Nginx反向代理ASP.Net应用失效,请求排查配置问题
问题描述
我有4个ASP.Net应用,尝试通过Nginx反向代理对外提供服务,但始终无法正常访问。无论调整何种配置都无法解决问题,急需帮助排查错误。
Nginx.conf配置
user nginx; worker_processes auto; error_log /var/log/nginx/error.log notice; pid /var/run/nginx.pid; events { worker_connections 1024; } http { include /etc/nginx/mime.types; default_type application/octet-stream; log_format main '$remote_addr - $remote_user [$time_local] "$request" ' '$status $body_bytes_sent "$http_referer" ' '"$http_user_agent" "$http_x_forwarded_for"'; access_log /var/log/nginx/access.log main; sendfile on; keepalive_timeout 65; server { listen 80 default_server; listen [::]:80 default_server; location / { root /usr/share/nginx/html; index index.html index.htm; } location /auth { proxy_pass http://0.0.0.0:5160; proxy_http_version 1.0; proxy_set_header Upgrade $http_upgrade; proxy_set_header Connection keep-alive; proxy_set_header Host $host; proxy_cache_bypass $http_upgrade; proxy_intercept_errors on; } location /company { proxy_pass http://0.0.0.0:5287; proxy_http_version 1.0; proxy_set_header Upgrade $http_upgrade; proxy_set_header Connection keep-alive; proxy_set_header Host $host; proxy_cache_bypass $http_upgrade; proxy_intercept_errors on; } location /equipment { proxy_pass http://0.0.0.0:5176; proxy_http_version 1.0; proxy_set_header Upgrade $http_upgrade; proxy_set_header Connection keep-alive; proxy_set_header Host $host; proxy_cache_bypass $http_upgrade; proxy_intercept_errors on; } location /featureflags { proxy_pass http://0.0.0.0:5291; proxy_http_version 1.0; proxy_set_header Upgrade $http_upgrade; proxy_set_header Connection keep-alive; proxy_set_header Host $host; proxy_cache_bypass $http_upgrade; proxy_intercept_errors on; } error_page 500 502 503 504 /50x.html; location = /50x.html { root /usr/share/nginx/html; } error_page 400 401 402 403 404 /40x.html; location = /40x.html { root /usr/share/nginx/html; } } }
应用健康检查地址
- http://localhost:5160/api/health/healthCheck --> Authentication
- http://localhost:5291/api/health/healthCheck --> FeatureFlags
- http://localhost:5176/api/health/healthCheck --> Equipment
- http://localhost:5287/api/health/healthCheck --> Company
排查与修复方案
1. 先确认后端应用可用性
在Nginx服务器上执行以下命令,逐个验证ASP.Net应用是否能正常响应:
curl http://localhost:5160/api/health/healthCheck curl http://localhost:5291/api/health/healthCheck curl http://localhost:5176/api/health/healthCheck curl http://localhost:5287/api/health/healthCheck
如果命令返回非200状态或无响应,先解决应用自身的启动、端口监听问题,再排查Nginx配置。
2. 修正Nginx代理配置中的核心问题
(1)调整HTTP协议版本
ASP.Net Core应用默认使用HTTP/1.1,当前配置中的proxy_http_version 1.0会导致兼容性问题,需改为:
proxy_http_version 1.1;
(2)修复路径转发错误
当前location /auth代理到http://0.0.0.0:5160时,Nginx会把请求路径/auth/api/health/healthCheck完整转发到后端,变成http://0.0.0.0:5160/auth/api/health/healthCheck,但后端应用的健康检查路径是/api/health/healthCheck,多了/auth前缀会导致404。
需给proxy_pass末尾添加斜杠,让Nginx去掉location前缀后再转发:
location /auth { proxy_pass http://0.0.0.0:5160/; # 其他配置保持调整后的内容 }
同理,/company、/equipment、/featureflags的proxy_pass都需要添加末尾的斜杠。
(3)优化Upgrade与Connection头配置
如果你的应用不需要WebSocket支持,可以直接删除proxy_set_header Upgrade $http_upgrade;和proxy_cache_bypass $http_upgrade;这两行;如果需要WebSocket,需调整Connection头并添加map规则:
在http块最上方添加:
map $http_upgrade $connection_upgrade { default upgrade; '' close; }
然后将每个location中的proxy_set_header Connection keep-alive;改为:
proxy_set_header Connection $connection_upgrade;
3. 验证Nginx配置并重启
执行以下命令检查配置语法是否正确:
nginx -t
如果输出test is successful,执行重启命令让配置生效:
nginx -s reload
4. 查看错误日志定位细节
如果问题仍存在,查看Nginx错误日志获取具体报错信息:
cat /var/log/nginx/error.log
日志中会包含连接超时、权限不足、后端无响应等具体原因,针对性解决。
5. 检查防火墙与端口权限
- 确认服务器防火墙已开放80端口,允许外部访问;
- 确认后端应用的端口(5160、5287等)在服务器本地没有被防火墙拦截,Nginx可以正常连接这些端口。
内容的提问来源于stack exchange,提问作者JAKDev

