Ubuntu22.04下无需Hitch配置Apache作为Varnish反向代理
Varnish Cache 7 + Apache2 纯组合HTTPS配置方案
核心思路
Varnish本身不支持TLS加密终止,所以让Apache承担HTTPS解密的角色,请求流转逻辑如下:
- 客户端HTTPS请求先到Apache 443端口,完成SSL解密
- Apache将解密后的HTTP请求转发给Varnish 80端口处理缓存逻辑
- Varnish把未命中缓存的请求转发给Apache 8080端口(后端应用服务器)
- 响应结果按原路返回给客户端
是否必须使用两个虚拟主机?
不是强制要求,但强烈建议分开配置:一个虚拟主机监听8080作为后端应用载体,另一个监听443专门处理HTTPS终止和反向代理。这样职责划分清晰,后续修改、排查问题更方便。如果想简化,也可以用<VirtualHost *:8080 *:443>合并配置,但分开管理的容错性更高。
修正后的完整配置
1. Apache 后端应用虚拟主机(8080端口)
这个配置作为Varnish的后端服务,保持原有逻辑即可:
<VirtualHost *:8080> ServerName mycloud.com DocumentRoot /var/www/mycloud.com <Directory /var/www/mycloud.com> Options Indexes FollowSymLinks AllowOverride All Order allow,deny allow from all </Directory> ErrorLog ${APACHE_LOG_DIR}/error.log CustomLog ${APACHE_LOG_DIR}/access.log combined </VirtualHost>
2. Apache HTTPS 终止虚拟主机(443端口)
修改反向代理规则,将所有请求转发给Varnish,并修正头信息传递逻辑:
<IfModule mod_ssl.c> <VirtualHost *:443> ServerName mycloud.com ErrorLog ${APACHE_LOG_DIR}/https_error.log CustomLog ${APACHE_LOG_DIR}/https_access.log combined Include /etc/letsencrypt/options-ssl-apache.conf SSLCertificateFile /etc/letsencrypt/live/mycloud.com/fullchain.pem SSLCertificateKeyFile /etc/letsencrypt/live/mycloud.com/privkey.pem # 禁用正向代理,启用反向代理模式 ProxyRequests Off ProxyPreserveHost On ProxyAddHeaders On # 将所有请求转发给Varnish的80端口 ProxyPass / http://127.0.0.1:80/ ProxyPassReverse / http://127.0.0.1:80/ # 传递HTTPS标识头,让Varnish和后端知道请求来自HTTPS RequestHeader set X-Forwarded-Proto "https" RequestHeader set X-Forwarded-Port "443" </VirtualHost> </IfModule>
3. Varnish VCL配置
调整头信息处理逻辑,确保HTTPS标识正确传递:
vcl 4.0; backend default { .host = "127.0.0.1"; .port = "8080"; } sub vcl_recv { # 保留HTTPS标识头,传递给后端应用 if (req.http.X-Forwarded-Proto) { set req.http.X-Forwarded-Proto = req.http.X-Forwarded-Proto; } # 可选:强制HTTP请求跳转到HTTPS(取消注释启用) # if (req.http.X-Forwarded-Proto != "https" && req.port != 443) { # return (synth(750, "")); # } } sub vcl_synth { # 实现HTTP到HTTPS的跳转逻辑(对应上面的强制跳转规则) if (resp.status == 750) { set resp.status = 301; set resp.http.Location = "https://" + req.http.host + req.url; return (deliver); } } sub vcl_backend_response { # 确保缓存对象携带HTTPS标识 if (bereq.http.X-Forwarded-Proto == "https") { set beresp.http.X-Forwarded-Proto = "https"; } unset beresp.http.X-Varnish; } sub vcl_deliver { if (obj.hits > 0) { set resp.http.X-Cache = "HIT"; set resp.http.X-Cache-Hits = obj.hits; } else { set resp.http.X-Cache = "MISS"; } # 可选:在响应头中显示HTTPS状态 set resp.http.X-Forwarded-Proto = req.http.X-Forwarded-Proto; }
4. Varnish服务配置
保持现有配置不变,确保Varnish监听80端口:
[Unit] Description=Varnish Cache, a high-performance HTTP accelerator Documentation=https://www.varnish-cache.org/docs/ man:varnishd [Service] Type=simple LimitNOFILE=131072 LimitMEMLOCK=85983232 ExecStart=/usr/sbin/varnishd \ -j unix,user=vcache \ -F \ -a :80 \ -a localhost:6092,PROXY \ -p feature=+http2 \ -f /etc/varnish/default.vcl \ -s malloc,256m ExecReload=/usr/share/varnish/varnishreload ProtectSystem=full ProtectHome=true PrivateTmp=true PrivateDevices=true [Install] WantedBy=multi-user.target
配置验证步骤
- 重启Apache服务:
systemctl restart apache2 - 重启Varnish服务:
systemctl restart varnish - 测试HTTPS请求:
curl -v https://mycloud.com,查看响应头中的X-Cache字段确认缓存生效 - 检查日志:查看Apache的
https_access.log和Varnish日志,确认请求流转正常
内容的提问来源于stack exchange,提问作者Muhammad Aslam
相关产品推荐
相关产品推荐

