【问题标题】:docker nginx ssl proxy pass to another containerdocker nginx ssl 代理传递到另一个容器
【发布时间】:2018-07-28 06:50:22
【问题描述】:

我有一个 docker-compose 文件,现在运行两个容器:

version: '3'

services:
  nginx-certbot-container:
    build: nginx-certbot
    restart: always
    links:
      - ghost-container:ghost-container
    ports:
      - 80:80
      - 443:443
    tty: true

  ghost-container:
    image: ghost
    restart: always
    ports:
      - 2368:2368

我有四个网站,l.com、t1.l.com、t2.l.com、t3.l.com,所有网站都使用letsencrypt完成的ssl证书,并且在URL上工作我可以看到绿色锁等...

对于 t2.l.com,我希望它是来自 ghost 的博客,但使用以下 nginx 配置,

upstream ghost-container {
    server ghost-container:2368;
}

server {
    server_name t2.l.com;

    location / {
        proxy_pass https://ghost-container;
        proxy_ssl_certificate /etc/letsencrypt/live/l.com/fullchain.pem;
        proxy_ssl_certificate_key /etc/letsencrypt/live/l.com/privkey.pem;
        proxy_ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
        proxy_ssl_ciphers "ECDHE-ECD ... BC3-SHA:!DSS";
        proxy_ssl_session_reuse on;
    }

    listen 443 ssl;
    ssl_certificate /etc/letsencrypt/live/l.com/fullchain.pem;
    ssl_certificate_key /etc/letsencrypt/live/l.com/privkey.pem;
    include /etc/letsencrypt/options-ssl-nginx.conf;
}

server {
    listen       80;
    listen [::]:80;
    server_name  t2.l.com;

    include /etc/nginx/snippets/letsencrypt.conf;

    location / {
        return 301 https://t2.l.com$request_uri;
        #proxy_pass http://ghost-container;
    }
}

如果我注释掉返回 301,只保留 proxy_pass,我会被重定向到 ghost blog服务器返回 502 错误网关。

我有什么遗漏吗?从其他人的代码看来,只有代理证书就足够了......

编辑

好吧,我只是做了一些我确定不会起作用的事情,并将 ssl 部分中的代理传递设置为 http: 而不是 https:,并且一切正常,所以如果有人能解释背后的机制或逻辑为什么会这样,我会很感兴趣,这在我看来没有意义。

【问题讨论】:

    标签: docker ssl nginx


    【解决方案1】:

    您必须区分从客户端到 nginx(这里是您的反向代理)的连接以及从 nginx 到您的 ghost 容器的连接。

    1. 从客户端到 nginx 服务器的连接可以加密(https,端口 443)或未加密(http,80)。在您的配置文件中,每个都有一个 server 块。如果客户端通过 https 连接(重定向后或直接),nginx 将使用/etc/letsencrypt/live/l.com/* 处的密钥来加密此连接的内容。内容可以从 nginx-certbot-container 容器内的文件系统或上游服务器(因此是反向代理)提供。

    2. 对于t2.l.com,您想使用上游服务器。 Nginx 将打开与上游服务器的连接。这取决于在ghost-container 内运行的服务器是否需要端口 2368 上的 http 或 https 连接。根据您提供的信息,我推断它接受 http 连接。否则,您还需要为 ghost 容器提供 SSL 证书,或者创建自签名证书并使 nginx 信任自签名上游连接。这意味着您的 proxy_pass 应该使用 http。由于此连接的包永远不会离开您的计算机,因此我认为在这种情况下使用 http 作为上游服务器是相当安全的。

    (如果这不是你想要的,你也可以在ghost-container中创建SSL端点。在这种情况下,nginx必须使用SNI来确定目标主机,因为它只看到加密的包。搜索nginx反向代理ssl左右。)

    注意:请注意ports 属性。上面的 docker-compose 文件发布了 2368 端口,所以可以通过http://t2.l.com:2368 访问 ghost 服务器。为避免这种情况,请将其替换为 expose: [2368]。

    【讨论】:

      猜你喜欢
      • 1970-01-01
      • 2022-01-22
      • 2018-03-09
      • 2012-05-09
      • 1970-01-01
      • 1970-01-01
      • 2020-12-10
      • 2014-12-05
      • 1970-01-01
      相关资源
      最近更新 更多