# Connect specific router to service on separate ports in docker-compose

**URL:** <https://community.traefik.io/t/connect-specific-router-to-service-on-separate-ports-in-docker-compose/1754>\
**Category:** Traefik v2\
**Tags:** docker\
**Created:** [September 20, 2019, 10:34am UTC](https://community.traefik.io/t/connect-specific-router-to-service-on-separate-ports-in-docker-compose/1754 "2019-09-20T10:34:51Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![dali99](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/dali99/32/736_2.png) [@dali99](https://community.traefik.io/u/dali99)\
**Post date:** [September 20, 2019, 10:34am UTC](https://community.traefik.io/t/connect-specific-router-to-service-on-separate-ports-in-docker-compose/1754/1 "2019-09-20T10:34:51Z")

</div>

In Traefik 1 you could connect two different frontends to two separate ports on the same container.

In my case that was sending git.MYDOMAIN to gitlab and \*.pages.MYDOMAIN to gitlab pages (running in their omnibus container)

However with traefik 2 I cant seem to figure out how to point a router to a specific service.loadbalancer.port. I might just be blind, but I would appreciate it greatly if anyone knew how to connect two different routers to two different services with docker labels.

My labels:

```auto
- "traefik.enable=true"

- "traefik.http.routers.gitlab-main-http.rule=Host(`git.dodsorf.as`)"
- "traefik.http.routers.gitlab-main-http.entrypoints=web"
- "traefik.http.routers.gitlab-main-http.middlewares=redirect@file"

- "traefik.http.routers.gitlab-main-https.rule=Host(`git.dodsorf.as`)"
- "traefik.http.routers.gitlab-main-https.tls=true"
- "traefik.http.routers.gitlab-main-https.tls.certresolver=normal"
- "traefik.http.routers.gitlab-main-https.entrypoints=websecure"

- "traefik.http.routers.gitlab-pages-http.rule=Host(`pages.dodsorf.as`) || HostRegexp(`{[a-z]+}.pages.dodsorf.as`)"
- "traefik.http.routers.gitlab-pages-http.entrypoints=web"
- "traefik.http.routers.gitlab-pages-http.middlewares=redirect@file"

- "traefik.http.routers.gitlab-pages-https.rule=Host(`pages.dodsorf.as`) || HostRegexp(`{[a-z]+}.pages.dodsorf.as`)"
- "traefik.http.routers.gitlab-pages-https.tls=true"
- "traefik.http.routers.gitlab-pages-https.tls.certresolver=pages"
- "traefik.http.routers.gitlab-pages-https.tls.domains.main=pages.dodsorf.as"
- "traefik.http.routers.gitlab-pages-https.tls.domains.sans=*.pages.dodsorf.as"

```

Also if anyone has any hints on how to reduce all the boileplate it would be much appreciated

---

<div class="post-metadata">

**Author:** ![ldez](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/ldez/32/5_2.png) [@ldez](https://community.traefik.io/u/ldez)\
**Post date:** [September 20, 2019, 10:54am UTC](https://community.traefik.io/t/connect-specific-router-to-service-on-separate-ports-in-docker-compose/1754/2 "2019-09-20T10:54:33Z")

</div>

For now, this part lacks a little doc on the subject in the Docker section.

But, it's pretty easy: a router (the rule) is linked to a service (the servers)

- [https://docs.traefik.io/v2.0/routing/overview/](https://docs.traefik.io/v2.0/routing/overview/)
- [https://docs.traefik.io/v2.0/routing/routers/](https://docs.traefik.io/v2.0/routing/routers/)
- [https://docs.traefik.io/v2.0/routing/services/](https://docs.traefik.io/v2.0/routing/services/)

So you need to define a relation between the router and the service (as with segment labels):

```auto
# Router named "tomato"
- "traefik.http.routers.tomato.rule=Host(`tomato.com`)"
- "traefik.http.routers.tomato.service=strawberry"

# Service named "strawberry"
- "traefik.http.services.strawberry.loadbalancer.server.port=80

# Router named "carrot"
- "traefik.http.routers.carrot.rule=Host(`carrot.com`)"
- "traefik.http.routers.carrot.service=orange"

# Service named "orange"
- "traefik.http.services.orange.loadbalancer.server.port=81

```

- [https://docs.traefik.io/reference/dynamic-configuration/docker/](https://docs.traefik.io/reference/dynamic-configuration/docker/)

* * *

Otherwise, there is some errors in your configuration:

```auto
- "traefik.http.routers.gitlab-pages-https.rule=Host(`pages.dodsorf.as`) || HostRegexp(`{[a-z]+}.pages.dodsorf.as`)"
- "traefik.http.routers.gitlab-pages-https.entrypoints=websecure"
- "traefik.http.routers.gitlab-pages-https.tls=true"
- "traefik.http.routers.gitlab-pages-https.tls.certresolver=pages"
- "traefik.http.routers.gitlab-pages-https.tls.domains[0].main=pages.dodsorf.as"
- "traefik.http.routers.gitlab-pages-https.tls.domains[0].sans=*.pages.dodsorf.as"

```

also I recommend to use only one resolver with 2 challenges inside.

