【问题标题】:Elastic Beantalks Proxy弹性 Beanstalk 代理
【发布时间】:2020-04-01 06:10:05
【问题描述】:

我正在尝试部署一个非常简单的代理,它将在端口 80 上侦听 HTTP,并在外部主机上的端口 433 上转发(不返回重定向 301!!)到 HTTPS。

我正在使用清晰的 Elastic Beanstalk 实例,只为 nginx 上传以下配置(https://docs.nginx.com/nginx/admin-guide/security-controls/securing-http-traffic-upstream/):

files:
  /etc/nginx/conf.d/proxy.conf:
    mode: "000644"
    owner: root
    group: root
    content: |
      upstream backend {
        server xxxxxx.execute-api.xx-xx-x.amazonaws.com:443;
      }

      server {
        listen 80;
        servername blablabla.eba-smthng.xx-xx-x.elasticbeanstalk.com;

        if ($time_iso8601 ~ "^(\d{4})-(\d{2})-(\d{2})T(\d{2})") {
            set $year $1;
            set $month $2;
            set $day $3;
            set $hour $4;
        }
        access_log /var/log/nginx/healthd/application.log.$year-$month-$day-$hour healthd;
        access_log /var/log/nginx/access.log  main;

        location / {
            proxy_pass https://backend;
        }

      }

  /opt/elasticbeanstalk/hooks/configdeploy/post/99_kill_default_nginx.sh:
    mode: "000755"
    owner: root
    group: root
    content: |
      #!/bin/bash -xe
      rm -f /etc/nginx/conf.d/00_elastic_beanstalk_proxy.conf
      service nginx stop 
      service nginx start

container_commands:
  removeconfig:
    command: "rm -f /tmp/deployment/config/#etc#nginx#conf.d#00_elastic_beanstalk_proxy.conf /etc/nginx/conf.d/00_elastic_beanstalk_proxy.conf"

我希望所有对 blablabla.eba-smthng.xx-xx-x.elasticbeanstalk.com 的 HTTP 请求都将被代理到 HTTPS 端点 xxxxxx.execute-api.xx-xx-x.amazonaws.com。

但我得到的总是:

$ curl -X POST http://blablabla.eba-smthng.xx-xx-x.elasticbeanstalk.com/some/resource -d "{}"

<html>
<head><title>302 Found</title></head>
<body>
<center><h1>302 Found</h1></center>
<hr><center>nginx/1.16.1</center>
</body>
</html>

怎么了?

【问题讨论】:

    标签: amazon-web-services nginx amazon-elastic-beanstalk


    【解决方案1】:

    好的,我在没有 Beantalks 的情况下解决了这个问题 - 只需使用 EC2 实例和 nginx。

    配置非常简单,我怀疑它也应该在 Beantalks 中工作:

          server {
            listen 80;
            server_name blablabla.eba-smthng.xx-xx-x.elasticbeanstalk.com;
    
            location / {
    
                proxy_pass https://xxxxxx.execute-api.xx-xx-x.amazonaws.com:443/;
                proxy_ssl_session_reuse on;
            }
    
          }
    

    保持关闭斜线很重要,如果proxy_pass 有URI 参数,则不需要重写和标头。 在我最初的帖子中使用了错误的令牌 servername - 必须是 server_name。

    【讨论】:

      猜你喜欢
      • 2020-08-08
      • 2020-08-16
      • 2015-04-20
      • 2018-11-23
      • 2022-11-12
      • 2017-04-04
      • 2017-02-05
      • 2014-12-17
      • 2015-12-23
      相关资源
      最近更新 更多