Traefik HTTP TLS 개요
Traefik HTTP TLS 개요 (Overview)
본문
Overview
General (일반)
HTTP 라우터가 HTTPS 트래픽을 처리하도록 구성할 때는 해당 라우터 정의에 tls 필드를 포함해요. 이 필드는 Traefik에게 라우터가 TLS 요청만 처리하고 비-TLS 트래픽은 무시하도록 알려줘요.
기본적으로 tls 필드가 있는 HTTP 라우터는 TLS 연결을 종료(terminate)해요. 즉, 서비스에는 복호화된 데이터를 보내요. TLS 구성은 자동 인증서 생성, 사용자 정의 TLS 옵션, 명시적 도메인 지정 등 TLS 동작을 세밀하게 조정할 수 있는 여러 옵션을 제공해요.
라우터 TLS는 엔트리포인트 TLS를 대체해요
엔트리포인트의 http.tls 설정은 라우터가 자신의 tls 섹션을 정의하지 않을 때만 적용돼요. 라우터에 tls 섹션을 정의하면(비어 있더라도, 또는 certResolver, options, domains 같은 어떤 필드든) Traefik은 그 라우터에 대해 해당 구성을 엔트리포인트 기본값과 병합하지 않아요. 라우터 TLS 구성은 엔트리포인트 TLS 구성을 완전히 대체해요.
예를 들어, 엔트리포인트 TLS 옵션이 다음과 같이 구성되어 있다면:
entryPoints:
websecure:
address: :443
http:
tls:
options: modern-tls@file
그리고 라우터가 인증서 리졸버만 설정한다면:
http:
routers:
sample:
rule: Host(`example.com`)
service: sample
tls:
certResolver: letsencrypt
엔트리포인트의 options(modern-tls@file)는 sample에 적용되지 않아요. 둘 다 유지하려면 엔트리포인트에서 함께 설정하거나, 라우터에 options와 certResolver를 모두 설정해야 해요.
Configuration Example (설정 예시)
Structured (YAML)
http:
routers:
my-https-router:
rule: "Host(`example.com`) && Path(`/api`)"
service: "my-http-service"
tls:
certResolver: "letsencrypt"
options: "modern-tls"
domains:
- main: "example.com"
sans:
- "www.example.com"
- "api.example.com"
Structured (TOML)
[http.routers.my-https-router]
rule = "Host(`example.com`) && Path(`/api`)"
service = "my-http-service"
[http.routers.my-https-router.tls]
certResolver = "letsencrypt"
options = "modern-tls"
[[http.routers.my-https-router.tls.domains]]
main = "example.com"
sans = ["www.example.com", "api.example.com"]
Labels
labels:
- "traefik.http.routers.my-https-router.rule=Host(`example.com`) && Path(`/api`)"
- "traefik.http.routers.my-https-router.service=my-http-service"
- "traefik.http.routers.my-https-router.tls=true"
- "traefik.http.routers.my-https-router.tls.certresolver=letsencrypt"
- "traefik.http.routers.my-https-router.tls.options=modern-tls"
- "traefik.http.routers.my-https-router.tls.domains[0].main=example.com"
- "traefik.http.routers.my-https-router.tls.domains[0].sans=www.example.com,api.example.com"
Tags
{
"Tags": [
"traefik.http.routers.my-https-router.rule=Host(`example.com`) && Path(`/api`)",
"traefik.http.routers.my-https-router.service=my-http-service",
"traefik.http.routers.my-https-router.tls=true",
"traefik.http.routers.my-https-router.tls.certresolver=letsencrypt",
"traefik.http.routers.my-https-router.tls.options=modern-tls",
"traefik.http.routers.my-https-router.tls.domains[0].main=example.com",
"traefik.http.routers.my-https-router.tls.domains[0].sans=www.example.com,api.example.com"
]
}
Configuration Options (설정 옵션)
| Field | Description | Default | Required |
| options | TLS 파라미터(암호화 스위트, 최소/최대 TLS 버전, 클라이언트 인증 등)를 구성하는 데 사용할 TLS 옵션 이름이에요. 상세 구성은 TLS Options를 참고해 주세요. | "" (런타임에서 default로 해석돼요) | No |
| certResolver | ACME provider(예: Let's Encrypt)를 통한 자동 인증서 생성을 위해 사용할 인증서 리졸버 이름이에요. 자세한 내용은 Certificate Resolver 섹션을 참고해 주세요. | "" | No |
| domains | 명시적 인증서 도메인 지정을 위한 도메인 및 Subject Alternative Names(SAN) 목록이에요. 자세한 내용은 Custom Domains 섹션을 참고해 주세요. | [] | No |
Certificate Resolver (인증서 리졸버)
tls.certResolver 옵션은 ACME provider(예: Let's Encrypt)를 통한 자동 인증서 생성을 위해 인증서 리졸버를 지정할 수 있게 해 줘요.
라우터에 인증서 리졸버가 구성되면, Traefik은 라우터 규칙(Host 매처)에 지정된 도메인 또는 tls.domains 구성(tls.domains가 우선)에 대해 TLS 인증서를 자동으로 획득하고 관리해요.
사전 요건
-
인증서 리졸버는 정적 구성에서 정의되어야 해요.
-
라우터에 tls가 활성화되어야 해요.
-
인증서 리졸버에 대해 ACME challenge 유형이 구성되어야 해요.
Custom Domains (사용자 정의 도메인)
ACME 인증서 리졸버를 사용할 때 도메인은 라우터 규칙에서 자동으로 추출되지만, tls.domains 옵션을 사용하면 인증서가 생성될 도메인과 Subject Alternative Names(SAN)을 명시적으로 지정할 수 있어요.
이를 통해 인증서 생성을 세밀하게 제어할 수 있고, 라우터 규칙에서 자동으로 추출된 도메인보다 우선해요.
모든 도메인은 Traefik을 가리키는 A/AAAA 레코드를 가져야 해요.
프로덕션에서 Traefik OSS를 사용하시나요?
직장에서 Traefik을 사용하고 있다면, 엔터프라이즈급 API 게이트웨이 기능이나 Traefik OSS에 대한 상용 지원을 고려해 보세요.
-
API 게이트웨이 데모 영상 보기
-
24/7/365 OSS 지원 요청하기
Traefik OSS에 API 게이트웨이 기능을 추가하는 것은 빠르고 자연스러워요. 기존 구성을 갈아엎거나 교체할 필요 없이 모든 설정이 그대로 유지돼요. 이 짧은 영상에서 직접 확인해 보세요.