NGINX反向代理.NET Core(含SSL)出现502 Bad Gateway故障排查
问题:NGINX反向代理.NET Core应用返回502 Bad Gateway
在Ubuntu服务器上部署NGINX作为反向代理,对接Kestrel托管的.NET Core应用,应用HTTP端口为5008、HTTPS端口为5009。原本运行正常,当前访问443/SSL端口时NGINX返回ERROR 502 BAD GATEWAY错误。
已知信息:
- NGINX以
MyUser用户运行 - .NET应用目录已配置该用户权限,但SSL证书目录未设置对应权限
- 无法定位问题根源,日志未提供有效线索
NGINX配置
http { include /etc/nginx/mime.types; include /etc/nginx/fastcgi.conf; index index.html; sendfile on; tcp_nopush on; default_type application/octet-stream; server { listen 80 default_server; server_name mysite.com www.mysite.com; return 301 https://$host$request_uri; } server { listen 443 ssl; server_name localhost; ssl_certificate /etc/nginx/ssl/bundle.crt; ssl_certificate_key /etc/nginx/ssl/private.key; root /var/www; index index.html; location / { proxy_pass http://127.0.0.1:5008; proxy_redirect off; proxy_http_version 1.1; proxy_cache_bypass $http_upgrade; proxy_set_header Upgrade $http_upgrade; proxy_set_header Connection keep-alive; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; proxy_set_header X-Forwarded-Host $server_name; } } }
.NET Core Kestrel配置
"Kestrel": { "Endpoints": { "Http": { "Url": "http://localhost:5008" }, "HttpsInlineCertFile": { "Url": "https://localhost:5009", "Certificate": { // REMOVED } } }, "Https": { "Url": "https://*:5009", "Certificate": { // REMOVED } }, "Certificates": { "Default": { // REMOVED } } }, "AllowedHosts": "*",
.NET应用日志
2024-05-08 10:05:36.585 +00:00 [WRN] Overriding address(es) 'http://127.0.0.1:5008, http://localhost:5008'. Binding to endpoints defined via IConfiguration and/or UseKestrel() instead. 2024-05-08 10:05:36.597 +00:00 [INF] Now listening on: http://localhost:5008 2024-05-08 10:05:36.598 +00:00 [INF] Now listening on: https://localhost:5009
排查与解决方案
1. 修复SSL证书目录权限
NGINX以MyUser运行,若证书目录无读取权限,会导致NGINX无法加载证书,间接引发502错误。执行以下命令:
# 给MyUser添加证书目录的读取权限 sudo chown -R root:MyUser /etc/nginx/ssl/ sudo chmod -R 750 /etc/nginx/ssl/ # 单独设置证书文件权限,确保可读 sudo chmod 640 /etc/nginx/ssl/bundle.crt /etc/nginx/ssl/private.key # 重启NGINX生效 sudo systemctl restart nginx
2. 验证Kestrel端口监听状态
应用日志显示监听http://localhost:5008,需确认端口实际被占用:
sudo ss -tulpn | grep :5008
若结果中无dotnet进程,说明Kestrel未正常启动。可尝试将Kestrel的HTTP端点改为http://0.0.0.0:5008(允许所有IP访问),避免回环地址解析问题。
3. 查看NGINX错误日志
默认日志路径为/var/log/nginx/error.log,查看最新错误信息:
sudo tail -n 20 /var/log/nginx/error.log
若日志出现permission denied,说明权限问题未解决;若出现connection refused,则是Kestrel未监听5008端口。
4. 清理Kestrel冗余配置
日志警告源于重复的HTTPS端点配置(Endpoints.HttpsInlineCertFile和Https节点都指向5009端口),删除冗余节点,简化配置:
"Kestrel": { "Endpoints": { "Http": { "Url": "http://0.0.0.0:5008" }, "Https": { "Url": "https://0.0.0.0:5009", "Certificate": { // 保留原有证书配置 } } }, "Certificates": { "Default": { // 保留原有配置 } } }, "AllowedHosts": "*",
修改后重启.NET应用:
sudo systemctl restart your-dotnet-app.service # 替换为你的应用服务名
5. 测试NGINX与Kestrel的连通性
在服务器上直接请求Kestrel端口,验证应用是否正常响应:
curl http://127.0.0.1:5008
若返回应用内容,说明Kestrel正常;若返回Connection refused,则需检查Kestrel启动状态或监听地址。
内容的提问来源于stack exchange,提问作者NOCARRIER
相关产品推荐
相关产品推荐

