How to redirect from http to https using middleware in treafik?

Viewed 852

I am testing treafik to set it up for exposing my docker containers with SSL.

I seams to mostly work but I am having some issues http to https redirect. I have middleware that shows up in the dashboard as successful but when I go http option of the address I get 404

enter image description here

Here is my docker-compose.yml for traefik

version: "3.3"

services:
  traefik:
    image: traefik:v2.5
    restart: always
    container_name: traefik
    ports:
      - "80:80" # <== http
      - "8080:8080" # <== :8080 is where the dashboard runs on
      - "443:443" # <== https
    command:
      - --api.insecure=false # <== Enabling insecure api, NOT RECOMMENDED FOR PRODUCTION
      - --api.dashboard=true # <== Enabling the dashboard to view services, middlewares, routers, etc.
      - --api.debug=true # <== Enabling additional endpoints for debugging and profiling
      - --log.level=DEBUG # <== Setting the level of the logs from traefik
      - --providers.docker=true # <== Enabling docker as the provider for traefik
      - --providers.docker.exposedbydefault=false # <== Don't expose every container to traefik
      - --providers.file.filename=/config/dynamic.yaml # <== Referring to a dynamic configuration file
      - --providers.docker.network=web # <== Operate on the docker network named web
      - --entrypoints.web.address=:80 # <== Defining an entrypoint for port :80 named web
      - --entrypoints.web.http.redirections.entryPoint.to=web-secure
      - --entrypoints.web.http.redirections.entryPoint.scheme=https
      - --entrypoints.web.http.redirections.entrypoint.permanent=true
      - --entrypoints.web-secured.address=:443 # <== Defining an entrypoint for https on port :443 (not really nee$
      - --certificatesresolvers.mytlschallenge.acme.tlschallenge=true # <== Enable TLS-ALPN-01 (not really needed)
      - --certificatesresolvers.mytlschallenge.acme.email=email@domain.com # <== Set your email (not really needed)
      - --certificatesresolvers.mytlschallenge.acme.storage=/letsencrypt/acme.json # <== SSL stuff we don't need.
    volumes:
      - ./letsencrypt:/letsencrypt # <== Volume for certs (TLS) (not really needed)
      - /var/run/docker.sock:/var/run/docker.sock # <== Volume for docker admin
      - ./config/:/config # <== Volume for dynamic conf file, **ref: line 27
    networks:
      - web # <== Placing traefik on the network named web, to access containers on this network
    labels:
      - "traefik.enable=true" # <== Enable traefik on itself to view dashboard and assign subdomain to$
      - "traefik.http.routers.api.rule=Host(`traefik.testing.domain.com`)" # <== Setting the domain for the d$
      - "traefik.http.routers.api.service=api@internal" # <== Enabling the api to be a service to acce$

networks:
  web:
    external: true
    name: web

Here is the config/dynamic.yaml for traefik to set up middleware

## Setting up the middleware for redirect to https ##
http:
  middlewares:
    httpsredirect:
      redirectScheme:
        scheme: https
        permanent: true

And here is test docker containers docker-compose.yml

version: '3.3'

services:
  whoami:
    # A container that exposes an API to show its IP address
    image: traefik/whoami
    networks:
      - web
    labels:
      - "traefik.enable=true"
      - "treafik.http.routers.whoami.entrypoints=web,web-secure"
      - "traefik.http.routers.whoami.rule=Host(`whoami.testing.domain.com`)"
      - "traefik.http.routers.whoami.tls=true"
      - "traefik.http.routers.whoami.middlewares=httpsredirect@file" # <== This is a middleware to redirect to htt$
      - "traefik.http.routers.whoami.tls.certresolver=mytlschallenge"

networks:
  web:
    external: true
    name: web
1 Answers

Try the following from redirect regex

Docker

# Redirect with domain replacement
# Note: all dollar signs need to be doubled for escaping.
labels:
  - "traefik.http.middlewares.test-redirectregex.redirectregex.regex=^https://localhost/(.*)"
  - "traefik.http.middlewares.test-redirectregex.redirectregex.replacement=http://mydomain/$${1}"
  • For kubernetes
---
apiVersion: traefik.containo.us/v1alpha1
kind: Middleware
metadata:
  name: http-to-https-redirect

spec:
  redirectRegex:
    regex: ^http://(www.)?yourdomain.com/(.*)
    replacement: https://yourdomain.com
    permanent: true

And you inject the middleware in your ingress route

apiVersion: traefik.containo.us/v1alpha1
kind: IngressRoute
metadata:
  name: ingressroute

spec:
  tls: {}        
  entryPoints:
    - web
    - websecure
  routes:
    - match: "HostRegexp(`{sub:(www.)?}yourdomain.com`) && PathPrefix(`/`)"
      kind: Rule
      services:
        - name: your-service
          port: 80
Related