AWS上Spring Boot+Nginx文件上传异常:1KB正常250KB报403禁止
问题
在AWS上运行的Spring Boot应用,用于向S3上传文件。1KB的TXT文件上传正常,但250KB的TXT文件上传时返回403 Forbidden错误,且Nginx的访问/错误日志无任何记录,请求也未到达Tomcat。即使移除了保存到磁盘/S3的逻辑,仍会立即触发403 Forbidden错误。
控制器代码
@GetMapping("/inputuploads") public String listInputUploads(Model model) { logger.info("Renedering upload page"); return "inputuploads"; } @PostMapping("/inputuploads") public String saveFile(Model model, @RequestParam("file") MultipartFile file, RedirectAttributes ra) throws IOException { logger.info("Saving file:"+file.getOriginalFilename()); ra.addFlashAttribute("message","Uploaded file: "+ file.getOriginalFilename()); return "redirect:/inputuploads"; }
模板代码
<div th:if="${message}"> <div th:text="${message}"> </div> </div> <div > <form method="post" th:action="@{/inputuploads}" enctype="multipart/form-data" > <div> <input type="file" name="file" accept=".xlsm" > </div> <div> <button type="submit" >Upload</button> </div> </form> </div>
application.yml配置
spring: servlet: multipart: max-file-size: 100MB max-request-size: 100MB server: port: 5000 tomcat: max-swallow-size: -1
.platform/nginx/nginx.conf配置
user nginx; error_log /var/log/nginx/error.log warn; pid /var/run/nginx.pid; worker_processes auto; worker_rlimit_nofile 32633; events { worker_connections 1024; } http { include /etc/nginx/mime.types; default_type application/octet-stream; log_format main '$remote_addr - $remote_user [$time_local] "$request" ' '$status $body_bytes_sent "$http_referer" ' '"$http_user_agent" "$http_x_forwarded_for"'; include conf.d/*.conf; map $http_upgrade $connection_upgrade { default "upgrade"; } server { listen 80; return 301 https://$host$request_uri; } server { listen 443 ssl default_server; ssl_certificate certificates/localhost.crt; ssl_certificate_key certificates/localhost.key; access_log /var/log/nginx/access.log main; client_header_timeout 1d; client_body_timeout 1d; client_max_body_size 100M; keepalive_timeout 1d; proxy_connect_timeout 1d; proxy_read_timeout 1d; proxy_send_timeout 1d; gzip off; gzip_comp_level 4; gzip_types text/plain text/css application/json application/javascript application/x-javascript text/xml application/xml application/xml+rss text/javascript; include conf.d/elasticbeanstalk/*.conf; } }
.platform/nginx/conf.d/client_max_body_size.conf配置
client_max_body_size 100M;
.platform/nginx/conf.d/elasticbeanstalk/00_application.conf配置
location / { proxy_pass http://127.0.0.1:5000; proxy_http_version 1.1; proxy_set_header Connection $connection_upgrade; proxy_set_header Upgrade $http_upgrade; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; }
.ebextensions/00-set-timezone.config配置
commands: set_time_zone: command: ln -f -s /usr/share/zoneinfo/Asia/Kolkata /etc/localtime
解决方案
由于请求既没进入Nginx日志,也未到达Tomcat,问题大概率出在AWS前端防护组件或平台配置层面,按以下步骤排查:
1. 检查WAF(Web应用防火墙)规则
若Elastic Beanstalk环境关联了WAF Web ACL,登录AWS控制台进入WAF服务,查看是否有拦截请求体大小的规则,或恶意请求检测规则误触发了403。调整规则阈值,添加允许100MB请求体的白名单规则。
2. 验证ALB(应用负载均衡器)配置
- 开启ALB访问日志,上传大文件后查看日志,确认请求是否到达ALB,以及返回403的具体原因(日志中会标记如
waf_blocked等字段)。 - 检查ALB是否有默认的请求大小限制,部分场景下ALB会在Nginx之前拦截超大请求。
3. 确认Nginx配置是否生效
登录EC2实例执行以下命令:
# 测试配置合法性 nginx -t # 重载配置 nginx -s reload # 确认client_max_body_size配置存在 cat /etc/nginx/conf.d/client_max_body_size.conf
若.platform目录配置未生效,改用.ebextensions添加Nginx配置:
files: "/etc/nginx/conf.d/00_client_max_body_size.conf": mode: "000644" owner: root group: root content: | client_max_body_size 100M;
4. 排查其他安全组件
- 检查AWS Shield Advanced是否有防护规则拦截大请求。
- 确认EC2实例的IAM角色权限无临时变更(小文件能正常上传,此概率较低)。
内容的提问来源于stack exchange,提问作者itsraja
相关产品推荐
相关产品推荐

