Automatic HTTP-to-HTTPS Redirection with Traefik and Let's Encrypt
Traefik can redirect HTTP traffic to HTTPS and provision Let's Encrypt certificates automatically - here's how to wire it together in Docker or Kubernetes.
30 Sept 2025, 15:45 UTC

The problem with default Traefik routing
When you deploy a service behind Traefik and expect all inbound traffic to use HTTPS, requests that arrive on the plain web entrypoint often hit a 404 or stay on HTTP. Without an explicit redirect, Traefik routes traffic based on rules but does not automatically force TLS or provision a Let's Encrypt certificate.
Useful takeaway: By combining a TLS-enabled router with a redirect middleware, Traefik can automatically send HTTP traffic to HTTPS and obtain a Let's Encrypt certificate - no manual cert renewal required.
Thesis: one configuration pattern does the job
Traefik's declarative model lets you declare a router that targets a TLS entrypoint and a middleware that redirects HTTP to that entrypoint. The two pieces work together: the middleware intercepts plain HTTP, issues a 301 to the HTTPS entrypoint, and the router then presents the certificate acquired from Let's Encrypt.
Step 1: Configure the TLS router
In a Docker container, add the certificate resolver and entrypoint labels:
traefik.http.routers.web.tls.certresolver=letsencrypt
traefik.http.routers.web.entrypoints=websecure
The websecure entrypoint must be defined in Traefik's static configuration with TLS enabled (e.g., entrypoints.websecure.tls).
Step 2: Add the HTTP redirect middleware
Create a middleware that redirects any request on the web scheme to HTTPS:
traefik.http.middlewares.web-redirect.redirectscheme.scheme=https
traefik.http.middlewares.web-redirect.redirectscheme.permanent=true
traefik.http.routers.web.middlewares=web-redirect
This middleware runs before the router's TLS logic, so inbound HTTP traffic is immediately sent to the HTTPS entrypoint, where Traefik can present the Let's Encrypt certificate.
Step 3: Verify the setup
- Restart the container and watch Traefik logs for certificate generation entries.
- Visit https://your-domain and confirm the padlock icon.
- Run openssl s_client -connect your-domain:443 -servername your-domain to inspect the certificate chain.
- Check the Traefik API dashboard (/dashboard or /api/http/routers) to confirm the router's TLS status.
Trade-off: challenge types and rate limits
Traefik supports HTTP-01, DNS-01, and TLS-ALPN-01 ACME challenges. HTTP-01 works when Traefik can serve .well-known/acme-challenge on the web entrypoint. DNS-01 is required for wildcard certificates or when port 80 is blocked. Each challenge type adds configuration complexity and, for DNS-01, exposes cloud provider credentials. Let's Encrypt rate limits (typically 50 certificates per week per domain) may delay issuance if many routers request certificates simultaneously.
Practical verification checklist
- Confirm the Docker label traefik.http.routers.web.tls.certresolver=letsencrypt is present.
- Restart Traefik and look for Acme or Certificate lines in the logs.
- Browser: padlock visible, valid certificate for the domain.
- Command line: openssl s_client -connect your-domain:443 -servername your-domain shows a valid chain.
- Traefik dashboard: /dashboard lists the router and its TLS configuration.
Closing
By pairing a TLS-configured router with a redirect middleware, Traefik can automatically shift HTTP traffic to HTTPS and obtain a Let's Encrypt certificate - no ongoing manual effort needed. Choose the challenge type that matches your network layout, watch the rate limits, and verify with the steps above. Your services will be served over TLS with minimal ongoing effort.
0 replies
A thoughtful contribution can make all the difference. Be the first to share one.