You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

NGINX反向代理.NET Core(含SSL)出现502 Bad Gateway故障排查

问题:NGINX反向代理.NET Core应用返回502 Bad Gateway

在Ubuntu服务器上部署NGINX作为反向代理,对接Kestrel托管的.NET Core应用,应用HTTP端口为5008、HTTPS端口为5009。原本运行正常,当前访问443/SSL端口时NGINX返回ERROR 502 BAD GATEWAY错误。

已知信息:

  • NGINX以MyUser用户运行
  • .NET应用目录已配置该用户权限,但SSL证书目录未设置对应权限
  • 无法定位问题根源,日志未提供有效线索

NGINX配置

http {
   include        /etc/nginx/mime.types;
   include        /etc/nginx/fastcgi.conf;
   index          index.html;

   sendfile       on; 
   tcp_nopush     on;

   default_type   application/octet-stream;

   server { 
        listen          80 default_server;
        server_name     mysite.com www.mysite.com;
        
        return 301 https://$host$request_uri;   
    }

    server {
        listen      443 ssl;
        server_name localhost;
        ssl_certificate /etc/nginx/ssl/bundle.crt;
        ssl_certificate_key /etc/nginx/ssl/private.key;

         root      /var/www;
         index     index.html;

    location / {
                proxy_pass         http://127.0.0.1:5008;
                proxy_redirect     off;
                proxy_http_version 1.1;
                proxy_cache_bypass $http_upgrade;
                proxy_set_header   Upgrade $http_upgrade;
                proxy_set_header   Connection keep-alive;
                proxy_set_header   Host $host;
                proxy_set_header   X-Real-IP $remote_addr;
                proxy_set_header   X-Forwarded-For $proxy_add_x_forwarded_for;
                proxy_set_header   X-Forwarded-Proto $scheme;
                proxy_set_header   X-Forwarded-Host $server_name;
        }
    }
}

.NET Core Kestrel配置

"Kestrel": {
    "Endpoints": {
      "Http": {
        "Url": "http://localhost:5008"
      },
      "HttpsInlineCertFile": {
        "Url": "https://localhost:5009",
        "Certificate": {
         // REMOVED
        }
      }
    },
    "Https": {
      "Url": "https://*:5009",
      "Certificate": {
         // REMOVED
      }
    },
    "Certificates": {
      "Default": {
          // REMOVED
      }
    }
  },
  "AllowedHosts": "*",

.NET应用日志

2024-05-08 10:05:36.585 +00:00 [WRN] Overriding address(es) 'http://127.0.0.1:5008, http://localhost:5008'. Binding to endpoints defined via IConfiguration and/or UseKestrel() instead.
2024-05-08 10:05:36.597 +00:00 [INF] Now listening on: http://localhost:5008
2024-05-08 10:05:36.598 +00:00 [INF] Now listening on: https://localhost:5009

排查与解决方案

1. 修复SSL证书目录权限

NGINX以MyUser运行,若证书目录无读取权限,会导致NGINX无法加载证书,间接引发502错误。执行以下命令:

# 给MyUser添加证书目录的读取权限
sudo chown -R root:MyUser /etc/nginx/ssl/
sudo chmod -R 750 /etc/nginx/ssl/
# 单独设置证书文件权限,确保可读
sudo chmod 640 /etc/nginx/ssl/bundle.crt /etc/nginx/ssl/private.key
# 重启NGINX生效
sudo systemctl restart nginx

2. 验证Kestrel端口监听状态

应用日志显示监听http://localhost:5008,需确认端口实际被占用:

sudo ss -tulpn | grep :5008

若结果中无dotnet进程,说明Kestrel未正常启动。可尝试将Kestrel的HTTP端点改为http://0.0.0.0:5008(允许所有IP访问),避免回环地址解析问题。

3. 查看NGINX错误日志

默认日志路径为/var/log/nginx/error.log,查看最新错误信息:

sudo tail -n 20 /var/log/nginx/error.log

若日志出现permission denied,说明权限问题未解决;若出现connection refused,则是Kestrel未监听5008端口。

4. 清理Kestrel冗余配置

日志警告源于重复的HTTPS端点配置(Endpoints.HttpsInlineCertFile和Https节点都指向5009端口),删除冗余节点,简化配置:

"Kestrel": {
    "Endpoints": {
      "Http": {
        "Url": "http://0.0.0.0:5008"
      },
      "Https": {
        "Url": "https://0.0.0.0:5009",
        "Certificate": {
         // 保留原有证书配置
        }
      }
    },
    "Certificates": {
      "Default": {
          // 保留原有配置
      }
    }
  },
  "AllowedHosts": "*",

修改后重启.NET应用:

sudo systemctl restart your-dotnet-app.service # 替换为你的应用服务名

5. 测试NGINX与Kestrel的连通性

在服务器上直接请求Kestrel端口,验证应用是否正常响应:

curl http://127.0.0.1:5008

若返回应用内容,说明Kestrel正常;若返回Connection refused,则需检查Kestrel启动状态或监听地址。


内容的提问来源于stack exchange,提问作者NOCARRIER

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.24 15:54:53