Docker-compose with Let’s Encrypt: TLS Challenge

This guide aims to demonstrate how to create a certificate with the Let’s Encrypt TLS challenge to use https on a simple service exposed with Traefik.
Please also read the basic example for details on how to expose such a service.

Prerequisite

For the TLS challenge you will need:

  • A publicly accessible host allowing connections on port 443 with docker & docker-compose installed.
  • A DNS record with the domain you want to expose pointing to this host.

Setup

  • Create a docker-compose.yml on your remote server with the following content:
  1. version: "3.3"
  2. services:
  3. traefik:
  4. image: "traefik:v3.3"
  5. container_name: "traefik"
  6. command:
  7. #- "--log.level=DEBUG"
  8. - "--api.insecure=true"
  9. - "--providers.docker=true"
  10. - "--providers.docker.exposedbydefault=false"
  11. - "--entryPoints.websecure.address=:443"
  12. - "--certificatesresolvers.myresolver.acme.tlschallenge=true"
  13. #- "--certificatesresolvers.myresolver.acme.caserver=https://acme-staging-v02.api.letsencrypt.org/directory"
  14. - "--certificatesresolvers.myresolver.acme.email=postmaster@example.com"
  15. - "--certificatesresolvers.myresolver.acme.storage=/letsencrypt/acme.json"
  16. ports:
  17. - "443:443"
  18. - "8080:8080"
  19. volumes:
  20. - "./letsencrypt:/letsencrypt"
  21. - "/var/run/docker.sock:/var/run/docker.sock:ro"
  22. whoami:
  23. image: "traefik/whoami"
  24. container_name: "simple-service"
  25. labels:
  26. - "traefik.enable=true"
  27. - "traefik.http.routers.whoami.rule=Host(`whoami.example.com`)"
  28. - "traefik.http.routers.whoami.entrypoints=websecure"
  29. - "traefik.http.routers.whoami.tls.certresolver=myresolver"
  • Replace [[email protected]](https://doc.traefik.io/cdn-cgi/l/email-protection) by your own email within the certificatesresolvers.myresolver.acme.email command line argument of the traefik service.
  • Replace whoami.example.com by your own domain within the traefik.http.routers.whoami.rule label of the whoami service.
  • Optionally uncomment the following lines if you want to test/debug:

    1. #- "--log.level=DEBUG"
    2. #- "--certificatesresolvers.myresolver.acme.caserver=https://acme-staging-v02.api.letsencrypt.org/directory"
  • Run docker-compose up -d within the folder where you created the previous file.

  • Wait a bit and visit https://your_own_domain to confirm everything went fine.

Note

If you uncommented the acme.caserver line, you will get an SSL error, but if you display the certificate and see it was emitted by Fake LE Intermediate X1 then it means all is good. (It is the staging environment intermediate certificate used by Let’s Encrypt). You can now safely comment the acme.caserver line, remove the letsencrypt/acme.json file and restart Traefik to issue a valid certificate.

Explanation

What changed between the basic example:

  • We replace the web entry point by one for the https traffic:
  1. command:
  2. # Traefik will listen to incoming request on the port 443 (https)
  3. - "--entryPoints.websecure.address=:443"
  4. ports:
  5. - "443:443"
  • We configure the TLS Let’s Encrypt challenge:
  1. command:
  2. # Enable a tls challenge named "myresolver"
  3. - "--certificatesresolvers.myresolver.acme.tlschallenge=true"
  • We add a volume to store our certificates:
  1. volumes:
  2. # Create a letsencrypt dir within the folder where the docker-compose file is
  3. - "./letsencrypt:/letsencrypt"
  4. command:
  5. # Tell to store the certificate on a path under our volume
  6. - "--certificatesresolvers.myresolver.acme.storage=/letsencrypt/acme.json"
  • We configure the whoami service to tell Traefik to use the certificate resolver named myresolver we just configured:
  1. labels:
  2. # Uses the Host rule to define which certificate to issue
  3. - "traefik.http.routers.whoami.tls.certresolver=myresolver"

Using Traefik OSS in Production?

If you are using Traefik at work, consider adding enterprise-grade API gateway capabilities or commercial support for Traefik OSS.

Adding API Gateway capabilities to Traefik OSS is fast and seamless. There’s no rip and replace and all configurations remain intact. See it in action via this short video.