You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Cloud Gateway集成HTTP2调用微服务报错排查咨询

Spring Cloud WebFlux 启用HTTP2网关调用报错问题

问题背景

我有一个Spring Cloud WebFlux应用,希望启用HTTP2协议。通过Keystore Explorer生成证书和密钥后,在网关与微服务中配置如下:

server:
  ssl:
    key-store: classpath:ssl.pfx
    key-store-password: password
    keyStoreType: PKCS12
    key-password: password
    enabled: true
  http2:
    enabled: true

将ssl.pfx文件放置在网关和微服务的resources目录下后,通过网关向微服务发起GET请求时出现报错:

微服务端错误日志

2024-06-17T15:22:04.048+03:00  WARN 14896 --- [my-service] [tor-http-nio-10] .s.ApplicationProtocolNegotiationHandler : [id: 0x5853edda, L:/192.168.78.78:54840 - R:/192.168.78.78:56587] Failed to select the application-level protocol:

io.netty.handler.ssl.NotSslRecordException: not an SSL/TLS record ....

网关端错误日志

reactor.netty.http.client.PrematureCloseException: Connection prematurely closed BEFORE response
    Suppressed: reactor.core.publisher.FluxOnAssembly$OnAssemblyException: 
Error has been observed at the following site(s):
    *__checkpoint ⇢ org.springframework.cloud.gateway.filter.WeightCalculatorWebFilter [DefaultWebFilterChain]
    *__checkpoint ⇢ AuthorizationWebFilter [DefaultWebFilterChain]
    *__checkpoint ⇢ ExceptionTranslationWebFilter [DefaultWebFilterChain]
    *__checkpoint ⇢ LogoutWebFilter [DefaultWebFilterChain]
    *__checkpoint ⇢ ServerRequestCacheWebFilter [DefaultWebFilterChain]
    *__checkpoint ⇢ SecurityContextServerWebExchangeWebFilter [DefaultWebFilterChain]
    *__checkpoint ⇢ AuthenticationWebFilter [DefaultWebFilterChain]
    *__checkpoint ⇢ ReactorContextWebFilter [DefaultWebFilterChain]
    *__checkpoint ⇢ HttpHeaderWriterWebFilter [DefaultWebFilterChain]
    *__checkpoint ⇢ ServerWebExchangeReactorContextWebFilter [DefaultWebFilterChain]
    *__checkpoint ⇢ org.springframework.security.web.server.WebFilterChainProxy [DefaultWebFilterChain]

直接通过https://调用微服务可正常运行,浏览器显示使用H2协议,但通过网关调用则失败。我有两个问题:

  1. 我哪里配置出错了?
  2. 是否可以让网关支持HTTP2协议?

目前相关配置案例较少,仅看到部分gRPC相关文章,理论上仅使用H2即可实现。


问题解答

1. 配置错误分析

报错核心是微服务端收到了非SSL/TLS请求,说明网关向微服务发起调用时用的是http而非https协议——但你的微服务已经开启了SSL强制加密,自然无法解析非SSL请求。

常见原因:

  • 网关路由配置的微服务地址是http协议(比如默认的lb://my-service会走http),没有指定https;
  • 网关内部HTTP客户端未开启HTTP2 over SSL支持,导致转发时无法适配微服务的HTTP2+SSL配置。

2. 网关支持HTTP2的实现方案

完全可以让Spring Cloud Gateway支持HTTP2,需分两部分配置:

(1)网关对外提供HTTP2服务

你当前的网关配置已经开启了server.http2.enabled=true和SSL,这部分是正确的,外部客户端可以通过https://网关地址用HTTP2协议访问网关。

(2)网关内部转发请求到微服务时启用HTTP2 over SSL

需要调整路由配置和客户端HTTP2支持:

  • 路由配置:确保路由的URI使用https协议,比如将lb://my-service改为lb://https://my-service,或者直接指定微服务的https地址;
  • 启用网关客户端HTTP2支持:在网关配置中添加Reactor Netty客户端的HTTP2配置:
spring:
  cloud:
    gateway:
      httpclient:
        http2:
          enabled: true
        ssl:
          use-insecure-trust-manager: true # 测试环境临时开启,生产环境禁用

生产环境需替换为信任微服务证书的配置:

spring:
  cloud:
    gateway:
      httpclient:
        ssl:
          trust-store: classpath:truststore.pfx
          trust-store-password: password
          trust-store-type: PKCS12

补充注意事项

  • 微服务的SSL配置需确保正确,且证书在网关的信任列表中(生产环境必须);
  • 若使用服务发现组件(如Eureka),需确保服务注册的是https端口,或在路由中显式指定https协议和端口;
  • 检查网关路由过滤器,避免存在强制将请求转为http的逻辑。

内容的提问来源于stack exchange,提问作者Арчи

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.22 07:54:59