# Troubleshot "service does not exist"

**URL:** <https://community.traefik.io/t/troubleshot-service-does-not-exist/20780>\
**Category:** Traefik v2\
**Tags:** docker-swarm\
**Created:** [December 14, 2023, 9:43pm UTC](https://community.traefik.io/t/troubleshot-service-does-not-exist/20780 "2023-12-14T21:43:03Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![bremoi](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/bremoi/32/7963_2.png) [@bremoi](https://community.traefik.io/u/bremoi)\
**Post date:** [December 14, 2023, 9:43pm UTC](https://community.traefik.io/t/troubleshot-service-does-not-exist/20780/1 "2023-12-14T21:43:03Z")

</div>

Hi,

I have "the service "wazuh-dashboard@docker" does not exist" error message, but the container actually exists.

Could you give me some tips to troubleshoot please?

Thanks in advance.

Regards

---

<div class="post-metadata">

**Author:** ![bluepuma77](https://avatars.discourse-cdn.com/v4/letter/b/a9adbd/32.png) [@bluepuma77](https://community.traefik.io/u/bluepuma77)\
**Post date:** [December 15, 2023, 8:38am UTC](https://community.traefik.io/t/troubleshot-service-does-not-exist/20780/2 "2023-12-15T08:38:06Z")

</div>

Share your full Traefik static and dynamic config, and `docker-compose.yml` if used.

"Service does not exist" does not mean a Docker "service", but the missing definition of a Traefik dynamic "service" configuration.

Compare with simple Traefik example ([link](https://github.com/bluepuma77/traefik-best-practice/tree/main/docker-traefik-dashboard-letsencrypt)).

---

<div class="post-metadata">

**Author:** ![bremoi](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/bremoi/32/7963_2.png) [@bremoi](https://community.traefik.io/u/bremoi)\
**Post date:** [December 15, 2023, 9:49am UTC](https://community.traefik.io/t/troubleshot-service-does-not-exist/20780/3 "2023-12-15T09:49:52Z")

</div>

Hi @bluepuma77,

Thanks for your comment.  
Below my docker-compose.yml for Traefik and my Wazuh service.

# Traefik

```auto
[...]
command:
  - --entrypoints.wm1514.address=:1514
  - --entrypoints.wm1515.address=:1515
  - --entrypoints.wm514.address=:514/udp
  - --entrypoints.wm55000.address=:55000
  - --entrypoints.wi9200.address=:9200
  - --entrypoints.wd5601.address=:5601
ports:
  - "1514:1514"
  - "1515:1515"
  - "514:514/udp"
  - "55000:55000"
  - "9200:9200"
  - "5601:5601"
[...]

```

# Wazuh

```auto
version: '3.7'
services:
  wazuh-manager:
    image: wazuh/wazuh-manager:4.6.0
    hostname: wazuh.manager
    [...]
    deploy:
      mode: replicated
      replicas: 1
      labels:
      - "traefik.enable=true"
      - "traefik.tcp.routers.wm1514.rule=Host(`wazuh.xxxx.tld`)"
      - "traefik.tcp.routers.wm1514.entrypoints=wm1514"
      - "traefik.tcp.services.wm1514.loadbalancer.server.port=1514"
      - "traefik.tcp.routers.wm1514.service=wazuh-manager"
      - "traefik.tcp.routers.wm1515.rule=Host(`wazuh.xxxx.tld`)"
      - "traefik.tcp.routers.wm1515.entrypoints=wm1515"
      - "traefik.tcp.services.wm1515.loadbalancer.server.port=1515"
      - "traefik.tcp.routers.wm1515.service=wazuh-manager"
      - "traefik.udp.routers.wm514.rule=Host(`wazuh.xxxx.tld`)"
      - "traefik.udp.routers.wm514.entrypoints=wm514"
      - "traefik.udp.services.wm514.loadbalancer.server.port=514"
      - "traefik.udp.routers.wm514.service=wazuh-manager"
      - "traefik.http.routers.wm55000.rule=Host(`wazuh.xxxx.tld`)"
      - "traefik.http.routers.wm55000.entrypoints=wm55000"
      - "traefik.http.services.wm55000.loadbalancer.server.port=55000"
      - "traefik.http.routers.wm55000.service=wazuh-manager"
    networks:
      - traefik
      - wazuh

  wazuh-indexer:
    image: wazuh/wazuh-indexer:4.6.0
    hostname: wazuh.indexer
    [...]
    deploy:
      mode: replicated
      replicas: 1
      labels:
      - "traefik.enable=true"
      - "traefik.http.routers.wi9200.rule=Host(`wazuh.xxxx.tld`)"
      - "traefik.http.routers.wi9200.entrypoints=wi9200"
      - "traefik.http.services.wi9200.loadbalancer.server.port=9200"
      - "traefik.http.routers.wi9200.service=wazuh-indexer"
    networks:
      - traefik
      - wazuh

  wazuh-dashboard:
    image: wazuh/wazuh-dashboard:4.6.0
    hostname: wazuh.dashboard
    [...]
    deploy:
      mode: replicated
      replicas: 1
      labels:
      - "traefik.enable=true"
      - "traefik.http.routers.wd5601.rule=Host(`wazuh.xxxx.tld`)"
      - "traefik.http.routers.wd5601.entrypoints=wd5601"
      - "traefik.http.services.wd5601.loadbalancer.server.port=5601"
      - "traefik.http.routers.wd5601.service=wazuh-dashboard"
    depends_on:
      - wazuh-indexer
      - wazuh-manager
    networks:
      - traefik
      - wazuh
[...]

