You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Ubuntu22.04下无需Hitch配置Apache作为Varnish反向代理

Varnish Cache 7 + Apache2 纯组合HTTPS配置方案

核心思路

Varnish本身不支持TLS加密终止,所以让Apache承担HTTPS解密的角色,请求流转逻辑如下:

  • 客户端HTTPS请求先到Apache 443端口,完成SSL解密
  • Apache将解密后的HTTP请求转发给Varnish 80端口处理缓存逻辑
  • Varnish把未命中缓存的请求转发给Apache 8080端口(后端应用服务器)
  • 响应结果按原路返回给客户端

是否必须使用两个虚拟主机?

不是强制要求,但强烈建议分开配置:一个虚拟主机监听8080作为后端应用载体,另一个监听443专门处理HTTPS终止和反向代理。这样职责划分清晰,后续修改、排查问题更方便。如果想简化,也可以用<VirtualHost *:8080 *:443>合并配置,但分开管理的容错性更高。

修正后的完整配置

1. Apache 后端应用虚拟主机(8080端口)

这个配置作为Varnish的后端服务,保持原有逻辑即可:

<VirtualHost *:8080>
    ServerName mycloud.com
    DocumentRoot /var/www/mycloud.com

    <Directory /var/www/mycloud.com>
                Options Indexes FollowSymLinks
                AllowOverride All
                Order allow,deny
                allow from all
    </Directory>
    
    ErrorLog ${APACHE_LOG_DIR}/error.log
    CustomLog ${APACHE_LOG_DIR}/access.log combined    
</VirtualHost>

2. Apache HTTPS 终止虚拟主机(443端口)

修改反向代理规则,将所有请求转发给Varnish,并修正头信息传递逻辑:

<IfModule mod_ssl.c>
<VirtualHost *:443>
    ServerName mycloud.com
    
    ErrorLog ${APACHE_LOG_DIR}/https_error.log
    CustomLog ${APACHE_LOG_DIR}/https_access.log combined

    Include /etc/letsencrypt/options-ssl-apache.conf
    SSLCertificateFile /etc/letsencrypt/live/mycloud.com/fullchain.pem
    SSLCertificateKeyFile /etc/letsencrypt/live/mycloud.com/privkey.pem
    
    # 禁用正向代理,启用反向代理模式
    ProxyRequests Off
    ProxyPreserveHost On
    ProxyAddHeaders On
    
    # 将所有请求转发给Varnish的80端口
    ProxyPass / http://127.0.0.1:80/
    ProxyPassReverse / http://127.0.0.1:80/
   
    # 传递HTTPS标识头,让Varnish和后端知道请求来自HTTPS
    RequestHeader set X-Forwarded-Proto "https"
    RequestHeader set X-Forwarded-Port "443"
</VirtualHost>
</IfModule>

3. Varnish VCL配置

调整头信息处理逻辑,确保HTTPS标识正确传递:

vcl 4.0;

backend default {
    .host = "127.0.0.1";
    .port = "8080";
}

sub vcl_recv {
    # 保留HTTPS标识头,传递给后端应用
    if (req.http.X-Forwarded-Proto) {
        set req.http.X-Forwarded-Proto = req.http.X-Forwarded-Proto;
    }
    # 可选:强制HTTP请求跳转到HTTPS(取消注释启用)
    # if (req.http.X-Forwarded-Proto != "https" && req.port != 443) {
    #     return (synth(750, ""));
    # }
}

sub vcl_synth {
    # 实现HTTP到HTTPS的跳转逻辑(对应上面的强制跳转规则)
    if (resp.status == 750) {
        set resp.status = 301;
        set resp.http.Location = "https://" + req.http.host + req.url;
        return (deliver);
    }
}

sub vcl_backend_response {
    # 确保缓存对象携带HTTPS标识
    if (bereq.http.X-Forwarded-Proto == "https") {
        set beresp.http.X-Forwarded-Proto = "https";
    }
    unset beresp.http.X-Varnish;
}

sub vcl_deliver {
    if (obj.hits > 0) {
        set resp.http.X-Cache = "HIT";
        set resp.http.X-Cache-Hits = obj.hits;
    } else {
        set resp.http.X-Cache = "MISS";
    }
    # 可选:在响应头中显示HTTPS状态
    set resp.http.X-Forwarded-Proto = req.http.X-Forwarded-Proto;
}

4. Varnish服务配置

保持现有配置不变,确保Varnish监听80端口:

[Unit]
Description=Varnish Cache, a high-performance HTTP accelerator
Documentation=https://www.varnish-cache.org/docs/ man:varnishd

[Service]
Type=simple

LimitNOFILE=131072
LimitMEMLOCK=85983232
ExecStart=/usr/sbin/varnishd \
          -j unix,user=vcache \
          -F \
          -a :80 \
          -a localhost:6092,PROXY \
          -p feature=+http2 \
          -f /etc/varnish/default.vcl \
          -s malloc,256m

ExecReload=/usr/share/varnish/varnishreload
ProtectSystem=full
ProtectHome=true
PrivateTmp=true
PrivateDevices=true

[Install]
WantedBy=multi-user.target

配置验证步骤

  1. 重启Apache服务:systemctl restart apache2
  2. 重启Varnish服务:systemctl restart varnish
  3. 测试HTTPS请求:curl -v https://mycloud.com,查看响应头中的X-Cache字段确认缓存生效
  4. 检查日志:查看Apache的https_access.log和Varnish日志,确认请求流转正常

内容的提问来源于stack exchange,提问作者Muhammad Aslam

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.21 14:57:01