如何通过Rancher标签为Traefik配置第三方域名SSL证书?
Absolutely! You’re right that configuring SSL and custom domains at the service level via Rancher tags is way more elegant than editing the global traefik.toml every time. For Traefik 1.5.4 (which you’re using), this is fully supported—here’s how to set it up step by step:
First, you need to make sure the third-party domain’s SSL certificate (.crt file) and private key (.key file) are accessible to your Traefik container. The easiest way to do this in Rancher is:
- Either mount a host directory containing the cert/key files to a path in the Traefik container (e.g.,
/certs/) - Or use Rancher’s secret management to create secrets for the cert and key, then mount those secrets to the Traefik container at a consistent path like
/certs/
Ensure the files are in PEM format (Traefik 1.5 requires this) and that the Traefik container has read permissions for them (setting file permissions to 644 usually works).
When creating or editing your target service in Rancher, add these custom labels to handle the domain and SSL configuration entirely at the service level:
traefik.enable=true: Tells Traefik to route traffic to this servicetraefik.frontend.rule=Host:your-third-party-domain.com: Replaceyour-third-party-domain.comwith the actual domain provided by the ownertraefik.frontend.entryPoints=https: Ensures traffic uses your pre-configured HTTPS entry point (you should already have this set up in yourtraefik.toml—if not, you’ll need to add it once, but that’s a one-time global config)traefik.frontend.auth.ssl.cert=/certs/your-domain.crt: Path to the certificate file inside the Traefik container (match the mount path you set in Step 1)traefik.frontend.auth.ssl.key=/certs/your-domain.key: Path to the private key file inside the Traefik container- Optional
traefik.frontend.redirect.entryPoint=https: Forces any HTTP traffic to this domain to redirect to HTTPS (add this if you want to enforce secure connections)
- Double-check that the third-party domain’s DNS records point to the public IP of your Traefik server—without this, the routing won’t work.
- Traefik 1.5 uses a specific set of labels (different from v2+), so make sure you don’t mix in newer label syntax.
- If you need to add multiple services with different custom domains/SSL certs, just repeat this process for each service—each can have its own unique labels pointing to its own cert files, no global config changes needed.
- After setting the labels, restart the target service (and Traefik if you modified its volume mounts) to let Traefik pick up the new configuration.
内容的提问来源于stack exchange,提问作者Robert Lachner