```

---

<div class="post-metadata">

**Author:** ![bremoi](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/bremoi/32/7963_2.png) [@bremoi](https://community.traefik.io/u/bremoi)\
**Post date:** [December 15, 2023, 10:51am UTC](https://community.traefik.io/t/troubleshot-service-does-not-exist/20780/4 "2023-12-15T10:51:38Z")

</div>

Hi,

Actually I have no more the error message from Traefik by changing the Traefik service name with the same container name.  
From `- "traefik.http.routers.wd5601.service=wazuh-dashboard"` to `- "traefik.http.routers.wazuh-dashboard.service=wazuh-dashboard"`

Is this the normal behavior ? I though that I could use any Traefik service name (e.g. wd5601) and then specify the container name for redirection (e.g. wazuh-dashboard).  
In this case, how configure multiple ports for the same container, e.g. for wazuh-manager above, by using the same Traefik service name because it doesn't matter?

Thanks

---

<div class="post-metadata">

**Author:** ![bluepuma77](https://avatars.discourse-cdn.com/v4/letter/b/a9adbd/32.png) [@bluepuma77](https://community.traefik.io/u/bluepuma77)\
**Post date:** [December 15, 2023, 11:32am UTC](https://community.traefik.io/t/troubleshot-service-does-not-exist/20780/5 "2023-12-15T11:32:03Z")

</div>

> [@bremoi](#):
>
> ```auto
> - "traefik.tcp.services.wm1514.loadbalancer.server.port=1514"
> - "traefik.tcp.routers.wm1514.service=wazuh-manager"
> 
> ```

should be

```auto
      - "traefik.tcp.services.wm1514.loadbalancer.server.port=1514"
      - "traefik.tcp.routers.wm1514.service=wm1514"

```

as you define the service in the upper line, assign that to the router in the lower line

---

<div class="post-metadata">

**Author:** ![bremoi](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/bremoi/32/7963_2.png) [@bremoi](https://community.traefik.io/u/bremoi)\
**Post date:** [December 15, 2023, 1:32pm UTC](https://community.traefik.io/t/troubleshot-service-does-not-exist/20780/6 "2023-12-15T13:32:48Z")

</div>

I undestand, thanks @bluepuma77, the Traefik error message came from that.

However now, when I try to reach [https://wazuh.xxxx.tld:5601](https://wazuh.xxxx.tld:5601), I have "404 page not found". If I directy expose a port at the same time Im' able to reach that URL bypassing Traefik.

---

<div class="post-metadata">

**Author:** ![bluepuma77](https://avatars.discourse-cdn.com/v4/letter/b/a9adbd/32.png) [@bluepuma77](https://community.traefik.io/u/bluepuma77)\
**Post date:** [December 15, 2023, 3:08pm UTC](https://community.traefik.io/t/troubleshot-service-does-not-exist/20780/7 "2023-12-15T15:08:36Z")

</div>

Enable and check Traefik debug log and dashboard. Specifically check for errors.

