Where Does Traefik Store Certificates?
Traefik's acme.json storage, required permissions, and Docker volume patterns.
Last updated
Traefik keeps ACME certificates in a single acme.json file named by the storage option of each certificate resolver. Lose it and every domain reissues from scratch, which is how people discover rate limits.
The file demands 600 permissions and a persistent mount. An unmounted container path works until the first restart wipes every certificate with it.
Where Traefik stores this, by platform
./letsencrypt/acme.json
Host side of the usual ./letsencrypt:/letsencrypt mount with storage=/letsencrypt/acme.json. Touch the file plus chmod 600 before first launch. Static config in traefik.yml or CLI flags names the resolver.
Frequently asked questions
Why is my acme.json empty after restart?
It was never mounted out of the container. Add the volume for the exact storage path and set 600 perms on the host file first.
Can I read certificates out of acme.json?
Only via dumper tools like traefik-certs-dumper, since it is JSON wrapped. Dump to PEM when another service needs the raw cert and key.
Notice an outdated path? Let us know.