【问题标题】:Artifactory 7.x behind nginx issuenginx问题背后的Artifactory 7.x
【发布时间】:2020-03-19 14:43:37
【问题描述】:

我有一个全新安装的 Artifactory 7.2.1(基于 docker),它工作正常,但我想通过 nginx 代理访问它,但那不起作用。 我的神器在http://192.168.211.207:8082/ 下运行 自定义基本 URL 设置为:http://192.168.211.207:8081/artifactory -> 将我重定向到 http://192.168.211.207:8082/

现在,我有一个 nginx 服务器,它在同一台服务器上运行,也通过 docker。

当我尝试访问时:

http://192.168.211.207 -> 将我重定向到https://192.168.211.207/artifactory + 502 Bad Gateway

https://192.168.211.207 ->将我重定向到https://192.168.211.207/ui + 502 Bad Gateway

http://192.168.211.207/artifactory -> 重定向到 https + 502 Bad Gateway

https://192.168.211.207/artifactory -> 502 错误网关

我真的不明白端口 8081 后面是什么,因为我无法在任何情况下使用它。端口 8082 正在工作,但不在 nginx 代理后面。

这是我的 docker-compose 文件:

version: '2'
    services:
      artifactory:
        image: docker.bintray.io/jfrog/artifactory-pro:7.2.1
        container_name: artifactory
        ports:
         - 8081:8081
         - 8082:8082
        volumes:
         - /data/artifactory:/var/opt/jfrog/artifactory
        restart: always
        ulimits:
          nproc: 65535
          nofile:
            soft: 32000
            hard: 40000
      nginx:
        image: docker.bintray.io/jfrog/nginx-artifactory-pro:7.2.1
        container_name: nginx
        ports:
         - 80:80
         - 443:443
        depends_on:
         - artifactory
        links:
         - artifactory
        volumes:
         - /data/nginx:/var/opt/jfrog/nginx
        environment:
         - ART_BASE_URL=http://localhost:8081/artifactory
         - SSL=true
         # Set SKIP_AUTO_UPDATE_CONFIG=true to disable auto loading of NGINX conf
         #- SKIP_AUTO_UPDATE_CONFIG=true
        restart: always
        ulimits:
          nproc: 65535
          nofile:
            soft: 32000
            hard: 40000

这是我的 nginx 配置文件:

    ssl_protocols TLSv1 TLSv1.1 TLSv1.2 TLSv1.3;
ssl_certificate  /var/opt/jfrog/nginx/ssl/example.crt;
ssl_certificate_key  /var/opt/jfrog/nginx/ssl/example.key;
ssl_session_cache shared:SSL:1m;
ssl_prefer_server_ciphers   on;
## server configuration
server {
  listen 443 ssl;
  listen 80 ;
  server_name ~(?<repo>.+)\.artifactory artifactory;

  if ($http_x_forwarded_proto = '') {
    set $http_x_forwarded_proto  $scheme;
  }
  ## Application specific logs
  ## access_log /var/log/nginx/artifactory-access.log timing;
  ## error_log /var/log/nginx/artifactory-error.log;
  if ( $repo != "" ){
    rewrite ^/(v1|v2)/(.*) /artifactory/api/docker/$repo/$1/$2;
  }
 rewrite ^/$ /ui/ redirect;
    rewrite ^/ui$ /ui/ redirect;
    proxy_buffer_size          128k;
    proxy_buffers              4 256k;
    proxy_busy_buffers_size    256k;
    chunked_transfer_encoding on;
    client_max_body_size 0;
    location / {
    proxy_read_timeout  2400s;
    proxy_pass_header   Server;
    proxy_cookie_path   ~*^/.* /;
    proxy_pass          http://localhost:8082;
    proxy_set_header    X-JFrog-Override-Base-Url $http_x_forwarded_proto://$host:$server_port;
    proxy_set_header    X-Forwarded-Port  $server_port;
    proxy_set_header    X-Forwarded-Proto $http_x_forwarded_proto;
    proxy_set_header    Host              $http_host;
    proxy_set_header    X-Forwarded-For   $proxy_add_x_forwarded_for;

        location ~ ^/artifactory/ {
            proxy_pass    http://localhost:8082;
        }
    }
}

我无法弄清楚我在这里做错了什么,但由于我不是 nginx 专家,因此可能会遗漏一些东西。

有人发现问题了吗? 有人有 nginx 和 artifactory 7.x 的示例配置文件吗?