---

<div class="post-metadata">

**Author:** ![bremoi](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/bremoi/32/7963_2.png) [@bremoi](https://community.traefik.io/u/bremoi)\
**Post date:** [December 15, 2023, 3:57pm UTC](https://community.traefik.io/t/troubleshot-service-does-not-exist/20780/8 "2023-12-15T15:57:59Z")

</div>

Nothing seems wrong, the only think that I see strange is the URL pointed by Traefik that is in HTTP ([http://10.0.14.73:5601](http://10.0.14.73:5601)) instead of HTTPS. How could I force redirection to HTTPS?

---

<div class="post-metadata">

**Author:** ![bluepuma77](https://avatars.discourse-cdn.com/v4/letter/b/a9adbd/32.png) [@bluepuma77](https://community.traefik.io/u/bluepuma77)\
**Post date:** [December 15, 2023, 5:07pm UTC](https://community.traefik.io/t/troubleshot-service-does-not-exist/20780/9 "2023-12-15T17:07:11Z")

</div>

By default, Traefik will internally forward requests with HTTP to the target service.

Enable Traefik access log in JSON format to see the http status code from target service (`OriginStatus`), if it even exists.

---

<div class="post-metadata">

**Author:** ![bremoi](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/bremoi/32/7963_2.png) [@bremoi](https://community.traefik.io/u/bremoi)\
**Post date:** [December 15, 2023, 9:01pm UTC](https://community.traefik.io/t/troubleshot-service-does-not-exist/20780/10 "2023-12-15T21:01:48Z")

</div>

Indeed, I would force Traefik to internally forward requests with HTTPS to the target service, insted of HTTP. Do know you how do this?

---

<div class="post-metadata">

**Author:** ![bluepuma77](https://avatars.discourse-cdn.com/v4/letter/b/a9adbd/32.png) [@bluepuma77](https://community.traefik.io/u/bluepuma77)\
**Post date:** [December 15, 2023, 9:30pm UTC](https://community.traefik.io/t/troubleshot-service-does-not-exist/20780/11 "2023-12-15T21:30:16Z")

</div>

Set the Traefik services `scheme` to `https` ([reference](https://doc.traefik.io/traefik/reference/dynamic-configuration/docker/)):

```auto
  - "traefik.http.services.service01.loadbalancer.server.port=foobar"
  - "traefik.http.services.service01.loadbalancer.server.scheme=foobar"

```

---

<div class="post-metadata">

**Author:** ![bremoi](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/bremoi/32/7963_2.png) [@bremoi](https://community.traefik.io/u/bremoi)\
**Post date:** [December 15, 2023, 9:49pm UTC](https://community.traefik.io/t/troubleshot-service-does-not-exist/20780/12 "2023-12-15T21:49:46Z")

</div>

Thanks, it's better. Traefik Dashboard now shows "[https://10.0.14.130:5601](https://10.0.14.130:5601)" which is good, but I have always "404 page not found".

```auto
labels:
  - "traefik.enable=true"
  - "traefik.http.routers.wd5601.rule=Host(`waz.brox.cloudns.eu`)"
  - "traefik.http.routers.wd5601.entrypoints=wd5601"
  - "traefik.http.routers.wd5601.service=wd5601"
  - "traefik.http.services.wd5601.loadbalancer.server.port=5601"
  - "traefik.http.services.wd5601.loadbalancer.server.scheme=https"

```

---

<div class="post-metadata">

**Author:** ![bluepuma77](https://avatars.discourse-cdn.com/v4/letter/b/a9adbd/32.png) [@bluepuma77](https://community.traefik.io/u/bluepuma77)\
**Post date:** [December 15, 2023, 11:22pm UTC](https://community.traefik.io/t/troubleshot-service-does-not-exist/20780/13 "2023-12-15T23:22:22Z")

</div>

You are sure your Elasticsearch Kibana Dashboard supports HTTPS on port 5601?

The sub-domain points to your Traefik IP?

