Traefik配置:实现服务本地IP与外部HTTPS双重访问
Absolutely, this setup is totally doable! You can have both external HTTPS access via your domain and local HTTP access without any conflicts—no need to choose one over the other. There are two common approaches to implement this, depending on whether you want local traffic to go through Traefik or directly to your service.
Option 1: Direct Local Access (Bypass Traefik)
This is the simplest method if you don’t need Traefik to handle local requests. Just expose your service’s port directly on your local network in its docker-compose configuration:
For example, if your service (like Home Assistant using port 8123) is defined in your docker-compose.yml, add a ports section to map its container port to your server’s local IP:
services: # ... your existing reverse-proxy service ... your-service: # ... existing service config ... ports: - "192.168.0.5:8123:8123" # Map local IP port to container port networks: - proxy
Once you update this, you’ll be able to access the service locally via http://192.168.0.5:8123 or http://my-server.local:8123 (assuming my-server.local resolves to your server’s local IP), while external traffic still routes through Traefik’s HTTPS proxy.
Option 2: Route Local Traffic Through Traefik (Unified Access)
If you prefer all traffic (local and external) to go through Traefik for consistent routing and rules, follow these steps:
Step 1: Update Traefik’s Entrypoints
Modify your reverse-proxy service to define two entrypoints: one for local HTTP traffic, and one for external HTTPS traffic. Here’s how to adjust the command and ports sections:
services: reverse-proxy: container_name: ReverseProxy image: traefik:v1.7 # Specify version to avoid unexpected upgrades restart: always command: --web # Enable Traefik's web dashboard (default port 8080) --docker # Enable Docker integration --docker.network=proxy # Use your external proxy network --docker.exposedbydefault=false # Disable auto-exposing all containers # Define entrypoints --entryPoints='Name:web Address::80' # Local HTTP entrypoint --entryPoints='Name:websecure Address::443 TLS' # External HTTPS entrypoint # Let's Encrypt config (for HTTPS certificates) --acme.email=your-email@example.com --acme.storage=/etc/traefik/acme.json --acme.entryPoint=websecure --acme.onhostrule=true ports: - "80:80" # Expose HTTP port for local access - "443:443" # Expose HTTPS port for external access - "8080:8080" # Traefik dashboard port volumes: - /var/run/docker.sock:/var/run/docker.sock # Required for Docker integration - ./traefik/acme.json:/etc/traefik/acme.json # Store SSL certificates networks: - proxy
Note: If you’re using Traefik v2+, the command structure changes slightly. For v2, replace the
commandsection with:command: --api.insecure=true --providers.docker=true --providers.docker.network=proxy --providers.docker.exposedbydefault=false --entrypoints.web.address=:80 --entrypoints.websecure.address=:443 --certificatesresolvers.myresolver.acme.email=your-email@example.com --certificatesresolvers.myresolver.acme.storage=/etc/traefik/acme.json --certificatesresolvers.myresolver.acme.httpchallenge.entrypoint=web
Step 2: Configure Your Service for Dual Access
Add Traefik labels to your service to define both the external HTTPS route and the local HTTP route. Here’s an example for a service using port 8123:
services: # ... your reverse-proxy service ... your-service: container_name: your-service image: your-service-image:latest restart: always volumes: - ./your-service/config:/config # Adjust to your service's needs networks: - proxy labels: - traefik.enable=true # Enable Traefik for this service - traefik.backend=your-service # Name the backend - traefik.port=8123 # Port the service listens on internally # External HTTPS route - traefik.frontend.rule=Host:MY-DOMAIN.COM - traefik.entrypoints=websecure # Local HTTP route (matches both local domain and IP) - traefik.frontend.rule=Host:my-server.local;Host:192.168.0.5 - traefik.frontend.entryPoints=web
For Traefik v2+, replace the labels with:
labels: - traefik.enable=true # External HTTPS router - traefik.http.routers.your-service-secure.rule=Host(`MY-DOMAIN.COM`) - traefik.http.routers.your-service-secure.entrypoints=websecure - traefik.http.routers.your-service-secure.tls.certresolver=myresolver # Local HTTP router - traefik.http.routers.your-service-local.rule=Host(`my-server.local`) || Host(`192.168.0.5`) - traefik.http.routers.your-service-local.entrypoints=web # Service definition - traefik.http.services.your-service.loadbalancer.server.port=8123
Key Notes
- DNS Resolution: Ensure
my-server.localresolves to your server’s local IP. You can set this up via your local router’s DNS or add an entry to your device’shostsfile. - Secure Certificates: For the
acme.jsonfile, set its permissions to600withchmod 600 ./traefik/acme.json—Traefik requires this to write SSL certificates securely. - Port Forwarding: On your router, only forward port 443 to your server’s port 443. This prevents external access to the HTTP entrypoint, keeping local HTTP access restricted to your network.
内容的提问来源于stack exchange,提问作者Jono Hunt

