You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何配置NuGet仅通过HTTPS/443与AWS CodeBuild通信?

如何配置NuGet仅通过HTTPS/443通信?

问题场景

我在AWS CodeBuild上构建、测试并发布.NET 8应用,用于后续集成测试。项目部署在带NAT网关的账户VPC内,需要访问私有VPC资源。

当CodeBuild安全组仅允许HTTPS/443出站公网请求时,dotnet restore --verbosity detailed步骤耗时长达22分钟;但开放80端口后,包恢复和DLL发布能在15秒内完成。我的nuget.config已经配置了HTTPS的公共NuGet源和私有AWS CodeArtifact仓库。

最初我推测NuGet会先尝试HTTP/80,超时后才回退到HTTPS/443,每个包都会重复这个超时重试流程。相关日志片段如下:

PackageSignatureVerificationLog: PackageIdentity: System.Reflection.TypeExtensions.4.3.0 Source: https://api.nuget.org/v3/index.json PackageSignatureValidity: True
Installed System.Reflection.TypeExtensions 4.3.0 from https://api.nuget.org/v3/index.json to /root/.nuget/packages/system.reflection.typeextensions/4.3.0 with content hash 7u6ulLcZbyxB5Gq0nMkQttcdBTx57ibzw+4IOXEfR+sXYQoHvjW5LTLyNr8O22UIMrqYbchJQJnos4eooYzYJA==.
Acquiring lock for the installation of runtime.opensuse.42.1-x64.runtime.native.System.Security.Cryptography.OpenSsl 4.3.2
Acquired lock for the installation of runtime.opensuse.42.1-x64.runtime.native.System.Security.Cryptography.OpenSsl 4.3.2
PackageSignatureVerificationLog: PackageIdentity: runtime.native.System.IO.Compression.4.3.0 Source: https://api.nuget.org/v3/index.json PackageSignatureValidity: True
PackageSignatureVerificationLog: PackageIdentity: System.Runtime.CompilerServices.Unsafe.4.3.0 Source: https://api.nuget.org/v3/index.json PackageSignatureValidity: True
Installed runtime.native.System.IO.Compression 4.3.0 from https://api.nuget.org/v3/index.json to /root/.nuget/packages/runtime.native.system.io.compression/4.3.0 with content hash INBPonS5QPEgn7naufQFXJEp3zX6L4bwHgJ/ZH78aBTpeNfQMtf7C6VrAFhlq2xxWBveIOWyFzQjJ8XzHMhdOQ==.
Acquiring lock for the installation of runtime.osx.10.10-x64.runtime.native.System.Security.Cryptography.OpenSsl 4.3.2
Acquired lock for the installation of runtime.osx.10.10-x64.runtime.native.System.Security.Cryptography.OpenSsl 4.3.2
Installed System.Runtime.CompilerServices.Unsafe 4.3.0 from https://api.nuget.org/v3/index.json to /root/.nuget/packages/system.runtime.compilerservices.unsafe/4.3.0 with content hash rcnXA1U9W3QUtMSGoyoNHH6w4V5Rxa/EKXmzpORUYlDAlDB34hIQoU57ATXl8xHa83VvzRm6PcElEizgUd7U5w==.
Acquiring lock for the installation of runtime.rhel.7-x64.runtime.native.System.Security.Cryptography.OpenSsl 4.3.2
Acquired lock for the installation of runtime.rhel.7-x64.runtime.native.System.Security.Cryptography.OpenSsl 4.3.2
PackageSignatureVerificationLog: PackageIdentity: System.Buffers.4.3.0 Source: https://api.nuget.org/v3/index.json PackageSignatureValidity: True

解决方法

后续通过设置环境变量NUGET_CERT_REVOCATION_MODE为offline,恢复速度回到了正常水平。经过排查,根本问题是NuGet的包签名吊销状态检查未使用HTTPS,导致在仅开放443端口的环境下频繁超时。

要确保NuGet仅通过HTTPS通信,可采取以下措施:

  • 配置环境变量:在CodeBuild构建环境中添加NUGET_CERT_REVOCATION_MODE=offline,避免签名检查时发起HTTP请求
  • 校验源协议:确认nuget.config中所有包源均使用HTTPS协议,不存在HTTP源配置

内容的提问来源于stack exchange,提问作者smk081

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.20 18:05:55