---

<div class="post-metadata">

**Author:** ![bremoi](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/bremoi/32/7963_2.png) [@bremoi](https://community.traefik.io/u/bremoi)\
**Post date:** [December 15, 2023, 11:38pm UTC](https://community.traefik.io/t/troubleshot-service-does-not-exist/20780/14 "2023-12-15T23:38:55Z")

</div>

Sure Dashboard supports HTTPS on port 5601 also because when I expose port bypassing Traefik everything works properly with my sub-domain too.

```auto
ports:
  - "5602:5601"

```

---

<div class="post-metadata">

**Author:** ![bremoi](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/bremoi/32/7963_2.png) [@bremoi](https://community.traefik.io/u/bremoi)\
**Post date:** [December 18, 2023, 12:07pm UTC](https://community.traefik.io/t/troubleshot-service-does-not-exist/20780/15 "2023-12-18T12:07:00Z")

</div>

Hi,

An important information to specify that may help. My target service handles certificates by itself, so I tried the following, but without success.

```auto
- "traefik.enable=true"
- "traefik.tcp.routers.wd5601.rule=HostSNI(`wazuh.xxxx.tld`)"
- "traefik.tcp.routers.wd5601.entrypoints=wd5601"
- "traefik.tcp.routers.wd5601.service=wd5601"
- "traefik.tcp.services.wd5601.loadbalancer.server.port=5601"
- "traefik.tcp.routers.wd5601.tls.passthrough=true"

```

---

<div class="post-metadata">

**Author:** ![bluepuma77](https://avatars.discourse-cdn.com/v4/letter/b/a9adbd/32.png) [@bluepuma77](https://community.traefik.io/u/bluepuma77)\
**Post date:** [December 18, 2023, 3:01pm UTC](https://community.traefik.io/t/troubleshot-service-does-not-exist/20780/16 "2023-12-18T15:01:07Z")

</div>

Traefik needs a cert to use `HostSNI()` with domain name. Without a cert only `HostSNI(`*`)` works, a real domain will trigger creation of a custom Traefik cert.

---

<div class="post-metadata">

**Author:** ![bremoi](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/bremoi/32/7963_2.png) [@bremoi](https://community.traefik.io/u/bremoi)\
**Post date:** [December 18, 2023, 7:33pm UTC](https://community.traefik.io/t/troubleshot-service-does-not-exist/20780/17 "2023-12-18T19:33:16Z")

</div>

Fantastic, it works 🙂

Thank you very much for all your help.

---

<div class="post-metadata">

**Author:** ![bremoi](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/bremoi/32/7963_2.png) [@bremoi](https://community.traefik.io/u/bremoi)\
**Post date:** [December 19, 2023, 7:37pm UTC](https://community.traefik.io/t/troubleshot-service-does-not-exist/20780/18 "2023-12-19T19:37:10Z")

</div>

Hi @bluepuma77,

Last questions, if I have no-TLS or a certificate handled by the container itself I have to use HostSNI(`*`) for both TCP and UDP, right? In case of certificate handled by itself I also add passthrough, right?

Thanks in advance

---

<div class="post-metadata">

**Author:** ![bluepuma77](https://avatars.discourse-cdn.com/v4/letter/b/a9adbd/32.png) [@bluepuma77](https://community.traefik.io/u/bluepuma77)\
**Post date:** [December 19, 2023, 7:52pm UTC](https://community.traefik.io/t/troubleshot-service-does-not-exist/20780/19 "2023-12-19T19:52:40Z")

</div>

`passthrough` sounds good for TCP.

Check UDP [docs](https://doc.traefik.io/traefik/routing/routers/#configuring-udp-routers):

> Therefore, there is no criterion that could be used as a rule to match incoming packets in order to route them. So UDP "routers" at this time are pretty much only load-balancers in one form or another.

---

<div class="post-metadata">

**Author:** ![bremoi](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/bremoi/32/7963_2.png) [@bremoi](https://community.traefik.io/u/bremoi)\
**Post date:** [December 19, 2023, 7:54pm UTC](https://community.traefik.io/t/troubleshot-service-does-not-exist/20780/20 "2023-12-19T19:54:27Z")

</div>

Thank you very much.
