I'm configuring Traefik through Docker Compose. The main domain is recognized, but the wildcard SAN is not. I've tried quoting the command values in several ways without success:
```yaml
command:
- --entrypoints.websecure.http.tls.domains[0].main=${MY_DOMAIN:?err}
- --entrypoints.websecure.http.tls.domains[0].sans=*.${MY_DOMAIN:?err}
```
The same TLS domain configuration works when it is hard-coded in my static configuration. What is the correct way to configure this when using Compose?
2 Answers
An easy alternative is to configure the certificate domains on the router labels, which are dynamic configuration and can use Compose variable substitution. For example:
```yaml
labels:
- traefik.http.routers.myapp.tls.domains[0].main=${MY_DOMAIN}
- traefik.http.routers.myapp.tls.domains[0].sans=*.${MY_DOMAIN}
```
Remove or comment out the conflicting static command settings, then let the router labels define the main and wildcard domains.
Traefik only loads static configuration from one source. If you are using a complete `traefik.yml` static configuration file, the command-line flags in Compose are ignored, even if only part of the configuration is duplicated there. You need to choose either the static file or command-line options for the static settings.
Got it—I was using a complete static configuration file, not just a separate domains block. That explains why the command options had no effect.

Thanks, I’ll try moving the domain settings to the router labels and keep the static configuration in one place.