Why is Traefik ignoring my wildcard TLS domain in Docker Compose?

0
0
Asked By VelvetComet42 On

I'm configuring Traefik through Docker Compose and can set the main TLS domain successfully, but the wildcard subject alternative name is not being recognized. I've tried different quoting styles without success:

```yaml
command:
- --entrypoints.websecure.http.tls.domains[0].main=${MY_DOMAIN:?err}
- --entrypoints.websecure.http.tls.domains[0].sans=*.${MY_DOMAIN:?err}
```

The same domain configuration works when it is hard-coded in my static configuration file. What is the correct way to configure the wildcard domain?

2 Answers

Answered By CopperLynx88 On

For a Docker provider setup, define the domains on the router instead. Compose can expand the environment variable in the labels, for example:

```yaml
labels:
- traefik.http.routers.myapp.tls.domains[0].main=${MY_DOMAIN}
- traefik.http.routers.myapp.tls.domains[0].sans=*.${MY_DOMAIN}
```

The important issue isn’t the quoting—the command flags are being ignored because Traefik is already reading its static configuration from the file.

VelvetComet42 -

Got it, that explains why changing the quoting had no effect. I’ll use the router labels or move the whole configuration into one static source.

Answered By MossyAtlas7 On

Traefik only loads static configuration from one source. If you’re using a complete static configuration file such as `traefik.yml`, the `command` options in Compose won’t be applied, even if only one section is duplicated or changed. You’ll need to put the settings in the static file or move the TLS domain configuration to the router labels.

VelvetComet42 -

So the static file and the Compose command options can’t be combined? I’ll move the domain settings into the router labels and test that.

Related Questions

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.