You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何借助Traefik、Cloudflare通过个人域名远程访问Docker容器?

Step-by-Step Guide to Remote Access with Traefik & Cloudflare

Great question! Let’s walk through exactly what you need to do to get your Home Assistant, Portainer, and Tautulli containers accessible via your custom subdomains. We’ll build on your existing docker-compose.yml and integrate Traefik as the reverse proxy with Cloudflare for SSL certificates and DNS management.

1. Prerequisites First

Before diving in, make sure you have these sorted:

  • A domain (e.g., example.com) managed by Cloudflare.
  • Your server’s public IP address (find this via curl ifconfig.me).
  • Docker and Docker Compose installed on your server.
  • Firewall rules allowing incoming traffic on ports 80 (HTTP) and 443 (HTTPS).

2. Configure Cloudflare

First, set up your subdomains and get the API token Traefik needs:

  • Go to your Cloudflare dashboard, navigate to your domain’s DNS section.
  • Create A records for each service:
    • ha.example.com → your server’s public IP
    • portainer.example.com → your server’s public IP
    • tautulli.example.com → your server’s public IP
  • Set the Proxy status for each record to "Proxied" (orange cloud) to leverage Cloudflare’s protection.
  • Next, create an API token:
    • Go to Cloudflare’s My Profile → API Tokens → Create Token.
    • Use the "Edit Zone DNS" template, restrict it to your domain, and copy the token (save this somewhere safe—you’ll need it for Traefik).

3. Update Your Docker Compose with Traefik

Add the Traefik service to your existing docker-compose.yml, and update each container with Traefik-specific labels. Here’s the complete snippet:

services:
  traefik:
    image: traefik:v2.10
    container_name: traefik
    restart: unless-stopped
    ports:
      - "80:80"
      - "443:443"
    volumes:
      - /var/run/docker.sock:/var/run/docker.sock:ro  # Traefik needs access to Docker socket
      - ./traefik-data:/acme  # Stores SSL certificates
    environment:
      - CF_API_EMAIL=your-cloudflare-email@example.com
      - CF_DNS_API_TOKEN=your-cloudflare-api-token
    command:
      - "--api.insecure=false"  # Disable insecure API access
      - "--providers.docker=true"
      - "--providers.docker.exposedbydefault=false"
      - "--entrypoints.web.address=:80"
      - "--entrypoints.websecure.address=:443"
      - "--entrypoints.web.http.redirections.entryPoint.to=websecure"
      - "--entrypoints.web.http.redirections.entryPoint.scheme=https"
      - "--certificatesresolvers.cloudflare.acme.dnschallenge=true"
      - "--certificatesresolvers.cloudflare.acme.dnschallenge.provider=cloudflare"
      - "--certificatesresolvers.cloudflare.acme.email=your-cloudflare-email@example.com"
      - "--certificatesresolvers.cloudflare.acme.storage=/acme/acme.json"
    networks:
      - traefik-network

  # Your existing Portainer service (updated with Traefik labels)
  portainer:
    image: portainer/portainer-ce:latest
    container_name: portainer
    restart: unless-stopped
    volumes:
      - /var/run/docker.sock:/var/run/docker.sock
      - ./portainer-data:/data
    labels:
      - "traefik.enable=true"
      - "traefik.http.routers.portainer.rule=Host(`portainer.example.com`)"
      - "traefik.http.routers.portainer.entrypoints=websecure"
      - "traefik.http.routers.portainer.tls.certresolver=cloudflare"
      - "traefik.http.services.portainer.loadbalancer.server.port=9000"
    networks:
      - traefik-network

  # Home Assistant service with Traefik labels
  homeassistant:
    image: homeassistant/home-assistant:stable
    container_name: homeassistant
    restart: unless-stopped
    volumes:
      - ./homeassistant-config:/config
      - /etc/localtime:/etc/localtime:ro
    labels:
      - "traefik.enable=true"
      - "traefik.http.routers.homeassistant.rule=Host(`ha.example.com`)"
      - "traefik.http.routers.homeassistant.entrypoints=websecure"
      - "traefik.http.routers.homeassistant.tls.certresolver=cloudflare"
      - "traefik.http.services.homeassistant.loadbalancer.server.port=8123"
    networks:
      - traefik-network

  # Tautulli service with Traefik labels
  tautulli:
    image: linuxserver/tautulli:latest
    container_name: tautulli
    restart: unless-stopped
    volumes:
      - ./tautulli-config:/config
      - ./plex-logs:/logs  # Update this path to your Plex logs directory
    environment:
      - PUID=1000  # Replace with your user ID
      - PGID=1000  # Replace with your group ID
      - TZ=America/New_York  # Replace with your timezone
    labels:
      - "traefik.enable=true"
      - "traefik.http.routers.tautulli.rule=Host(`tautulli.example.com`)"
      - "traefik.http.routers.tautulli.entrypoints=websecure"
      - "traefik.http.routers.tautulli.tls.certresolver=cloudflare"
      - "traefik.http.services.tautulli.loadbalancer.server.port=8181"
    networks:
      - traefik-network

# Shared network for Traefik and your containers
networks:
  traefik-network:
    external: false

Quick Notes for the Compose File:

  • Replace your-cloudflare-email@example.com and your-cloudflare-api-token with your actual Cloudflare details.
  • Adjust volume paths (like ./homeassistant-config or ./plex-logs) to match your server’s setup.
  • Update PUID/PGID and timezone for Tautulli to your system’s values.

4. Deploy the Updated Configuration

Once your docker-compose.yml is ready, run this command in the same directory to start everything:

docker-compose up -d

This will pull any missing images, create the shared network, and start all services in detached mode.

5. Verify Everything Works

  • Wait 1-2 minutes for Traefik to issue SSL certificates via Cloudflare.
  • Visit each subdomain in your browser:
    • https://portainer.example.com
    • https://ha.example.com
    • https://tautulli.example.com
  • You should see each service load over HTTPS with a valid SSL certificate (check the lock icon in your browser).

6. Optional Security Enhancements

  • Cloudflare Access: Add an extra layer of authentication before reaching your services.
  • Restrict IPs: Use Cloudflare’s firewall rules to allow only specific IP addresses to access your subdomains.
  • Disable Unused Ports: Ensure no unnecessary ports are exposed on your server.

内容的提问来源于stack exchange,提问作者TheTrepanier

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.26 10:10:44