我遵循了quick start guide ,并使用了基本的traefik.toml
:
traefik.toml
[entryPoints]
[entryPoints.web]
address = ":80"
[entryPoints.websecure]
address = ":443"
[api]
dashboard = true
insecure = true
[providers.docker]
docker-compose.yml
version: "3.7"
services:
traefik:
image: traefik
ports:
- "8080:8080"
- "80:80"
- "443:443"
volumes:
- /var/run/docker.sock:/var/run/docker.sock
- "$PWD/traefik.toml:/etc/traefik/traefik.toml"
whoami:
image: containous/whoami
labels:
- "traefik.http.routers.whoami.rule=Host(`whoami.docker.localhost`)"
HTTP端点的调用:
$ curl -H Host:whoami.docker.localhost http://127.0.0.1
Hostname: aa6bfee60f2d
IP: 127.0.0.1
IP: 172.29.0.4
调用HTTPS端点:
curl --insecure -H Host:whoami.docker.localhost https://127.0.0.1
404 page not found
我的问题:它返回 404页面未找到,而不是HTTP端点执行的whoami内容。
如何在Traefik v2中正确启用 HTTPS ?
可以在此处找到完整的(不用担心)MWE:https://github.com/boldt/traefik-v2-mwe/
答案 0 :(得分:0)
这是一个工作示例:
<块引用>后端服务以 HTTP 模式运行。这意味着此配置不是完整的 HTTPS。
<块引用>端口 8082 用于指标。如果您没有指标,则可以将其删除。从 traefik.yml
和 static.yml
中删除配置。
通过您的服务端口更改端口 traefik.http.services.my-service.loadbalancer.server.port=8484
。
traefil.yml
version: "3.7"
services:
traefik:
image: traefik:v2.4.6
command: --providers.docker
restart: always
container_name: traefik
networks:
- web
- internal
ports:
- 80:80
- 443:443
- 28080:8080
- 8082:8082
volumes:
- /var/run/docker.sock:/var/run/docker.sock:ro
- ./traefik/static.yml:/etc/traefik/traefik.yml:ro
- ./traefik/dynamic.yml:/etc/traefik/dynamic/dynamic.yaml
- ./certs/localhost.crt:/etc/traefik/certs/traefik.crt:ro
- ./certs/localhost.key:/etc/traefik/certs/traefik.key:ro
static.yml
log:
level: DEBUG
entryPoints:
web:
address: ":80"
http:
redirections:
entryPoint:
to: web-secure
web-secure:
address: ":443"
metrics:
address: ":8082"
providers:
docker:
watch: true
exposedbydefault: false
file:
directory: /etc/traefik/dynamic
watch: true
filename: dynamic.yml
api:
dashboard: true
insecure: true
metrics:
prometheus:
buckets:
- 0.1
- 0.3
- 1.2
- 5.0
addEntryPointsLabels: true
addServicesLabels: true
entryPoint: metrics
dynamic.yml
tls:
certificates:
- certFile: "/etc/traefik/certs/traefik.crt"
keyFile: "/etc/traefik/certs/traefik.key"
stores:
- default
stores:
default:
defaultCertificate:
certFile: "/etc/traefik/certs/traefik.crt"
keyFile: "/etc/traefik/certs/traefik.key"
my-service.yml
version: "3.7"
services:
my-service:
image: my-service
networks:
- internal
volumes:
- ./certs/cacerts:/opt/java/openjdk/jre/lib/security/cacerts:ro
- ./certs/keystore.p12:/opt/java/openjdk/jre/lib/security/keystore.p12:ro
labels:
- "traefik.enable=true"
- "traefik.http.routers.my-service.rule=Host(`my-service.localhost`)"
- "traefik.http.routers.my-service.entrypoints=web,web-secure"
- "traefik.http.routers.my-service.tls=true"
- "traefik.http.routers.my-service.service=my-service"
- "traefik.http.middlewares.my-service.redirectscheme.scheme=https"
- "traefik.http.middlewares.my-service.redirectscheme.permanent=true"
- "traefik.http.services.my-service.loadbalancer.server.port=8284"