telling your local Docker client to connect to the remote Droplet's Docker daemon. But using sudo with docker-compose can bypass this environment variable (since sudo uses a separate shell context).
Try running your commands without sudo:
docker-compose -f production.yml build docker-compose -f production.yml up -d
If you hit permission errors, add your user to the Docker group on the Droplet instead of relying on sudo:
# SSH into your Droplet first sudo usermod -aG docker $USER # Log out and back in for changes to take effect
4. Confirm Traefik and Django Are on the Same Network
Cookiecutter-Django uses a custom Docker network by default. Make sure both the Traefik and Django services are attached to the same network in production.yml:
networks: default: external: name: your_project_network_name
If they're on separate networks, Traefik can't route traffic to Django—this would break the ACME challenge and prevent your site from loading.
5. Double-Check Domain and DNS Settings
- Wait 10-15 minutes for DNS changes to propagate (local DNS might show the A record, but global propagation takes time)
- Verify your domain's A record points directly to your Droplet's public IP (avoid proxies like Cloudflare until you've confirmed basic connectivity)
- Ensure
DJANGO_ALLOWED_HOSTSin.envs/.production/.djangoincludes your full domain (e.g.,DJANGO_ALLOWED_HOSTS=example.com,www.example.com)
6. Test the ACME Challenge Manually
After fixing the above, restart your containers with docker-compose -f production.yml up. If you still get errors, test if the ACME challenge path is reachable:
curl http://your-droplet-ip/.well-known/acme-challenge/test
If you get a connection refused, loop back to steps 1-3—your ports still aren't open or mapped correctly.
内容的提问来源于stack exchange,提问作者marcu1000s

