在Traefik中配置完整SSL证书链的可行性及实现方法
Absolutely! Traefik v1.6.1 does support configuring a full SSL certificate chain for your wildcard *.mydomain.com certificate, and it works seamlessly with Docker Swarm and Consul as your service discovery backend. Let's break down exactly how to set this up:
First, make sure you have your certificate assets organized correctly:
- Combine your wildcard server certificate (e.g.,
cert.pem) and all intermediate CA certificates into a single file namedfullchain.pem. Order matters: place your server certificate first, followed by each intermediate CA certificate in sequence (no extra blank lines or unrelated content). - Keep your private key file (e.g.,
privkey.pem) separate, and ensure it’s not password-protected—Traefik v1.6 doesn’t support encrypted private keys.
Since you’re using Docker Swarm, Docker Secrets are the safest way to manage sensitive certificate files (they’re encrypted at rest and only accessible to authorized services):
# Create secrets for your full chain and private key docker secret create traefik_wildcard_cert fullchain.pem docker secret create traefik_wildcard_key privkey.pem
Modify your Traefik docker-compose stack to include the SSL configuration and Consul integration. Here’s a complete example:
version: '3.3' services: traefik: image: traefik:v1.6.1 command: - "--api" - "--docker" - "--docker.swarmmode" - "--docker.domain=mydomain.com" - "--docker.watch" - "--consul" - "--consul.endpoint=consul:8500" # Adjust to your Consul service address - "--consul.watch" - "--entrypoints=Name:http Address::80 Redirect.EntryPoint:https" - "--entrypoints=Name:https Address::443 TLS" - "--defaultentrypoints=http,https" - "--acme=false" # Disable ACME since we're using a custom wildcard cert - "--tls=true" - "--tls.certificates=/run/secrets/traefik_wildcard_cert" - "--tls.key=/run/secrets/traefik_wildcard_key" ports: - "80:80" - "443:443" - "8080:8080" # Traefik API dashboard port secrets: - traefik_wildcard_cert - traefik_wildcard_key deploy: placement: constraints: - node.role == manager networks: - traefik-net - consul-net # Connect to your Consul network secrets: traefik_wildcard_cert: external: true traefik_wildcard_key: external: true networks: traefik-net: external: true consul-net: external: true
Key notes about this config:
--tls.certificatesand--tls.keypoint to the secret files automatically mounted by Swarm at/run/secrets/- The
httpentrypoint redirects all traffic tohttpsfor seamless encryption - Consul integration ensures Traefik automatically discovers services registered in your Consul cluster
For each microservice (like microservice2.mydomain.com), add Traefik labels to its Swarm service definition to route traffic correctly:
services: microservice2: image: your-microservice-image:latest deploy: labels: - "traefik.enable=true" - "traefik.port=80" # Match your microservice's internal port - "traefik.frontend.rule=Host:microservice2.mydomain.com" - "traefik.docker.network=traefik-net" - "traefik.backend.loadbalancer.swarm=true" networks: - traefik-net
Traefik will automatically apply your wildcard certificate to this subdomain since microservice2.mydomain.com matches *.mydomain.com.
To confirm your full chain is working correctly, run this openssl command from any machine with network access to your cluster:
openssl s_client -connect microservice2.mydomain.com:443 -showcerts
Check the output to ensure your server certificate and all intermediate CA certificates are listed in the chain. You can also verify in a browser by visiting https://microservice2.mydomain.com and inspecting the certificate details.
内容的提问来源于stack exchange,提问作者Tharcis Dal Moro

