You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Traefik配置后https://www域名出现SSL错误及404问题求助

故障根因
  • SSL证书错误:当前签发的Let's Encrypt证书仅覆盖根域名mysite.com,未包含www.mysite.com,访问HTTPS的www域名时触发证书域名不匹配错误。
  • 404错误:仅配置了HTTP端口的www跳转规则,HTTPS端口的www域名请求匹配到路由后无对应跳转逻辑,同时旧的Host匹配规则语法错误导致Traefik未正确识别www域名的路由归属。
可行解决方案

步骤1:修正配置规则

替换mysite服务的labels配置为以下内容,修正Host匹配语法、显式指定双域名证书、新增HTTPS端口的www跳转规则:

version: "3.3"
services:
  traefik:
    command:
      # Get Docker as the provider
      - "--providers.docker=true"
      # Avoid that all containers are exposed
      - "--providers.docker.exposedbydefault=false"
      # Settle the ports for the entry points
      - "--entrypoints.web.address=:80"
      - "--entrypoints.web-secure.address=:443"
      # Settle the autentification method to http challenge
      - "--certificatesresolvers.myhttpchallenge.acme.httpchallenge=true"
      - "--certificatesresolvers.myhttpchallenge.acme.httpchallenge.entrypoint=web"
      # Uncomment this to get a fake certificate when testing
      #- "--certificatesresolvers.myhttpchallenge.acme.caserver=https://acme-staging-v02.api.letsencrypt.org/directory"
      # Settle letsencrypt as the certificate provider
      - "--certificatesresolvers.myhttpchallenge.acme.email=你的实际注册邮箱"
      - "--certificatesresolvers.myhttpchallenge.acme.storage=/letsencrypt/acme.json"
  mysite:
    labels:
      - "traefik.enable=true"
      - "traefik.docker.network=traefik"
      # HTTP路由配置
      - "traefik.http.routers.mysite.rule=Host(`mysite.com`, `www.mysite.com`)"
      - "traefik.http.routers.mysite.entrypoints=web"
      - "traefik.http.middlewares.redirect-to-https.redirectscheme.scheme=https"
      - "traefik.http.routers.mysite.middlewares=redirect-to-https@docker"
      # 新增www跳转根域名的中间件
      - "traefik.http.middlewares.redirect-www-to-root.redirectregex.regex=^https?://www\\.mysite\\.com/(.*)"
      - "traefik.http.middlewares.redirect-www-to-root.redirectregex.replacement=https://mysite.com/$1"
      - "traefik.http.middlewares.redirect-www-to-root.redirectregex.permanent=true"
      # HTTPS路由配置
      - "traefik.http.routers.mysite-secured.rule=Host(`mysite.com`, `www.mysite.com`)"
      - "traefik.http.routers.mysite-secured.entrypoints=web-secure"
      - "traefik.http.routers.mysite-secured.tls=true"
      - "traefik.http.routers.mysite-secured.tls.certresolver=myhttpchallenge"
      # 显式指定证书覆盖的双域名,确保ACME签发多域名证书
      - "traefik.http.routers.mysite-secured.tls.domains[0].main=mysite.com"
      - "traefik.http.routers.mysite-secured.tls.domains[0].sans=www.mysite.com"
      # 给HTTPS路由绑定www跳转中间件
      - "traefik.http.routers.mysite-secured.middlewares=redirect-www-to-root@docker"

步骤2:清理旧证书重启服务

  1. 删除你挂载的/letsencrypt路径下的acme.json文件,清除之前仅包含根域名的旧证书
  2. 执行docker compose down && docker compose up -d重启所有服务,等待Traefik重新申请包含两个域名的新证书,等待1-2分钟后验证即可。

内容的提问来源于stack exchange,提问作者aaaaaaaaaaa

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.10.03 12:18:03