You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Docker部署Nginx+WordPress容器访问域名返回403错误求助

问题:Docker部署WordPress主域名403错误,仅/wp-admin可访问

我在DigitalOcean Droplet上从零搭建Docker环境部署WordPress和Nginx服务,域名已正确解析到服务器IP,但访问主域名retronexus.net返回403错误,只有访问retronexus.net/wp-admin/index.php能正常打开。已重新部署服务器,未发现配置明显问题,附上我的docker-compose.yml和nginx.conf,求排查解决。


docker-compose.yml

version : '3'

services:
  db:
    image: mysql:8.0
    container_name: wordpress_db
    restart: unless-stopped
    env_file: .env
    environment:
      - MYSQL_DATABASE=wordpress
    volumes:
      - rn_dbdata:/var/lib/mysql
    command: '--default-authentication-plugin=mysql_native_password'
    # command: mysqld --initialize-insecure --user=mysql
    networks:
      - rn-network

  wordpress:
    depends_on:
      - db
    image: wordpress:6.6.2-fpm-alpine
    container_name: wordpress
    restart: unless-stopped
    env_file: .env
    environment:
      - WORDPRESS_DB_HOST=db:3306
      - WORDPRESS_DB_USER=$MYSQL_USER
      - WORDPRESS_DB_PASSWORD=$MYSQL_PASSWORD
      - WORDPRESS_DB_NAME=wordpress
    volumes:
      - rn_wordpress:/var/www/html
    networks:
      - rn-network

  webserver:
    depends_on:
      - wordpress
    image: nginx:1.27.2-alpine
    container_name: webserver
    restart: unless-stopped
    ports:
      - "80:80"
    volumes:
      - rn_wordpress:/var/www/html
      - ./nginx-conf:/etc/nginx/conf.d
      - certbot-etc:/etc/letsencrypt
    networks:
      - rn-network

  certbot:
    depends_on:
      - webserver
    image: certbot/certbot
    container_name: certbot
    volumes:
      - certbot-etc:/etc/letsencrypt
      - rn_wordpress:/var/www/html
    command: certonly --webroot --webroot-path=/var/www/html --email EMAIL --agree-tos --no-eff-email --staging -d retronexus.net -d www.retronexus.net

volumes:
  certbot-etc:
  rn_wordpress:
  rn_dbdata:

networks:
  rn-network:
    driver: bridge

nginx.conf

# Default server block to handle all unspecified domains and specify it as default. This block returns an 404 error or redirect to different page.
server {
        listen 80;
        listen [::]:80 default_server;
        server_name _;
        return 404;
}

server {
        # listen on specified ports
    listen 80;
        listen [::]:80;

        # define server names. 
        server_name www.retronexus.net retronexus.net

        # defines the files that will be used as indexes when processing requests to the server.
        index index.php index.html index.htm;

        # root directory for requests to the server. the directory also is created as a mount point at build time for docker
        root /var/www/html;

        # Handle requests to the well-known dir, where certbot will place a temp file to validate that the DNS for the domain resolves to the server. 
        location ~ /.well-known/acme-challenge {
                allow all;
                root /var/www/html;
        }

        # try_files is used to check for files that match individual URI requests. Instead of 404 status as default, control is passed to wordpress index.php file with request arguments
        location / {
                try_files $uri $uri/ /index.php$is_args$args;
        }

        # Handles PHP processing and proxy these requests to the wordpress container. as the wordpress container will be based on php fpm image, also uncluding config options for FastCGI.
        # NGINX requires an independent PHP processor for PHP requests. In this case, these requests will be handled by the PHP-fprm processor thats included with the wordpress image. 
        # FastCGI specific directives, vars and options that will proxy requests to the wordpress app running on the wordpress container, set preferred index for the parsed URI and parse URI requests.
        location ~ \.php$ {
                try_files $uri =404;
                fastcgi_split_path_info ^(.+\.php)(/.+)$;
                fastcgi_pass wordpress:9000;
                fastcgi_index index.php;
                include fastcgi_params;
                fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;
                fastcgi_param PATH_INFO $fastcgi_path_info;
        }

        # Handle htaccess files since nginx won't serve them. deny-all ensures that htaccess files will never be served to users.
        location ~ /\.ht {
                deny all;
        }

        # ensure that requests to favicon will not be logged
        location = /favicon.ico {
                log_not_found off; access_log off;
        }

        # ensure that requests to robots will not be logged
        location = /robots.txt {
                log_not_found off; access_log off; allow all;
        }

        # turns off logging for static asset requets and and ensures assets being cacheable
        location ~* \.(css|gif|ico|jpeg|jpg|js|png)$ {
                expires max;
                log_not_found off;
        }
}

排查与解决步骤

1. 修复Nginx配置语法错误

你的nginx.conf中,server_name www.retronexus.net retronexus.net这一行末尾缺少分号,这会导致Nginx无法正确加载配置,请求可能被路由到第一个返回404的默认server块。

修改为:

server_name www.retronexus.net retronexus.net;

重启Nginx容器生效:

docker-compose restart webserver

2. 检查WordPress目录权限

主域名访问403但/wp-admin可打开,大概率是网站根目录的文件权限异常,Nginx进程无读取权限。

进入WordPress容器查看权限:

docker-compose exec wordpress ls -l /var/www/html

如果文件所有者不是www-data,执行以下命令修复:

docker-compose exec wordpress chown -R www-data:www-data /var/www/html

3. 验证Nginx配置有效性

检查Nginx配置是否正确加载:

docker-compose exec webserver nginx -t

输出test is successful说明配置无语法问题,否则根据提示修复错误。

4. 确认WordPress站点URL设置

登录/wp-admin后,进入设置→常规,确保WordPress地址(URL)和站点地址(URL)都设置为http://retronexus.net(或带www的域名),不一致的话修改后保存。

5. 查看Nginx错误日志定位问题

如果以上步骤无效,查看Nginx错误日志找原因:

docker-compose logs webserver

日志会明确标注403错误的触发原因,比如权限不足、文件缺失等。


内容的提问来源于stack exchange,提问作者retronexus

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.16 17:15:54