通过HTTP代理连接云端ActiveMQ Artemis失败的问题排查
问题描述
本地服务器所有公网流量均通过代理转发,已配置https_proxy和http_proxy环境变量,需连接云端带公网IP的ActiveMQ Artemis实例。当前curl访问管理控制台正常,但telnet <ip> 61616超时。
broker.xml中的acceptor配置:
<acceptor name="artemis">tcp://0.0.0.0:61616?tcpSendBufferSize=1048576;tcpReceiveBufferSize=1048576;amqpMinLargeMessageSize=102400;protocols=CORE,AMQP,STOMP,HORNETQ,MQTT,OPENWIRE;useEpoll=true;amqpCredits=1000;amqpLowCredits=300;amqpDuplicateDetection=true;supportAdvisory=false;suppressInternalManagementObjects=false</acceptor>
尝试使用Netty over HTTP协议连接,执行命令:
artemis producer --url "tcp://<ip>:61616?httpEnabled=true" --user "artemis" --password "artemis" --message-count 1
仍超时,报错:
Exception in thread "main" javax.jms.JMSException: Failed to create session factory at org.apache.activemq.artemis.jms.client.ActiveMQConnectionFactory.createConnectionInternal(ActiveMQConnectionFactory.java:915) at org.apache.activemq.artemis.jms.client.ActiveMQConnectionFactory.createConnection(ActiveMQConnectionFactory.java:314) at org.apache.activemq.artemis.jms.client.ActiveMQConnectionFactory.createConnection(ActiveMQConnectionFactory.java:309) at org.apache.activemq.artemis.cli.commands.messages.Producer.execute(Producer.java:142) at org.apache.activemq.artemis.cli.Artemis.internalExecute(Artemis.java:219) at org.apache.activemq.artemis.cli.Artemis.execute(Artemis.java:165) at java.base/jdk.internal.reflect.NativeMethodAccessorImpl.invoke0(Native Method) at java.base/jdk.internal.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:77) at java.base/jdk.internal.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43) at java.base/java.lang.reflect.Method.invoke(Method.java:568) at org.apache.activemq.artemis.boot.Artemis.execute(Artemis.java:157) at org.apache.activemq.artemis.boot.Artemis.main(Artemis.java:64) Caused by: ActiveMQNotConnectedException[errorType=NOT_CONNECTED message=AMQ219007: Cannot connect to server(s). Tried with all available servers.] at org.apache.activemq.artemis.core.client.impl.ServerLocatorImpl.createSessionFactory(ServerLocatorImpl.java:735) at org.apache.activemq.artemis.jms.client.ActiveMQConnectionFactory.createConnectionInternal(ActiveMQConnectionFactory.java:913) ... 11 more
解决思路与方案
1. 处理TCP流量的代理适配
http_proxy和https_proxy仅对HTTP/HTTPS流量生效,原生TCP连接(如telnet、Artemis默认TCP协议)不会自动走这些代理。若环境强制所有公网流量走代理,可按以下方式处理:
- 若代理服务器支持SOCKS协议,设置SOCKS代理环境变量:
export SOCKS_PROXY=socks://<proxy-ip>:<proxy-port> - 或使用
proxychains-ng等工具转发TCP流量,配置后用proxychains telnet <ip> 61616测试连通性。
2. 正确配置Netty over HTTP
httpEnabled=true需要服务端和客户端配合,且客户端需明确指定代理信息:
- 服务端调整:在broker.xml的acceptor中添加
httpUpgradeEnabled=true参数,开启HTTP隧道支持:<acceptor name="artemis">tcp://0.0.0.0:61616?tcpSendBufferSize=1048576;tcpReceiveBufferSize=1048576;amqpMinLargeMessageSize=102400;protocols=CORE,AMQP,STOMP,HORNETQ,MQTT,OPENWIRE;useEpoll=true;amqpCredits=1000;amqpLowCredits=300;amqpDuplicateDetection=true;supportAdvisory=false;suppressInternalManagementObjects=false;httpUpgradeEnabled=true</acceptor> - 客户端调整:连接URL中加入代理地址参数:
替换artemis producer --url "tcp://<ip>:61616?httpEnabled=true;httpProxyHost=<proxy-ip>;httpProxyPort=<proxy-port>" --user "artemis" --password "artemis" --message-count 1<proxy-ip>和<proxy-port>为实际代理地址。
3. 检查云端端口放行状态
确认云端服务器的安全组/防火墙已开放61616端口的入站规则,允许本地服务器的公网IP访问。即使管理控制台可访问,61616端口可能未被单独放行。
4. 临时排查代理干扰
若怀疑代理配置异常,可临时取消代理环境变量测试:
unset http_proxy https_proxy
再尝试telnet <ip> 61616,若能连通,说明本地代理规则限制了TCP流量,需调整代理策略。
内容的提问来源于stack exchange,提问作者Subhidh Agarwal
相关产品推荐
相关产品推荐