By example (TLS-ALPN + DNS):

```auto
--entryPoints.web.address=":80"
--entryPoints.websecure.address=":443"
# ...
--certificatesResolvers.sugar.acme.email="your-email@your-domain.org"
--certificatesResolvers.sugar.acme.httpChallenge.entryPoint=web
--certificatesResolvers.sugar.acme.dnsChallenge.provider=digitalocean

```

---

<div class="post-metadata">

**Author:** ![dali99](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/dali99/32/736_2.png) [@dali99](https://community.traefik.io/u/dali99)\
**Post date:** [September 20, 2019, 11:30am UTC](https://community.traefik.io/t/connect-specific-router-to-service-on-separate-ports-in-docker-compose/1754/3 "2019-09-20T11:30:10Z")

</div>

Wow thanks for the quick indepth answer

> [@ldez](#):
>
> But, it's pretty easy: a router (the rule) in linked to a service (the servers)
> 
> So you need to define a relation between the router and the service (as with segment labels):
> 
> ```auto
> # Router named "tomato"
> - "traefik.http.routers.tomato.rule=Host(`tomato.com`)"
> - "traefik.http.routers.tomato.service=strawberry"
> 
> # Service named "strawberry"
> - "traefik.http.services.strawberry.loadbalancer.port=80
> 
> # Router named "carrot"
> - "traefik.http.routers.carrot.rule=Host(`carrot.com`)"
> - "traefik.http.routers.carrot.service=orange"
> 
> # Service named "orange"
> - "traefik.http.services.orange.loadbalancer.port=81
> 
> ```

I see, I figured it would be something like this but didn't manage to see it, much thanks.  
Setting

```auto
- "traefik.http.services.orange.loadbalancer. **server**.port=80

```

With the `routers.<router>.service` thing works!

> [@ldez](#):
>
> Otherwise, there is some errors in your configuration:
> 
> ```auto
> - "traefik.http.routers.gitlab-pages-https.rule=Host(`pages.dodsorf.as`) || HostRegexp(`{[a-z]+}.pages.dodsorf.as`)"
> - "traefik.http.routers.gitlab-pages-https.entrypoints=websecure"
> - "traefik.http.routers.gitlab-pages-https.tls=true"
> - "traefik.http.routers.gitlab-pages-https.tls.certresolver=pages"
> - "traefik.http.routers.gitlab-pages-https.tls.domains[0].main=pages.dodsorf.as"
> - "traefik.http.routers.gitlab-pages-https.tls.domains[0].sans=*.pages.dodsorf.as"
> 
> ```

ah so I do need the domains[0] thing, I was unsure if it was meant literally, thanks

> [@ldez](#):
>
> also I recommend to use only one resolver with 2 challenges inside.
> 
> By example (TLS-ALPN + DNS):
> 
> ```auto
> --entryPoints.web.address=":80"
> --entryPoints.websecure.address=":443"
> # ...
> --certificatesResolvers.sugar.acme.email="your-email@your-domain.org"
> --certificatesResolvers.sugar.acme.httpChallenge.entryPoint=web
> --certificatesResolvers.sugar.acme.dnsChallenge.provider=digitalocean
> 
> ```

I've gone ahead and done this, but is there a particular reason it's recommended?

Thanks for all your help

---

<div class="post-metadata">

**Author:** ![dali99](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/dali99/32/736_2.png) [@dali99](https://community.traefik.io/u/dali99)\
**Post date:** [September 21, 2019, 10:10am UTC](https://community.traefik.io/t/connect-specific-router-to-service-on-separate-ports-in-docker-compose/1754/4 "2019-09-21T10:10:00Z")

</div>

Most of it seems to work, but traefik can't get a cert for \*.pages.dodsorf.as, complaining about:

```auto
Error -> One or more domains had a problem:\n[*.pages.dodsorf.as] [*.pages.dodsorf.as] acme: could not determine solvers\n" providerName=gitlab.acme

