【问题标题】:Traefik with docker-compose, LetsEncrypt, and multiple domainsTraefik 与 docker-compose、LetsEncrypt 和多个域
【发布时间】:2018-09-19 12:00:12
【问题描述】:

我正在尝试使用 traefik 作为反向代理,通过docker-compose 运行幻影图像。

我有两个域,sub.foo.combar.com。在调用docker-compose up -d 后,容器可以通过sub.foo.com:2386 访问,但不能通过bar.com 访问。我知道在ghost.service 中没有必要有ports 选项,但有它可以证明容器出现了。

这是我的配置:


traefik.toml

debug = false

logLevel = "ERROR"
defaultEntryPoints = ["https","http"]

[entryPoints]

[entryPoints.http]
address = ":80"
[entryPoints.http.redirect]
entryPoint = "https"

[entryPoints.https]
address = ":443"
  [entryPoints.https.tls]

[retry]

[docker]
endpoint = "unix:///var/run/docker.sock"
domain = "sub.foo.com"
watch = true
exposedbydefault = false

[acme]
email = "john.doe@example.com"
storage = "acme.json"
entryPoint = "https"
onHostRule = true
[acme.httpChallenge]
entryPoint = "http"

docker-compose.yml

version: "3.3"

services:
  db:
    image: mysql:5.7
    volumes:
      - db_data:/var/lib/mysql
    restart: always
    networks:
      - ghost
    environment:
      MYSQL_ROOT_PASSWORD: testing
      MYSQL_DATABASE: ghost
      MYSQL_USER: ghost
      MYSQL_PASSWORD: ghost
  ghost:
    depends_on:
      - db
    image: ghost:2.1.2-alpine
    ports:
      - "2368:2368"
    networks:
      - traefik
      - ghost
    volumes:
      - ghost_data:/var/lib/ghost/content
    environment:
      database__client: mysql
      database__connection__host: db
      database__connection__user: ghost
      database__connection__password: ghost
      database__connection__database: ghost
    labels:
      - "traefik.backend=ghost"
      - "traefik.docker.network=traefik"
      - "traefik.enable=true"
      - "traefik.frontend.rule=Host:bar.com"
      - "traefik.port=2368"
      - "traefik.protocol=http"

volumes:
  db_data: {}
  ghost_data: {}

networks:
  ghost: {}
  traefik:
    external: true

任何想法我做错了什么?我的 DNS 记录指向 sub.foo.combar.com。当我导航到bar.com 时,我最终得到:

<!DOCTYPE html>
<html><head>
<meta http-equiv="content-type" content="text/html; charset=UTF-8" />
<title>Access Denied</title>
<style type="text/css">body {margin:0;font-family:verdana,sans-serif;} h1 {margin:0;padding:12px 25px;background-color:#343434;color:#ddd} p {margin:12px 25px;} strong {color:#E0042D;}</style>
</head>
<body>
<h1>Access Denied</h1>
<p>
<strong>You are attempting to access a forbidden site.</strong><br/><br/>
Consult your system administrator for details.
</p>
</body>
</html>

这不是您的标准 traefik 错误。有什么东西没有约束力吗?

【问题讨论】:

    标签: docker docker-compose reverse-proxy traefik


    【解决方案1】:

    也许它被切断了,但你的 toml 中还需要以下内容:

    ...
    [acme]
    email = "john.doe@example.com"
    storage = "acme.json"
    entryPoint = "https"
    onHostRule = true
    [[acme.domains]]
      main = "bar.com"
    [acme.httpChallenge]
      entryPoint = "http"
    

    您的 docker-compose 可能缺少以下内容:

    labels:
      ....
      - "traefik.frontend.entryPoints=http,https"
    

    然而,该错误看起来与 treafik 无关。 treafik 是否暴露在您服务器上的 80 和 443 端口?

    【讨论】:

    • 我的浏览器上的entryPoints 和缓存清除修复了它,感谢您的帮助!
    猜你喜欢
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 2023-03-19
    • 2020-02-12
    • 1970-01-01
    • 1970-01-01
    相关资源
    最近更新 更多