You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

多域名Traefik配置问题:Let’s Encrypt证书异常

Hey there, let's dig into why your test-1.domain2.com is pulling a self-signed cert instead of a valid Let's Encrypt one. Here are the most common issues to check and fix step by step:

1. Verify Your Let’s Encrypt Resolver Configuration

First, make sure your Traefik config doesn't restrict the resolver to only domain1.com. In your traefik.toml, check the certificatesResolvers section:

  • Ensure there’s no explicit domains list locking it to domain1.com — the resolver should automatically handle all requested domains, or you can explicitly include domain2.com and its subdomains.
  • Double-check that the ACME challenge (HTTP-01 is most common) is properly configured and linked to your web entrypoint.
  • Critical: The acme.json file must have 600 permissions (chmod 600 acme.json), otherwise Traefik can’t write certificates and will fall back to self-signed ones.

Example valid resolver config:

[certificatesResolvers.le.acme]
  email = "your-email@example.com"  # Required for Let's Encrypt account
  storage = "acme.json"
  [certificatesResolvers.le.acme.httpChallenge]
    entryPoint = "web"  # Must match your 80-port entrypoint name
2. Fix Docker Container Labels for the Subdomain

For the container serving test-1.domain2.com, you need to explicitly link it to your Let’s Encrypt resolver and set the correct host rule:

  • Make sure the Host() rule exactly matches your subdomain.
  • Add the tls.certResolver tag to tell Traefik to use your Let’s Encrypt resolver for this router.
  • Don’t forget to enable TLS for the router.

Example Docker Compose labels:

labels:
  - "traefik.enable=true"
  - "traefik.http.routers.test-service.rule=Host(`test-1.domain2.com`)"
  - "traefik.http.routers.test-service.entrypoints=websecure"
  - "traefik.http.routers.test-service.tls=true"
  - "traefik.http.routers.test-service.tls.certResolver=le"  # Matches your resolver name
3. Validate Domain & Port Connectivity

Let’s Encrypt needs to reach your server via port 80 to complete the HTTP-01 challenge:

  • Confirm test-1.domain2.com resolves to your Traefik server’s public IP (use nslookup test-1.domain2.com to check).
  • Ensure ports 80 and 443 are open to the internet (no firewall/security group blocking them).
  • Test the challenge path manually: Run curl -v http://test-1.domain2.com/.well-known/acme-challenge/test — you should get a 404 (normal, since it’s a test path), but if you get a timeout or connection refused, the challenge will fail.
4. Check Traefik Logs for Errors

Enable debug logging in traefik.toml to see exactly why the certificate isn’t being issued:

log.level = "debug"

Then view the logs with:

docker logs <your-traefik-container-name>

Look for lines like failed to obtain certificate — they’ll tell you if the issue is a DNS problem, permission error, or challenge failure.

5. Confirm EntryPoints Are Configured Correctly

Make sure your web (80) and websecure (443) entrypoints are set up to handle redirects and TLS:

[entryPoints]
  [entryPoints.web]
    address = ":80"
    [entryPoints.web.http.redirections.entryPoint]
      to = "websecure"
      scheme = "https"
  [entryPoints.websecure]
    address = ":443"

Start with these checks — the most likely culprits are missing certResolver tags on the subdomain’s router, or a restricted resolver config. Once you fix those, Traefik should automatically request and install the Let’s Encrypt cert for test-1.domain2.com.

内容的提问来源于stack exchange,提问作者Chris L.

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 08:17:47