【问题讨论】:

    标签: nginx reverse-proxy artifactory


    【解决方案1】:

    谢谢大家的回答。我已经能够与支持人员取得联系,在与专家交谈后,他们确认在 7.x 版本中他们不再支持 webcontext,因此在我的情况下,运行两个工件的唯一方法是创建单独的子域。


    为了让该主题的未来访问者更清楚,jFrog 支持向我确认,从 7.0 及更高版本开始,Artifactory 不再支持 /webcontext 功能,他们不打算支持它。

    因此 mydomain.com/artifactory-one 和 mydomain.com/artifactory-two 不再可能,您必须使用子域来完成。

    mydomain.com/artifactory-one -> artifactory-one.mydomain.com mydomain.com/artifactory-two -> artifactory-two.mydomain.com

    【讨论】:

      【解决方案2】:

      问题可能就在这里。当您在 docker 容器中运行它时,容器中的 nginx 无法正确处理 - >proxy_pass http://localhost:8082; 请改用 IP。它对我有用

      【讨论】:

      • 您好,感谢您的建议。我还尝试将它们放在同一个 docker 网络中并通过 IP 访问它,但还没有好的结果。你用什么版本?我知道,在
      【解决方案3】:

      试试这个

             location ~ ^/artifactory/ {
                  proxy_pass    http://127.0.0.1:8081;
              }
      

      【讨论】:

        【解决方案4】:

        这是我在 Nginx 反向代理前面使用 AWS NLB 的 Nginx 反向代理配置

        ssl_protocols TLSv1 TLSv1.1 TLSv1.2 TLSv1.3;
        ssl_certificate  /var/opt/jfrog/nginx/ssl/tls.crt;
        ssl_certificate_key  /var/opt/jfrog/nginx/ssl/tls.key;
        ssl_session_cache shared:SSL:1m;
        ssl_prefer_server_ciphers   on;
        ## server configuration
        
        server {
          listen 443 ssl;
          listen 80;
          server_name ~(?<repo>.+)\.artifactory artifactory;
        
          if ($http_x_forwarded_proto = '') {
            set $http_x_forwarded_proto  $scheme;
          }
          ## Application specific logs
          ## access_log /var/log/nginx/artifactory-access.log timing;
          ## error_log /var/log/nginx/artifactory-error.log;
          rewrite ^/$ /ui/ redirect;
          rewrite ^/ui$ /ui/ redirect;
          rewrite ^/artifactory/?$ / redirect;
          if ( $repo != "" ) {
            rewrite ^/(v1|v2)/(.*) /artifactory/api/docker/$repo/$1/$2 break;
          }
          chunked_transfer_encoding on;
          client_max_body_size 0;
        
          location / {
            proxy_read_timeout  2400;
            proxy_pass_header   Server;
            proxy_cookie_path   ~*^/.* /;
            proxy_buffer_size 128k;
            proxy_buffers 40 128k;
            proxy_busy_buffers_size 128k;
            proxy_pass          http://artifactory:8082/;
            proxy_set_header    X-JFrog-Override-Base-Url $http_x_forwarded_proto://$host;
            proxy_set_header    Host              $http_host;
            add_header Strict-Transport-Security always;
        
            location /artifactory/ {
              if ( $request_uri ~ ^/artifactory/(.*)$ ) {
                proxy_pass       http://artifactory:8081/artifactory/$1;
              }
              proxy_pass         http://artifactory:8081/artifactory/;
            }
          }
        }
        

        【讨论】:

          猜你喜欢
          • 1970-01-01
          • 2016-02-19
          • 1970-01-01
          • 1970-01-01
          • 2021-09-08
          • 2023-01-19
          • 1970-01-01
          • 2021-05-09
          • 2014-11-06
          相关资源
          最近更新 更多