# Confusion over basic configuration

**URL:** <https://community.traefik.io/t/confusion-over-basic-configuration/16497>\
**Category:** Traefik v2\
**Tags:** cli\
**Created:** [November 17, 2022, 10:53am UTC](https://community.traefik.io/t/confusion-over-basic-configuration/16497 "2022-11-17T10:53:27Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![mbwhite](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/mbwhite/32/6201_2.png) [@mbwhite](https://community.traefik.io/u/mbwhite)\
**Post date:** [November 17, 2022, 10:53am UTC](https://community.traefik.io/t/confusion-over-basic-configuration/16497/1 "2022-11-17T10:53:27Z")

</div>

Hello;

I think I'm making a very basic mistake here, but I'm not clear what it could be. Essentially I'm attempting to setup traefik to listen for incoming https requests and then route (depending on the hostname) to a certain backend server. (and pass through the TLS).

eg client connects to htts://srv1.localho.st:8443 and I want traefikl to route that to [https://srv1.localho.st:9000](https://srv1.localho.st:9000) srv2.localho.st:8433 to srv2.localho.st:9500

I believe the configuration is not being properly loaded, as I can get traefik to listen on port 8443 but no other TLS configuration appears to be accepted. The error "No Default Certificate Found"

CLI ~/traefik --providers.file.filename=traefik/config.yaml --configFile=traefik/traefik.yaml

traefik.yaml

```auto
log:
  level: DEBUG

providers:
  file:
    filename: "/home/matthew/github.com/ampretia/tls-expr/traefik/config.yaml"
    watch: true

```

config.yaml

```auto
entryPoints:
  websecure:
    address: ":8443"

tls:
  options:
    opt1:
      passthrough: true
  stores: 
    default:
      defaultCertificate:
        certFile: "/home/matthew/github.com/ampretia/tls-expr/proxy.crt"
        keyFile: "/home/matthew/github.com/ampretia/tls-expr/proxy.key"
      

http:
    routers:
        Router-1:
            rule: "Host('srv1.localho.st')"
            service: my-service           
            tls:
              options: opt1

    services:
        my-service:
            loadBalancer:
              serversTransports: transport_host
              servers:
                - url: "https://localho.st:9443"
                          

    serversTransports: 
      transport_host: 
        insecureSkipVerify: true 
log:
  level: DEBUG

providers:
  file:
    filename: "/home/matthew/github.com/ampretia/tls-expr/traefik/config.yaml"
    watch: true   

```

Many thanks for any pointers  
Matthew

---

<div class="post-metadata">

**Author:** ![bluepuma77](https://avatars.discourse-cdn.com/v4/letter/b/a9adbd/32.png) [@bluepuma77](https://community.traefik.io/u/bluepuma77)\
**Post date:** [November 17, 2022, 11:36am UTC](https://community.traefik.io/t/confusion-over-basic-configuration/16497/2 "2022-11-17T11:36:54Z")

</div>

> [@mbwhite](#):
>
> --configFile

If you use `--configFile` then you can't use other parameters on CLI. Place them instead in you static config.

So `--providers.file.filename=traefik/config.yaml` needs to go into `traefik.yaml`.

---

<div class="post-metadata">

**Author:** ![mbwhite](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/mbwhite/32/6201_2.png) [@mbwhite](https://community.traefik.io/u/mbwhite)\
**Post date:** [November 17, 2022, 12:25pm UTC](https://community.traefik.io/t/confusion-over-basic-configuration/16497/3 "2022-11-17T12:25:40Z")

</div>

ah thanks for that!

made some progress

```auto
Cannot start the provider *file.Provider: field not found, node: passthrough

```

Really confused at that one as I'm sure the docs say it's `passthrough`

---

<div class="post-metadata">

**Author:** ![ldez](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/ldez/32/5_2.png) [@ldez](https://community.traefik.io/u/ldez)\
**Post date:** [November 17, 2022, 12:55pm UTC](https://community.traefik.io/t/confusion-over-basic-configuration/16497/4 "2022-11-17T12:55:10Z")

</div>

Hello,

the root TLS section doesn't have a passthrough option.

> **[Traefik File Dynamic Configuration - Traefik](https://doc.traefik.io/traefik/reference/dynamic-configuration/file/)**
>
> This guide will provide you with the YAML and TOML files for dynamic configuration in Traefik Proxy. Read the technical documentation.

Also the passthrough is only for TCP routers.

> **[Traefik Routers Documentation - Traefik](https://doc.traefik.io/traefik/routing/routers/#passthrough)**
>
> In Traefik Proxy, a router is in charge of connecting incoming requests to the Services that can handle them. Read the technical documentation.

So [dynamic configuration](https://docs.traefik.io/getting-started/configuration-overview/#the-dynamic-configuration) (config.yaml) should look like that:

```auto
tls:
  stores:
    default:
      defaultCertificate:
        certFile: "/home/matthew/github.com/ampretia/tls-expr/proxy.crt"
        keyFile: "/home/matthew/github.com/ampretia/tls-expr/proxy.key"

http:
  routers:
    Router-1:
      rule: "Host('srv1.localho.st')"
      service: my-service
      tls: {}

  services:
    my-service:
      loadBalancer:
        serversTransport: transport_host
        servers:
          - url: "https://localho.st:9443"

  serversTransports:
    transport_host:
      insecureSkipVerify: true

```

And your [static configuration](https://docs.traefik.io/getting-started/configuration-overview/#the-static-configuration) (traefik.yaml):

```auto
log:
  level: DEBUG

providers:
  file:
    filename: "/home/matthew/github.com/ampretia/tls-expr/traefik/config.yaml"
    watch: true

entryPoints:
  websecure:
    address: ":8443" 

```
