You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

无法使用Artifactory HTTPS访问问题求助

问题

需要强制通过HTTPS访问Artifactory,但配置完成后仍无法访问https://server:1448,且无法使用反向代理。已按官方文档配置并重新部署,问题依旧。

启动命令

docker run -d \
           --name artifactory \
           --restart=always \
           -p 1446:8081 \
           -p 1447:8082 \
           -p 1448:8443 \
           -v /etc/localtime:/etc/localtime \
           -v /etc/localtime:/etc/timezone \
           -v /artifactory/var/:/var/opt/jfrog/artifactory \
           -v /artifactory/certs:/certs \
           releases-docker.jfrog.io/jfrog/artifactory-pro:7.84.16

system.yaml 配置

shared:
    ## Java 17 distribution to use
    #javaHome: "JFROG_HOME/artifactory/app/third-party/java"

    ## Extra Java options to pass to the JVM. These values add to or override the defaults.
    #extraJavaOpts: "-Xms512m -Xmx2g"

    ## Security Configuration
    security:
    ## Join key value for joining the cluster (takes precedence over 'joinKeyFile')
    #joinKey: "<Your joinKey>"

    ## Join key file location
    #joinKeyFile: "<For example: JFROG_HOME/artifactory/var/etc/security/join.key>"

    ## Master key file location
    ## Generated by the product on first startup if not provided
    #masterKeyFile: "<For example: JFROG_HOME/artifactory/var/etc/security/master.key>"

    ## Maximum time to wait for key files (master.key and join.key)
    #bootstrapKeysReadTimeoutSecs: 120

    ## Node Settings
    node:
    ## A unique id to identify this node.
    ## Default auto generated at startup.
    #id: "art1"

    ## Default auto resolved by startup script
    #ip:

    ## Sets this node as primary in HA installation
    #primary: true

    ## Sets this node as part of HA installation
    #haEnabled: true

    ## Database Configuration
    database:
        ## To run Artifactory with any database other than PostgreSQL allowNonPostgresql set to true.
        #allowNonPostgresql: false
        allowNonPostgresql: true

        ## One of mysql, oracle, mssql, postgresql, mariadb
        ## Default Embedded derby

        ## Example for postgresql
        #type: postgresql
        #driver: org.postgresql.Driver
        #url: "jdbc:postgresql://<your db url, for example: localhost:5432>/artifactory"
        #username: artifactory
        #password: password


## ARTIFACTORY TEMPLATE
artifactory:
  ## Artifactory Tomcat connector customization on the Artifactory port
  tomcat:
    ## Set up an HTTPS connector for artifactory. This opens a port 
    ## in addition to the default HTTP connector. All relevant 
    ## properties configured for the HTTP connector are applied also
    ## for this connector (e.g. "maxThreads")
    httpsConnector:
      ## Enable connector with SSL/TLS
      #enabled: false
      enabled: true

      ## Port to use for the HTTPS connector
      #port: 8443
      port: 8443

      ## Certificate file to use
      #certificateFile: "$JFROG_HOME/artifactory/var/etc/artifactory/security/ssl/server.crt"
      certificateFile: "/certs/server.crt"

      ## Certificate key file to use.
      #certificateKeyFile: "$JFROG_HOME/artifactory/var/etc/artifactory/security/ssl/server.key"
      certificateKeyFile: "/certs/server.key"

      ## Extra configuration for the HTTPS connector.
      ## For example extraConfig: "SSLProtocol='TLSv1+TLSv1.1+TLSv1.2'"
      #extraConfig: ""
access:
  security:
    tls: true

排查与解决建议
  • 检查证书权限与格式
    容器内/certs目录下的server.crt和server.key需确保Artifactory进程有读取权限。进入容器执行ls -l /certs查看权限,若权限不足,执行chmod 644 /certs/server.crt /certs/server.key;同时确认证书为PEM格式,无额外换行或错误字符。

  • 验证端口映射与防火墙
    执行netstat -tulnp | grep 1448检查宿主机1448端口是否被其他进程占用;同时确认宿主机防火墙/安全组已开放1448端口,允许外部HTTPS流量进入。

  • 查看Artifactory启动日志
    执行docker logs artifactory查看容器日志,重点查找HTTPS连接器初始化相关错误,比如证书加载失败、端口绑定失败等,这类日志会直接指明问题根源。

  • 补全Access服务的HTTPS配置
    Artifactory 7.x版本中Access服务独立运行,仅开启access.security.tls: true不足以完成配置,需补充完整的HTTPS连接器设置:

    access:
      security:
        tls: true
      tomcat:
        httpsConnector:
          enabled: true
          port: 8443
          certificateFile: "/certs/server.crt"
          certificateKeyFile: "/certs/server.key"
    
  • 确认配置文件路径与生效状态
    确保system.yaml位于宿主机/artifactory/var/etc/目录下(对应容器内/var/opt/jfrog/artifactory/etc/system.yaml),修改配置后需重启容器使设置生效。


内容的提问来源于stack exchange,提问作者Viewer

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.21 10:45:05