如何借助Traefik、Cloudflare通过个人域名远程访问Docker容器?
Great question! Let’s walk through exactly what you need to do to get your Home Assistant, Portainer, and Tautulli containers accessible via your custom subdomains. We’ll build on your existing docker-compose.yml and integrate Traefik as the reverse proxy with Cloudflare for SSL certificates and DNS management.
1. Prerequisites First
Before diving in, make sure you have these sorted:
- A domain (e.g.,
example.com) managed by Cloudflare. - Your server’s public IP address (find this via
curl ifconfig.me). - Docker and Docker Compose installed on your server.
- Firewall rules allowing incoming traffic on ports 80 (HTTP) and 443 (HTTPS).
2. Configure Cloudflare
First, set up your subdomains and get the API token Traefik needs:
- Go to your Cloudflare dashboard, navigate to your domain’s DNS section.
- Create A records for each service:
ha.example.com→ your server’s public IPportainer.example.com→ your server’s public IPtautulli.example.com→ your server’s public IP
- Set the Proxy status for each record to "Proxied" (orange cloud) to leverage Cloudflare’s protection.
- Next, create an API token:
- Go to Cloudflare’s My Profile → API Tokens → Create Token.
- Use the "Edit Zone DNS" template, restrict it to your domain, and copy the token (save this somewhere safe—you’ll need it for Traefik).
3. Update Your Docker Compose with Traefik
Add the Traefik service to your existing docker-compose.yml, and update each container with Traefik-specific labels. Here’s the complete snippet:
services: traefik: image: traefik:v2.10 container_name: traefik restart: unless-stopped ports: - "80:80" - "443:443" volumes: - /var/run/docker.sock:/var/run/docker.sock:ro # Traefik needs access to Docker socket - ./traefik-data:/acme # Stores SSL certificates environment: - CF_API_EMAIL=your-cloudflare-email@example.com - CF_DNS_API_TOKEN=your-cloudflare-api-token command: - "--api.insecure=false" # Disable insecure API access - "--providers.docker=true" - "--providers.docker.exposedbydefault=false" - "--entrypoints.web.address=:80" - "--entrypoints.websecure.address=:443" - "--entrypoints.web.http.redirections.entryPoint.to=websecure" - "--entrypoints.web.http.redirections.entryPoint.scheme=https" - "--certificatesresolvers.cloudflare.acme.dnschallenge=true" - "--certificatesresolvers.cloudflare.acme.dnschallenge.provider=cloudflare" - "--certificatesresolvers.cloudflare.acme.email=your-cloudflare-email@example.com" - "--certificatesresolvers.cloudflare.acme.storage=/acme/acme.json" networks: - traefik-network # Your existing Portainer service (updated with Traefik labels) portainer: image: portainer/portainer-ce:latest container_name: portainer restart: unless-stopped volumes: - /var/run/docker.sock:/var/run/docker.sock - ./portainer-data:/data labels: - "traefik.enable=true" - "traefik.http.routers.portainer.rule=Host(`portainer.example.com`)" - "traefik.http.routers.portainer.entrypoints=websecure" - "traefik.http.routers.portainer.tls.certresolver=cloudflare" - "traefik.http.services.portainer.loadbalancer.server.port=9000" networks: - traefik-network # Home Assistant service with Traefik labels homeassistant: image: homeassistant/home-assistant:stable container_name: homeassistant restart: unless-stopped volumes: - ./homeassistant-config:/config - /etc/localtime:/etc/localtime:ro labels: - "traefik.enable=true" - "traefik.http.routers.homeassistant.rule=Host(`ha.example.com`)" - "traefik.http.routers.homeassistant.entrypoints=websecure" - "traefik.http.routers.homeassistant.tls.certresolver=cloudflare" - "traefik.http.services.homeassistant.loadbalancer.server.port=8123" networks: - traefik-network # Tautulli service with Traefik labels tautulli: image: linuxserver/tautulli:latest container_name: tautulli restart: unless-stopped volumes: - ./tautulli-config:/config - ./plex-logs:/logs # Update this path to your Plex logs directory environment: - PUID=1000 # Replace with your user ID - PGID=1000 # Replace with your group ID - TZ=America/New_York # Replace with your timezone labels: - "traefik.enable=true" - "traefik.http.routers.tautulli.rule=Host(`tautulli.example.com`)" - "traefik.http.routers.tautulli.entrypoints=websecure" - "traefik.http.routers.tautulli.tls.certresolver=cloudflare" - "traefik.http.services.tautulli.loadbalancer.server.port=8181" networks: - traefik-network # Shared network for Traefik and your containers networks: traefik-network: external: false
Quick Notes for the Compose File:
- Replace
your-cloudflare-email@example.comandyour-cloudflare-api-tokenwith your actual Cloudflare details. - Adjust volume paths (like
./homeassistant-configor./plex-logs) to match your server’s setup. - Update PUID/PGID and timezone for Tautulli to your system’s values.
4. Deploy the Updated Configuration
Once your docker-compose.yml is ready, run this command in the same directory to start everything:
docker-compose up -d
This will pull any missing images, create the shared network, and start all services in detached mode.
5. Verify Everything Works
- Wait 1-2 minutes for Traefik to issue SSL certificates via Cloudflare.
- Visit each subdomain in your browser:
https://portainer.example.comhttps://ha.example.comhttps://tautulli.example.com
- You should see each service load over HTTPS with a valid SSL certificate (check the lock icon in your browser).
6. Optional Security Enhancements
- Cloudflare Access: Add an extra layer of authentication before reaching your services.
- Restrict IPs: Use Cloudflare’s firewall rules to allow only specific IP addresses to access your subdomains.
- Disable Unused Ports: Ensure no unnecessary ports are exposed on your server.
内容的提问来源于stack exchange,提问作者TheTrepanier

