You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Amazon Linux实例部署httpd返回403 Forbidden问题求助

问题描述

我通过AWS CDK部署了搭载Amazon Linux镜像的EC2 Auto Scaling Group,并在实例中安装了httpd服务。但在实例内执行curl http://localhost -I时返回403 Forbidden错误,响应信息如下:

sh-4.2$ curl http://localhost -I
HTTP/1.1 403 Forbidden
Date: Thu, 16 May 2024 04:12:52 GMT
Server: Apache/2.4.59 ()
Upgrade: h2,h2c
Connection: Upgrade
Last-Modified: Mon, 22 Apr 2024 13:06:15 GMT
ETag: "e2e-616af1a347fc0"
Accept-Ranges: bytes
Content-Length: 3630
Content-Type: text/html; charset=UTF-8

使用的AWS CDK代码:

from aws_cdk import (
    # Duration,
    Stack,
    CfnOutput,
    aws_ec2 as _ec2,
    aws_iam as _iam,
    aws_autoscaling as _autoscaling,
    aws_elasticloadbalancingv2 as _elbv2,
    # aws_sqs as sqs,
)
from constructs import Construct

class WebServerStack(Stack):

    def __init__(self, scope: Construct, construct_id: str, vpc, **kwargs) -> None:
        super().__init__(scope, construct_id, **kwargs)

        # Read bootstrap script 
        with open("bootstrap_scripts/install_httpd.sh",
                  mode="r") as fp:
            user_data = fp.read()

        # Get latest ami
        amzn_linux_ami = _ec2.AmazonLinuxImage(
            generation=_ec2.AmazonLinuxGeneration.AMAZON_LINUX_2,
            edition=_ec2.AmazonLinuxEdition.STANDARD,
            storage=_ec2.AmazonLinuxStorage.GENERAL_PURPOSE,
            virtualization=_ec2.AmazonLinuxVirt.HVM,
        )

        # Create Application load balancer
        alb = _elbv2.ApplicationLoadBalancer(
            self,
            "myAlbId",
            vpc=vpc,
            internet_facing=True,
            load_balancer_name="WebServerAlb",
        )

        # Allow from internet
        alb.connections.allow_from_any_ipv4(
            _ec2.Port.tcp(80),
            description="Allow Internet access on ALB Port 80",
        )

        # Add listener to ALB
        listener = alb.add_listener("listenerId",
                                    port=80,
                                    open=True)

        # Webserver IAM role
        web_server_role = _iam.Role(
            self,
            "webServerRoleId",
            assumed_by=_iam.ServicePrincipal("ec2.amazonaws.com"),
            managed_policies=[
                _iam.ManagedPolicy.from_aws_managed_policy_name(
                    'AmazonSSMManagedInstanceCore'
                ),
                _iam.ManagedPolicy.from_aws_managed_policy_name(
                    'AmazonS3ReadOnlyAccess'
                ),
            ]
        )

        # Create AutoScaling Group with 2 EC2 Instances
        web_server_asg = _autoscaling.AutoScalingGroup(
            self,
            "webServerAsgId",
            vpc=vpc,
            vpc_subnets=_ec2.SubnetSelection(
                subnet_type=_ec2.SubnetType.PRIVATE_WITH_EGRESS,
            ),
            instance_type=_ec2.InstanceType(
                instance_type_identifier="t2.micro"
            ),
            machine_image=amzn_linux_ami,
            role=web_server_role,
            min_capacity=2,
            max_capacity=2,
            # desired_capacity=2,
            user_data=_ec2.UserData.custom(
                user_data
            )
        )

        # Allow ASG Security Group receive traffic from ALB
        web_server_asg.connections.allow_from(
            alb,
            _ec2.Port.tcp(80),
            description="Allow ASG Security Group receive traffic from ALB"
        )

        listener.add_targets(
            "listenerId",
            port=80,
            targets=[web_server_asg]
        )

        # Output of the ALB Domain Name
        output_alb_1 = CfnOutput(
            self,
            "albDomainName",
            value=f"http://{alb.load_balancer_dns_name}",
            description="Web Server ALB Domain Name"
        )

启动脚本bootstrap_scripts/install_httpd.sh内容:

#!/bin/bash
sudo yum install -y httpd
sudo chkconfig httpd on
sudo service httpd start
原因分析

出现403 Forbidden的核心原因是Apache默认没有可访问的首页文件,且默认配置禁止列出目录内容。

在Amazon Linux 2上,httpd安装后的网站根目录为/var/www/html,但该目录初始为空,没有index.html或Apache默认识别的首页文件。当请求http://localhost时,Apache找不到首页文件,又因默认配置不允许显示目录内容,就会返回403错误。你的启动脚本仅完成了httpd的安装和启动,未添加任何可访问的内容文件,这直接导致了访问被拒绝。

解决方案

修改启动脚本,在安装启动httpd后,添加一个默认首页文件到/var/www/html目录即可:

#!/bin/bash
sudo yum install -y httpd
sudo chkconfig httpd on
# 添加自定义首页文件
echo "<html><body><h1>Hello from EC2 Auto Scaling Group</h1></body></html>" | sudo tee /var/www/html/index.html
sudo service httpd start

也可以复制系统自带的测试页面到网站根目录替代:

sudo cp /usr/share/httpd/noindex/index.html /var/www/html/

修改后重新部署ASG,实例启动完成后再执行curl http://localhost -I,即可返回200 OK的响应。


内容的提问来源于stack exchange,提问作者NPatel

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.24 00:54:54