# Traefik with Docker, shows 404 for HTTPS

**URL:** <https://community.traefik.io/t/traefik-with-docker-shows-404-for-https/23101>\
**Category:** Traefik v3 (latest)\
**Tags:** docker\
**Created:** [June 7, 2024, 3:01pm UTC](https://community.traefik.io/t/traefik-with-docker-shows-404-for-https/23101 "2024-06-07T15:01:39Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![splitbrain](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/splitbrain/32/8868_2.png) [@splitbrain](https://community.traefik.io/u/splitbrain)\
**Post date:** [June 7, 2024, 3:01pm UTC](https://community.traefik.io/t/traefik-with-docker-shows-404-for-https/23101/1 "2024-06-07T15:01:39Z")

</div>

I want to use traefik to manage ingress to various docker containers. However so far I'm starting with a very basic config:

```auto
services:
  traefik:
    image: traefik:v3.0
    container_name: traefik
    restart: unless-stopped
    security_opt:
      - no-new-privileges:true
    networks:
      - proxy
    ports:
      - 80:80
      - 443:443
    volumes:
      - /etc/localtime:/etc/localtime:ro
      - /var/run/docker.sock:/var/run/docker.sock:ro
    command:
      - "--api=true"
      - "--api.dashboard=true"
      - "--serversTransport.insecureSkipVerify=true"
      - "--log.level=DEBUG"
      - "--providers.docker=true"
      - "--providers.docker.network=proxy"
      - "--providers.docker.exposedbydefault=false"
      - "--entrypoints.websecure.address=:443"      
      - "--entrypoints.web.address=:80"

  whoami:
    image: traefik/whoami:latest
    container_name: whoami
    command:
      - "--verbose"
    labels:
      - "traefik.enable=true"
      - "traefik.http.routers.whoami.rule=Host(`whoami.my.domain`)"
      - "traefik.http.routers.whoami.entrypoints=web"
      - "traefik.http.routers.whoami-secure.rule=Host(`whoami.my.domain`)"
      - "traefik.http.routers.whoami-secure.entrypoints=websecure"

    networks:
      - proxy
      
networks:
  proxy:
    external: true

```

My problem is that access to [http://whoami.my.domain](http://whoami.my.domain) works as expected, but accessing [https://whoami.my.domain](https://whoami.my.domain) shows a `404 page not found`only.

I am not sure what I am doing wrong. If I understand the documentation correctly, I wouldn't even need to define the entrypoints for the whoami service, since by default all HTTP and HTTPS entrypoints should point to the first exposed port of the container.

Indeed the following works just as fine:

```auto
  whoami:
    image: traefik/whoami:latest
    container_name: whoami
    command:
      - "--verbose"
    labels:
      - "traefik.enable=true"
      - "traefik.http.routers.whoami.rule=Host(`whoami.my.domain`)"
    networks:
      - proxy

```

But the symptoms are the same. Port 80 works, port 443 returns a 404.

What am I missing?

---

<div class="post-metadata">

**Author:** ![bluepuma77](https://avatars.discourse-cdn.com/v4/letter/b/a9adbd/32.png) [@bluepuma77](https://community.traefik.io/u/bluepuma77)\
**Post date:** [June 7, 2024, 3:56pm UTC](https://community.traefik.io/t/traefik-with-docker-shows-404-for-https/23101/2 "2024-06-07T15:56:30Z")

</div>

You set the router to only use `entrypoint` _web_, not _websecure_. So requests with https to `router` _websecure_ have no `rule` to match.

Compare to [simple Traefik example](https://github.com/bluepuma77/traefik-best-practice/tree/main/docker-traefik-dashboard-letsencrypt).

---

<div class="post-metadata">

**Author:** ![splitbrain](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/splitbrain/32/8868_2.png) [@splitbrain](https://community.traefik.io/u/splitbrain)\
**Post date:** [June 7, 2024, 7:25pm UTC](https://community.traefik.io/t/traefik-with-docker-shows-404-for-https/23101/3 "2024-06-07T19:25:57Z")

</div>

Turns out the problem is that no TLS configuration was added. This was deliberate since I wanted to use Traefik's self signed certificate while figuring things out. The trick is to simply set `--entrypoints.websecure.http.tls=true`.

For completeness, here is a working configuration:

```auto
services:
  traefik:
    image: traefik:v3.0
    container_name: traefik
    restart: unless-stopped
    security_opt:
      - no-new-privileges:true
    networks:
      - proxy
    ports:
      - 80:80
      - 443:443
    volumes:
      - /etc/localtime:/etc/localtime:ro
      - /var/run/docker.sock:/var/run/docker.sock:ro
    command:
      - "--api=true"
      - "--api.dashboard=true"
      - "--serversTransport.insecureSkipVerify=true"
      - "--log.level=DEBUG"
      - "--providers.docker=true"
      - "--providers.docker.network=proxy"
      - "--providers.docker.exposedbydefault=false"
      - "--entrypoints.websecure.address=:443"
      - "--entrypoints.websecure.http.tls=true"
      - "--entrypoints.web.address=:80"

  whoami:
    image: traefik/whoami:latest
    container_name: whoami
    command:
      - "--verbose"
    labels:
      - "traefik.enable=true"
      - "traefik.http.routers.whoami.rule=Host(`whoami.my.domain`)"

    networks:
      - proxy
      
networks:
  proxy:
    external: true

```

The above makes the first exposed port of the whoami image available via HTTP and HTTPs (the latter with a self signed certificate).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex020/uploads/containo/original/2X/b/bd81ebdb578656e76e56ff3cc3eed021d3ba132d.png) [@system](https://community.traefik.io/u/system)\
**Post date:** [June 10, 2024, 7:26pm UTC](https://community.traefik.io/t/traefik-with-docker-shows-404-for-https/23101/4 "2024-06-10T19:26:20Z")

</div>

This topic was automatically closed 3 days after the last reply. New replies are no longer allowed.
