Synology NAS部署Go网站遇HTTPS 403错误求助
Synology NAS DSM 7.2.1部署Go网站HTTPS访问403错误排查求助
配置详情
- 端口配置:为域名example.com(示例域名,实际使用其他域名)专属分配端口8888。
- Go应用:main.go代码如下:
package main import ( "fmt" "html/template" "log" "net/http" "os" "path/filepath" "github.com/russross/blackfriday/v2" ) type MarkdownTemplateData struct { Title string Body template.HTML } func renderMarkdown(w http.ResponseWriter, r *http.Request) { path := r.URL.Path if path == "/" { path = "/index.md" } mdPath := "." + path mdFile, err := os.ReadFile(mdPath) if err != nil { http.NotFound(w, r) return } mdContent := blackfriday.Run(mdFile) tmplData := MarkdownTemplateData{ Title: filepath.Base(mdPath), Body: template.HTML(mdContent), } tmpl, err := template.ParseFiles("template.html") if err != nil { http.Error(w, err.Error(), http.StatusInternalServerError) return } tmpl.Execute(w, tmplData) } func main() { http.HandleFunc("/", renderMarkdown) fmt.Println("Serving on https://example.com:443") log.Fatal(http.ListenAndServeTLS(":8888", "/usr/syno/etc/certificate/_archive/1Dih2C/fullchain.pem", "/usr/syno/etc/certificate/_archive/1Dih2C/privkey.pem", nil)) }
- Nginx配置:example.com的Nginx配置文件位于
/etc/nginx/conf.d/example.conf,内容如下:
server { listen 443 ssl; server_name example.com; ssl_certificate /usr/syno/etc/certificate/_archive/1Dih2C/fullchain.pem; ssl_certificate_key /usr/syno/etc/certificate/_archive/1Dih2C/privkey.pem; location / { proxy_pass https://127.0.0.1:8888; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; } }
- HTML测试:使用简单test.html页面测试(无Go),访问完全正常。
排查步骤与观察
- Go服务器运行正常,执行
sudo lsof -i :8888显示端口8888处于监听状态:
COMMAND PID USER FD TYPE DEVICE SIZE/OFF NODE NAME example 9663 root 3u IPv6 3355074 0t0 TCP *:8888 (LISTEN)
- 执行
curl -k https://127.0.0.1:8888可成功获取预期HTML内容。 - 通过浏览器访问
https://example.com时出现403错误。
已尝试多种配置,确认Nginx设置、Go代码及防火墙规则无误,但403错误仍存在,恳请提供故障排查建议。
内容的提问来源于stack exchange,提问作者Vanessa
相关产品推荐
相关产品推荐

