使用Traefik作为Ingress Controller配置Let's Encrypt时出现404错误
Hey there, let's figure out why you're getting a 404 when accessing your Traefik Web UI over HTTPS. I’ve worked through similar issues with Traefik on Kubernetes before, so let’s break this down step by step.
From your setup description, the HTTP-to-HTTPS redirect is working, so your entry point configuration is solid. The 404 almost always stems from one of these issues:
- Missing or incorrect routing rules for the Traefik Dashboard (it requires specific path matches, not just the domain)
- The Dashboard route isn’t properly linked to your Let’s Encrypt certificate resolver
- The Traefik service’s API port (default 9000) isn’t exposed in your Kubernetes deployment
- You’re accessing the root domain (
https://traefik.mydomain.de) instead of the Dashboard path (/dashboard/)
First, let’s update your traefik.yml to ensure the API/Dashboard is enabled correctly, then add the necessary Kubernetes routing resources.
Updated traefik.yml Static Configuration
global: checkNewVersion: true sendAnonymousUsage: false entryPoints: web: address: ":80" http: redirections: entryPoint: to: websecure scheme: https permanent: true websecure: address: ":443" providers: kubernetesIngress: enabled: true kubernetesCRD: enabled: true # Required if using IngressRoute (recommended for Traefik-specific features) certificatesResolvers: letsencrypt: acme: email: your-email@mydomain.de # Replace with your valid email for Let's Encrypt storage: /data/acme.json httpChallenge: entryPoint: web # Uses HTTP-01 challenge for certificate issuance api: dashboard: true insecure: false # Disable insecure mode since we're using HTTPS log: level: DEBUG # Keep debug logs for troubleshooting
Kubernetes IngressRoute for Traefik Dashboard (Recommended)
Create this resource in the same namespace where Traefik is deployed (usually kube-system):
apiVersion: traefik.containo.us/v1alpha1 kind: IngressRoute metadata: name: traefik-dashboard namespace: kube-system spec: entryPoints: - websecure routes: - match: Host(`traefik.mydomain.de`) && (PathPrefix(`/dashboard`) || PathPrefix(`/api`)) kind: Rule services: - name: traefik # Name of your Traefik service in Kubernetes port: 9000 # Default API/Dashboard port middlewares: - name: dashboard-auth # Optional but highly recommended to add basic auth tls: certResolver: letsencrypt # Links this route to your Let's Encrypt resolver
Alternative: Traditional Kubernetes Ingress Resource
If you prefer using standard Ingress instead of CRDs:
apiVersion: networking.k8s.io/v1 kind: Ingress metadata: name: traefik-dashboard namespace: kube-system annotations: traefik.ingress.kubernetes.io/router.entrypoints: websecure traefik.ingress.kubernetes.io/router.tls: "true" traefik.ingress.kubernetes.io/router.tls.certresolver: letsencrypt spec: rules: - host: traefik.mydomain.de http: paths: - path: /dashboard pathType: Prefix backend: service: name: traefik port: number: 9000 - path: /api pathType: Prefix backend: service: name: traefik port: number: 9000 tls: - hosts: - traefik.mydomain.de
Critical Deployment Check
Ensure your Traefik Deployment exposes the API port (9000) in its container ports:
# Excerpt from your Traefik Deployment ports: - name: web containerPort: 80 - name: websecure containerPort: 443 - name: api containerPort: 9000 # This must be present for Dashboard access
Verify Certificate Issuance: Check if Let’s Encrypt issued a certificate successfully:
kubectl logs -n kube-system <your-traefik-pod-name> | grep "acme"Look for lines like
Successfully authorized certificateto confirm no issues with the ACME challenge.Check Routing Resources: Ensure your IngressRoute/Ingress is recognized by Kubernetes:
# For IngressRoute kubectl get ingressroute -n kube-system # For traditional Ingress kubectl get ingress -n kube-systemThe status should show
Readyor no errors.Access the Correct Path: Visit
https://traefik.mydomain.de/dashboard/(note the trailing slash!) — the root domain doesn’t map to anything by default, so accessing it directly will return a 404.
内容的提问来源于stack exchange,提问作者Alexander Schmidt

