多域名Traefik配置问题:Let’s Encrypt证书异常
Hey there, let's dig into why your test-1.domain2.com is pulling a self-signed cert instead of a valid Let's Encrypt one. Here are the most common issues to check and fix step by step:
First, make sure your Traefik config doesn't restrict the resolver to only domain1.com. In your traefik.toml, check the certificatesResolvers section:
- Ensure there’s no explicit
domainslist locking it todomain1.com— the resolver should automatically handle all requested domains, or you can explicitly includedomain2.comand its subdomains. - Double-check that the ACME challenge (HTTP-01 is most common) is properly configured and linked to your
webentrypoint. - Critical: The
acme.jsonfile must have 600 permissions (chmod 600 acme.json), otherwise Traefik can’t write certificates and will fall back to self-signed ones.
Example valid resolver config:
[certificatesResolvers.le.acme] email = "your-email@example.com" # Required for Let's Encrypt account storage = "acme.json" [certificatesResolvers.le.acme.httpChallenge] entryPoint = "web" # Must match your 80-port entrypoint name
For the container serving test-1.domain2.com, you need to explicitly link it to your Let’s Encrypt resolver and set the correct host rule:
- Make sure the
Host()rule exactly matches your subdomain. - Add the
tls.certResolvertag to tell Traefik to use your Let’s Encrypt resolver for this router. - Don’t forget to enable TLS for the router.
Example Docker Compose labels:
labels: - "traefik.enable=true" - "traefik.http.routers.test-service.rule=Host(`test-1.domain2.com`)" - "traefik.http.routers.test-service.entrypoints=websecure" - "traefik.http.routers.test-service.tls=true" - "traefik.http.routers.test-service.tls.certResolver=le" # Matches your resolver name
Let’s Encrypt needs to reach your server via port 80 to complete the HTTP-01 challenge:
- Confirm
test-1.domain2.comresolves to your Traefik server’s public IP (usenslookup test-1.domain2.comto check). - Ensure ports 80 and 443 are open to the internet (no firewall/security group blocking them).
- Test the challenge path manually: Run
curl -v http://test-1.domain2.com/.well-known/acme-challenge/test— you should get a 404 (normal, since it’s a test path), but if you get a timeout or connection refused, the challenge will fail.
Enable debug logging in traefik.toml to see exactly why the certificate isn’t being issued:
log.level = "debug"
Then view the logs with:
docker logs <your-traefik-container-name>
Look for lines like failed to obtain certificate — they’ll tell you if the issue is a DNS problem, permission error, or challenge failure.
Make sure your web (80) and websecure (443) entrypoints are set up to handle redirects and TLS:
[entryPoints] [entryPoints.web] address = ":80" [entryPoints.web.http.redirections.entryPoint] to = "websecure" scheme = "https" [entryPoints.websecure] address = ":443"
Start with these checks — the most likely culprits are missing certResolver tags on the subdomain’s router, or a restricted resolver config. Once you fix those, Traefik should automatically request and install the Let’s Encrypt cert for test-1.domain2.com.
内容的提问来源于stack exchange,提问作者Chris L.

