You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AWS EC2 Ubuntu部署Django遇Invalid HTTP_HOST错误求助

问题描述

在AWS EC2的Ubuntu服务器部署Django应用时,使用nohup在8000端口启动Django服务,配置Nginx及SSL证书将域名fmartns.dev映射至80/443端口,触发DisallowedHost错误,错误日志如下:

DisallowedHost at /
Invalid HTTP_HOST header: 'fmartns.dev,fmartns.dev'. The domain name provided is not valid according to RFC 1034/1035.


当前配置

Nginx 默认配置

server {
    listen 80;
    listen 443 ssl;
    server_name fmartns.dev;

    ssl_certificate /etc/letsencrypt/live/fmartns.dev/fullchain.pem;
    ssl_certificate_key /etc/letsencrypt/live/fmartns.dev/privkey.pem;

    location = /favicon.ico { access_log off; log_not_found off; }
    location /static/ {
        root /home/ubuntu/fmartns.dev;
    }

    location / {
        include proxy_params;
        proxy_pass http://3.82.145.23:8000;  # Port where Django is running
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;
    }
}

Django settings.py 配置

# SECURITY WARNING: don't run with debug turned on in production!
DEBUG = True

ALLOWED_HOSTS = ['fmartns.dev', '*']

SECURE_CONTENT_TYPE_NOSNIFF = True
SECURE_BROWSER_XSS_FILTER = True
SESSION_COOKIE_SECURE = True
CSRF_COOKIE_SECURE = True
SECURE_SSL_REDIRECT = True
SECURE_PROXY_SSL_HEADER = ('HTTP_X_FORWARDED_PROTO', 'https')
CSRF_TRUSTED_ORIGINS = ['http://fmartns.dev']

解决思路

1. 修复Nginx的Host头重复问题

错误核心是HTTP_HOST头出现重复域名,大概率是Nginx配置中重复传递了Host参数:

  • 检查/etc/nginx/proxy_params文件,若其中已包含proxy_set_header Host $host;,则当前location /块的配置会导致Host头被重复设置。此时可直接删除include proxy_params;,或显式在location /中设置正确的Host头:
    location / {
        # 移除 include proxy_params; 避免重复设置Host
        proxy_pass http://localhost:8000;  # 改用本地回环地址,更稳定
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;
    }
    
  • 建议拆分80和443端口的配置,将80端口专门用于HTTP跳转HTTPS,避免同一server块处理两种协议的潜在冲突:
    # 处理HTTP请求,强制跳转HTTPS
    server {
        listen 80;
        server_name fmartns.dev;
        return 301 https://$host$request_uri;
    }
    
    # 处理HTTPS请求
    server {
        listen 443 ssl;
        server_name fmartns.dev;
    
        ssl_certificate /etc/letsencrypt/live/fmartns.dev/fullchain.pem;
        ssl_certificate_key /etc/letsencrypt/live/fmartns.dev/privkey.pem;
    
        location = /favicon.ico { access_log off; log_not_found off; }
        location /static/ {
            root /home/ubuntu/fmartns.dev;
        }
    
        location / {
            proxy_pass http://localhost:8000;
            proxy_set_header Host $host;
            proxy_set_header X-Real-IP $remote_addr;
            proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
            proxy_set_header X-Forwarded-Proto $scheme;
        }
    }
    

2. 修正Django的安全配置

  • 更新CSRF_TRUSTED_ORIGINS,加入HTTPS域名(因已启用SSL跳转):
    CSRF_TRUSTED_ORIGINS = ['https://fmartns.dev', 'http://fmartns.dev']
    
  • 生产环境建议关闭DEBUG模式,并清理ALLOWED_HOSTS中的通配符,仅保留合法域名/IP:
    DEBUG = False
    ALLOWED_HOSTS = ['fmartns.dev', '3.82.145.23']
    

3. 重启服务生效

  • 验证Nginx配置:sudo nginx -t,无错误后重载配置:sudo systemctl reload nginx
  • 重启Django应用(若修改了settings.py):先终止原nohup进程,再重新启动nohup python manage.py runserver 0:8000 &

内容的提问来源于stack exchange,提问作者Filipe

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.25 21:33:27