Sharing Acme configuration for multiple Traefik services

Viewed 196

I have a server running Docker containers with Traefik. Let's say the machine's hostname is machine1.example.com, and each service runs as a subdomain, e.g. srv1.machine1.example.com, srv2.machine1.example.com, srv3.machine1.example.com....

I want to have LetsEncrypt generate a Wildcard certificate for *.machine1.example.com and use it for all of the services instead of generating a separate certificate for each service.

The annoyance is that I have to put the configuration lines into every single service's labels:

labels:
  - traefik.http.routers.srv1.rule=Host(`srv1.machine1.example.com`)
  - traefik.http.routers.srv1.tls=true
  - traefik.http.routers.srv1.tls.certresolver=myresolver
  - traefik.http.routers.srv1.tls.domains[0].main=machine1.example.com
  - traefik.http.routers.srv1.tls.domains[0].sans=*.machine1.example.com

labels:
  - traefik.http.routers.srv2.rule=Host(`srv2.machine1.example.com`)
  - traefik.http.routers.srv2.tls=true
  - traefik.http.routers.srv2.tls.certresolver=myresolver
  - traefik.http.routers.srv2.tls.domains[0].main=machine1.example.com
  - traefik.http.routers.srv2.tls.domains[0].sans=*.machine1.example.com

# etc.

This gets to be a lot of seemingly-needless boilerplate.

I tried work around it (in a way that is still ugly and annoying, but less so) by using the templating feature in the file provider like this:

[http]
  [http.routers]

  {{ range $i, $e := list "srv1" "srv2 }}
    [http.routers."{{ $e }}".tls]
      certResolver = "letsencrypt"
      [[http.routers."{{ $e }}".tls.domains]]
        main = "machine1.example.com"
        sans = ["*.machine1.example.com"]
  {{ end }}

That did not work because the routers created here are srv1@file, srv2@file instead of srv1@docker, srv2@docker which are created by the docker-compose configuration.

Is there any way to specify this configuration only once and have it apply to multiple services?

0 Answers
Related