Spring Cloud Gateway集成HTTP2调用微服务报错排查咨询
Spring Cloud WebFlux 启用HTTP2网关调用报错问题
问题背景
我有一个Spring Cloud WebFlux应用,希望启用HTTP2协议。通过Keystore Explorer生成证书和密钥后,在网关与微服务中配置如下:
server: ssl: key-store: classpath:ssl.pfx key-store-password: password keyStoreType: PKCS12 key-password: password enabled: true http2: enabled: true
将ssl.pfx文件放置在网关和微服务的resources目录下后,通过网关向微服务发起GET请求时出现报错:
微服务端错误日志
2024-06-17T15:22:04.048+03:00 WARN 14896 --- [my-service] [tor-http-nio-10] .s.ApplicationProtocolNegotiationHandler : [id: 0x5853edda, L:/192.168.78.78:54840 - R:/192.168.78.78:56587] Failed to select the application-level protocol: io.netty.handler.ssl.NotSslRecordException: not an SSL/TLS record ....
网关端错误日志
reactor.netty.http.client.PrematureCloseException: Connection prematurely closed BEFORE response Suppressed: reactor.core.publisher.FluxOnAssembly$OnAssemblyException: Error has been observed at the following site(s): *__checkpoint ⇢ org.springframework.cloud.gateway.filter.WeightCalculatorWebFilter [DefaultWebFilterChain] *__checkpoint ⇢ AuthorizationWebFilter [DefaultWebFilterChain] *__checkpoint ⇢ ExceptionTranslationWebFilter [DefaultWebFilterChain] *__checkpoint ⇢ LogoutWebFilter [DefaultWebFilterChain] *__checkpoint ⇢ ServerRequestCacheWebFilter [DefaultWebFilterChain] *__checkpoint ⇢ SecurityContextServerWebExchangeWebFilter [DefaultWebFilterChain] *__checkpoint ⇢ AuthenticationWebFilter [DefaultWebFilterChain] *__checkpoint ⇢ ReactorContextWebFilter [DefaultWebFilterChain] *__checkpoint ⇢ HttpHeaderWriterWebFilter [DefaultWebFilterChain] *__checkpoint ⇢ ServerWebExchangeReactorContextWebFilter [DefaultWebFilterChain] *__checkpoint ⇢ org.springframework.security.web.server.WebFilterChainProxy [DefaultWebFilterChain]
直接通过https://调用微服务可正常运行,浏览器显示使用H2协议,但通过网关调用则失败。我有两个问题:
- 我哪里配置出错了?
- 是否可以让网关支持HTTP2协议?
目前相关配置案例较少,仅看到部分gRPC相关文章,理论上仅使用H2即可实现。
问题解答
1. 配置错误分析
报错核心是微服务端收到了非SSL/TLS请求,说明网关向微服务发起调用时用的是http而非https协议——但你的微服务已经开启了SSL强制加密,自然无法解析非SSL请求。
常见原因:
- 网关路由配置的微服务地址是
http协议(比如默认的lb://my-service会走http),没有指定https; - 网关内部HTTP客户端未开启HTTP2 over SSL支持,导致转发时无法适配微服务的HTTP2+SSL配置。
2. 网关支持HTTP2的实现方案
完全可以让Spring Cloud Gateway支持HTTP2,需分两部分配置:
(1)网关对外提供HTTP2服务
你当前的网关配置已经开启了server.http2.enabled=true和SSL,这部分是正确的,外部客户端可以通过https://网关地址用HTTP2协议访问网关。
(2)网关内部转发请求到微服务时启用HTTP2 over SSL
需要调整路由配置和客户端HTTP2支持:
- 路由配置:确保路由的URI使用
https协议,比如将lb://my-service改为lb://https://my-service,或者直接指定微服务的https地址; - 启用网关客户端HTTP2支持:在网关配置中添加Reactor Netty客户端的HTTP2配置:
spring: cloud: gateway: httpclient: http2: enabled: true ssl: use-insecure-trust-manager: true # 测试环境临时开启,生产环境禁用
生产环境需替换为信任微服务证书的配置:
spring: cloud: gateway: httpclient: ssl: trust-store: classpath:truststore.pfx trust-store-password: password trust-store-type: PKCS12
补充注意事项
- 微服务的SSL配置需确保正确,且证书在网关的信任列表中(生产环境必须);
- 若使用服务发现组件(如Eureka),需确保服务注册的是https端口,或在路由中显式指定https协议和端口;
- 检查网关路由过滤器,避免存在强制将请求转为http的逻辑。
内容的提问来源于stack exchange,提问作者Арчи
相关产品推荐
相关产品推荐

