Traefik's ACME resolver stored the epicnabbo.nl leaf certificate without the Let's Encrypt intermediate. With Cloudflare in Full (strict) mode the origin TLS handshake failed (HTTP 525), breaking every asset and the whole site layout (JS/CSS chunks, Nitro client, toolbar). Configure the epicnabbo router to use a file-based certificate that includes the full chain (leaf + LE YR2 intermediate), referenced from dynamic/epicnabbo-tls.yml. Add a regeneration script and README.
1.7 KiB
Traefik infrastructure (epicnabbo.nl)
This directory mirrors the live Traefik dynamic configuration used to proxy
epicnabbo.nl (and subdomains) on the production host. The dynamic config
lives on the server at /docker/proxyserver/dynamic/.
Fix: HTTP 525 / broken layout (origin TLS chain)
The site returned HTTP 525 (Cloudflare SSL handshake failed) for every asset, which broke the whole UI (JS/CSS chunks, the Nitro client, the toolbar, the "Enter Hotel" button, etc.).
Root cause: Traefik's ACME resolver stored the epicnabbo.nl leaf
certificate in /letsencrypt/acme.json without the Let's Encrypt
intermediate. When Cloudflare connects to the origin in "Full (strict)" mode
it cannot build the certificate chain and aborts the TLS handshake → 525.
Fix: the epicnabbo router serves a file-based certificate that includes
the full chain (leaf + LE YR2 intermediate), configured in
dynamic/epicnabbo-tls.yml and referenced from dynamic/epicnabbo.nl.yml
(tls: {} enables TLS on the router so the SNI matches the file cert).
Files
dynamic/epicnabbo.nl.yml— router/service/serversTransport for epicnabbo.nl.dynamic/epicnabbo-tls.yml— file-based certificate (leaf + intermediate).regenerate-epicnabbo-chain.sh— rebuilds the full chain fromacme.json.
NOT committed (contain secrets)
epicnabbo-fullchain.pem— leaf + intermediate.epicnabbo-key.pem— private key.
Re-generating the chain (e.g. after cert renewal, before 2026-10-03)
./infra/traefik/regenerate-epicnabbo-chain.sh
docker restart traefik
The epicnabbo.nl entry must be absent from acme.json so Traefik does
not prefer the (incomplete-chain) ACME certificate over the file certificate.