You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Traefik配置:实现服务本地IP与外部HTTPS双重访问

Can I Have Both External HTTPS Access (via Domain) and Local HTTP Access with Traefik?

Absolutely, this setup is totally doable! You can have both external HTTPS access via your domain and local HTTP access without any conflicts—no need to choose one over the other. There are two common approaches to implement this, depending on whether you want local traffic to go through Traefik or directly to your service.

Option 1: Direct Local Access (Bypass Traefik)

This is the simplest method if you don’t need Traefik to handle local requests. Just expose your service’s port directly on your local network in its docker-compose configuration:

For example, if your service (like Home Assistant using port 8123) is defined in your docker-compose.yml, add a ports section to map its container port to your server’s local IP:

services:
  # ... your existing reverse-proxy service ...

  your-service:
    # ... existing service config ...
    ports:
      - "192.168.0.5:8123:8123" # Map local IP port to container port
    networks:
      - proxy

Once you update this, you’ll be able to access the service locally via http://192.168.0.5:8123 or http://my-server.local:8123 (assuming my-server.local resolves to your server’s local IP), while external traffic still routes through Traefik’s HTTPS proxy.

Option 2: Route Local Traffic Through Traefik (Unified Access)

If you prefer all traffic (local and external) to go through Traefik for consistent routing and rules, follow these steps:

Step 1: Update Traefik’s Entrypoints

Modify your reverse-proxy service to define two entrypoints: one for local HTTP traffic, and one for external HTTPS traffic. Here’s how to adjust the command and ports sections:

services:
  reverse-proxy:
    container_name: ReverseProxy
    image: traefik:v1.7 # Specify version to avoid unexpected upgrades
    restart: always
    command:
      --web # Enable Traefik's web dashboard (default port 8080)
      --docker # Enable Docker integration
      --docker.network=proxy # Use your external proxy network
      --docker.exposedbydefault=false # Disable auto-exposing all containers
      # Define entrypoints
      --entryPoints='Name:web Address::80' # Local HTTP entrypoint
      --entryPoints='Name:websecure Address::443 TLS' # External HTTPS entrypoint
      # Let's Encrypt config (for HTTPS certificates)
      --acme.email=your-email@example.com
      --acme.storage=/etc/traefik/acme.json
      --acme.entryPoint=websecure
      --acme.onhostrule=true
    ports:
      - "80:80" # Expose HTTP port for local access
      - "443:443" # Expose HTTPS port for external access
      - "8080:8080" # Traefik dashboard port
    volumes:
      - /var/run/docker.sock:/var/run/docker.sock # Required for Docker integration
      - ./traefik/acme.json:/etc/traefik/acme.json # Store SSL certificates
    networks:
      - proxy

Note: If you’re using Traefik v2+, the command structure changes slightly. For v2, replace the command section with:

command:
  --api.insecure=true
  --providers.docker=true
  --providers.docker.network=proxy
  --providers.docker.exposedbydefault=false
  --entrypoints.web.address=:80
  --entrypoints.websecure.address=:443
  --certificatesresolvers.myresolver.acme.email=your-email@example.com
  --certificatesresolvers.myresolver.acme.storage=/etc/traefik/acme.json
  --certificatesresolvers.myresolver.acme.httpchallenge.entrypoint=web

Step 2: Configure Your Service for Dual Access

Add Traefik labels to your service to define both the external HTTPS route and the local HTTP route. Here’s an example for a service using port 8123:

services:
  # ... your reverse-proxy service ...

  your-service:
    container_name: your-service
    image: your-service-image:latest
    restart: always
    volumes:
      - ./your-service/config:/config # Adjust to your service's needs
    networks:
      - proxy
    labels:
      - traefik.enable=true # Enable Traefik for this service
      - traefik.backend=your-service # Name the backend
      - traefik.port=8123 # Port the service listens on internally
      # External HTTPS route
      - traefik.frontend.rule=Host:MY-DOMAIN.COM
      - traefik.entrypoints=websecure
      # Local HTTP route (matches both local domain and IP)
      - traefik.frontend.rule=Host:my-server.local;Host:192.168.0.5
      - traefik.frontend.entryPoints=web

For Traefik v2+, replace the labels with:

labels:
  - traefik.enable=true
  # External HTTPS router
  - traefik.http.routers.your-service-secure.rule=Host(`MY-DOMAIN.COM`)
  - traefik.http.routers.your-service-secure.entrypoints=websecure
  - traefik.http.routers.your-service-secure.tls.certresolver=myresolver
  # Local HTTP router
  - traefik.http.routers.your-service-local.rule=Host(`my-server.local`) || Host(`192.168.0.5`)
  - traefik.http.routers.your-service-local.entrypoints=web
  # Service definition
  - traefik.http.services.your-service.loadbalancer.server.port=8123

Key Notes

  • DNS Resolution: Ensure my-server.local resolves to your server’s local IP. You can set this up via your local router’s DNS or add an entry to your device’s hosts file.
  • Secure Certificates: For the acme.json file, set its permissions to 600 with chmod 600 ./traefik/acme.json—Traefik requires this to write SSL certificates securely.
  • Port Forwarding: On your router, only forward port 443 to your server’s port 443. This prevents external access to the HTTP entrypoint, keeping local HTTP access restricted to your network.

内容的提问来源于stack exchange,提问作者Jono Hunt

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.27 04:26:47