无法使用Artifactory HTTPS访问问题求助
需要强制通过HTTPS访问Artifactory,但配置完成后仍无法访问https://server:1448,且无法使用反向代理。已按官方文档配置并重新部署,问题依旧。
启动命令
docker run -d \ --name artifactory \ --restart=always \ -p 1446:8081 \ -p 1447:8082 \ -p 1448:8443 \ -v /etc/localtime:/etc/localtime \ -v /etc/localtime:/etc/timezone \ -v /artifactory/var/:/var/opt/jfrog/artifactory \ -v /artifactory/certs:/certs \ releases-docker.jfrog.io/jfrog/artifactory-pro:7.84.16
system.yaml 配置
shared: ## Java 17 distribution to use #javaHome: "JFROG_HOME/artifactory/app/third-party/java" ## Extra Java options to pass to the JVM. These values add to or override the defaults. #extraJavaOpts: "-Xms512m -Xmx2g" ## Security Configuration security: ## Join key value for joining the cluster (takes precedence over 'joinKeyFile') #joinKey: "<Your joinKey>" ## Join key file location #joinKeyFile: "<For example: JFROG_HOME/artifactory/var/etc/security/join.key>" ## Master key file location ## Generated by the product on first startup if not provided #masterKeyFile: "<For example: JFROG_HOME/artifactory/var/etc/security/master.key>" ## Maximum time to wait for key files (master.key and join.key) #bootstrapKeysReadTimeoutSecs: 120 ## Node Settings node: ## A unique id to identify this node. ## Default auto generated at startup. #id: "art1" ## Default auto resolved by startup script #ip: ## Sets this node as primary in HA installation #primary: true ## Sets this node as part of HA installation #haEnabled: true ## Database Configuration database: ## To run Artifactory with any database other than PostgreSQL allowNonPostgresql set to true. #allowNonPostgresql: false allowNonPostgresql: true ## One of mysql, oracle, mssql, postgresql, mariadb ## Default Embedded derby ## Example for postgresql #type: postgresql #driver: org.postgresql.Driver #url: "jdbc:postgresql://<your db url, for example: localhost:5432>/artifactory" #username: artifactory #password: password ## ARTIFACTORY TEMPLATE artifactory: ## Artifactory Tomcat connector customization on the Artifactory port tomcat: ## Set up an HTTPS connector for artifactory. This opens a port ## in addition to the default HTTP connector. All relevant ## properties configured for the HTTP connector are applied also ## for this connector (e.g. "maxThreads") httpsConnector: ## Enable connector with SSL/TLS #enabled: false enabled: true ## Port to use for the HTTPS connector #port: 8443 port: 8443 ## Certificate file to use #certificateFile: "$JFROG_HOME/artifactory/var/etc/artifactory/security/ssl/server.crt" certificateFile: "/certs/server.crt" ## Certificate key file to use. #certificateKeyFile: "$JFROG_HOME/artifactory/var/etc/artifactory/security/ssl/server.key" certificateKeyFile: "/certs/server.key" ## Extra configuration for the HTTPS connector. ## For example extraConfig: "SSLProtocol='TLSv1+TLSv1.1+TLSv1.2'" #extraConfig: "" access: security: tls: true
检查证书权限与格式
容器内/certs目录下的server.crt和server.key需确保Artifactory进程有读取权限。进入容器执行ls -l /certs查看权限,若权限不足,执行chmod 644 /certs/server.crt /certs/server.key;同时确认证书为PEM格式,无额外换行或错误字符。验证端口映射与防火墙
执行netstat -tulnp | grep 1448检查宿主机1448端口是否被其他进程占用;同时确认宿主机防火墙/安全组已开放1448端口,允许外部HTTPS流量进入。查看Artifactory启动日志
执行docker logs artifactory查看容器日志,重点查找HTTPS连接器初始化相关错误,比如证书加载失败、端口绑定失败等,这类日志会直接指明问题根源。补全Access服务的HTTPS配置
Artifactory 7.x版本中Access服务独立运行,仅开启access.security.tls: true不足以完成配置,需补充完整的HTTPS连接器设置:access: security: tls: true tomcat: httpsConnector: enabled: true port: 8443 certificateFile: "/certs/server.crt" certificateKeyFile: "/certs/server.key"确认配置文件路径与生效状态
确保system.yaml位于宿主机/artifactory/var/etc/目录下(对应容器内/var/opt/jfrog/artifactory/etc/system.yaml),修改配置后需重启容器使设置生效。
内容的提问来源于stack exchange,提问作者Viewer

