You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Synology NAS部署Go网站遇HTTPS 403错误求助

Synology NAS DSM 7.2.1部署Go网站HTTPS访问403错误排查求助

配置详情

  • 端口配置:为域名example.com(示例域名,实际使用其他域名)专属分配端口8888。
  • Go应用:main.go代码如下:
package main

import (
    "fmt"
    "html/template"
    "log"
    "net/http"
    "os"
    "path/filepath"
    "github.com/russross/blackfriday/v2"
)

type MarkdownTemplateData struct {
    Title string
    Body  template.HTML
}

func renderMarkdown(w http.ResponseWriter, r *http.Request) {
    path := r.URL.Path
    if path == "/" {
        path = "/index.md"
    }
    mdPath := "." + path

    mdFile, err := os.ReadFile(mdPath)
    if err != nil {
        http.NotFound(w, r)
        return
    }

    mdContent := blackfriday.Run(mdFile)
    tmplData := MarkdownTemplateData{
        Title: filepath.Base(mdPath),
        Body:  template.HTML(mdContent),
    }

    tmpl, err := template.ParseFiles("template.html")
    if err != nil {
        http.Error(w, err.Error(), http.StatusInternalServerError)
        return
    }

    tmpl.Execute(w, tmplData)
}

func main() {
    http.HandleFunc("/", renderMarkdown)
    fmt.Println("Serving on https://example.com:443")
    log.Fatal(http.ListenAndServeTLS(":8888", "/usr/syno/etc/certificate/_archive/1Dih2C/fullchain.pem", "/usr/syno/etc/certificate/_archive/1Dih2C/privkey.pem", nil))
}
  • Nginx配置:example.com的Nginx配置文件位于/etc/nginx/conf.d/example.conf,内容如下:
server {
    listen 443 ssl;
    server_name example.com;

    ssl_certificate /usr/syno/etc/certificate/_archive/1Dih2C/fullchain.pem;
    ssl_certificate_key /usr/syno/etc/certificate/_archive/1Dih2C/privkey.pem;

    location / {
        proxy_pass https://127.0.0.1:8888;
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;
    }
}
  • HTML测试:使用简单test.html页面测试(无Go),访问完全正常。

排查步骤与观察

  • Go服务器运行正常,执行sudo lsof -i :8888显示端口8888处于监听状态:
COMMAND    PID USER   FD   TYPE DEVICE SIZE/OFF NODE NAME
example   9663 root   3u  IPv6 3355074      0t0  TCP *:8888 (LISTEN)
  • 执行curl -k https://127.0.0.1:8888可成功获取预期HTML内容。
  • 通过浏览器访问https://example.com时出现403错误。

已尝试多种配置,确认Nginx设置、Go代码及防火墙规则无误,但403错误仍存在,恳请提供故障排查建议。

内容的提问来源于stack exchange,提问作者Vanessa

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.19 16:54:53