```

static labels:

```auto
      - "--entrypoints.web.address=:80"
      - "--entrypoints.websecure.address=:443"

      - "--certificatesresolvers.normal.acme.httpchallenge=true"
      - "--certificatesresolvers.normal.acme.httpchallenge.entrypoint=web"
      - "--certificatesresolvers.normal.acme.email=admin@dodsorf.as"
      - "--certificatesresolvers.normal.acme.storage=/acme/normal.json"

      - "--certificatesresolvers.gitlab.acme.dnschallenge=true"
      - "--certificatesResolvers.gitlab.acme.dnsChallenge.provider=digitalocean"
      - "--certificatesResolvers.gitlab.acme.dnsChallenge.delayBeforeCheck=0"

      - "--certificatesresolvers.gitlab.acme.httpchallenge=true"
      - "--certificatesresolvers.gitlab.acme.httpchallenge.entrypoint=web"

      - "--certificatesresolvers.gitlab.acme.email=admin@dodsorf.as"
      - "--certificatesresolvers.gitlab.acme.storage=/acme/gitlab.json"

```

dynamic labels:

```auto
      - "traefik.enable=true"

      - "traefik.http.routers.gitlab-main-http.rule=Host(`git.dodsorf.as`)"
      - "traefik.http.routers.gitlab-main-http.entrypoints=web"
      - "traefik.http.routers.gitlab-main-http.middlewares=redirect@file"
      - "traefik.http.routers.gitlab-main-http.service=gitlab-main"

      - "traefik.http.services.gitlab-main.loadbalancer.server.port=80"

      - "traefik.http.routers.gitlab-main-https.rule=Host(`git.dodsorf.as`)"
      - "traefik.http.routers.gitlab-main-https.tls=true"
      - "traefik.http.routers.gitlab-main-https.tls.certresolver=gitlab"
      - "traefik.http.routers.gitlab-main-https.entrypoints=websecure"
      - "traefik.http.routers.gitlab-main-https.service=gitlab-main"

      - "traefik.http.routers.gitlab-pages-http.rule=Host(`pages.dodsorf.as`) || HostRegexp(`{[a-z]+}.pages.dodsorf.as`)"
      - "traefik.http.routers.gitlab-pages-http.entrypoints=web"
      - "traefik.http.routers.gitlab-pages-http.middlewares=redirect@file"
      - "traefik.http.routers.gitlab-pages-http.service=gitlab-pages"

      - "traefik.http.services.gitlab-pages.loadbalancer.server.port=8091"

      - "traefik.http.routers.gitlab-pages-https.rule=Host(`pages.dodsorf.as`) || HostRegexp(`{[a-z]+}.pages.dodsorf.as`)"
      - "traefik.http.routers.gitlab-pages-https.entrypoints=websecure"
      - "traefik.http.routers.gitlab-pages-https.tls=true"
      - "traefik.http.routers.gitlab-pages-https.tls.certresolver=gitlab"
      - "traefik.http.routers.gitlab-pages-https.tls.domains[0].main=pages.dodsorf.as"
      - "traefik.http.routers.gitlab-pages-https.tls.domains[0].sans=*.pages.dodsorf.as"
      - "traefik.http.routers.gitlab-pages-https.service=gitlab-pages"

```

---

<div class="post-metadata">

**Author:** ![ldez](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/ldez/32/5_2.png) [@ldez](https://community.traefik.io/u/ldez)\
**Post date:** [September 21, 2019, 11:30am UTC](https://community.traefik.io/t/connect-specific-router-to-service-on-separate-ports-in-docker-compose/1754/5 "2019-09-21T11:30:07Z")

</div>

it's related to:

> **[LetsEncrypt JSON file is not being stored](https://community.traefik.io/t/letsencrypt-json-file-is-not-being-stored/1470/13)**
>
> It's just a problem related to case: - --certificatesresolvers.default.acme.httpchallenge.entrypoint=http - --certificatesResolvers.default.acme.email=support@trajano.net - --certificatesResolvers.default.acme.storage=/letsencrypt/acme.json ...

So just use `certificatesresolvers` everywhere instead of `certificatesResolvers`.

The problem with the case will be fixed in the next version.

---

<div class="post-metadata">

**Author:** ![dali99](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/dali99/32/736_2.png) [@dali99](https://community.traefik.io/u/dali99)\
**Post date:** [September 21, 2019, 3:44pm UTC](https://community.traefik.io/t/connect-specific-router-to-service-on-separate-ports-in-docker-compose/1754/6 "2019-09-21T15:44:54Z")

</div>

Thank you, that worked!

For anyone viewing the thread in the future. Check the edit history of the post/comments, Idez has edited my wrong config and fixed the errors.

This makes it very easy to see what's wrong because of the diff view, but its confusing for later readers of the thread.
