You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Laravel Octane(Swoole)配置Apache虚拟主机HTTPS遇代理错误求助

问题描述

我正在为运行于Laravel Octane(基于Swoole)的Laravel 11网站配置SSL,已生成Let's Encrypt证书,并在Octane配置文件中设置swoole.ssl为true。启动Octane服务器后,访问域名HTTP版本出现502代理错误,HTTPS版本则出现浏览器通用错误。请问我的Apache虚拟主机配置缺失了什么才能正常通过HTTPS提供服务?

当前Apache虚拟主机配置

<VirtualHost *:80>
    ProxyPreserveHost On

    ProxyPass / http://127.0.0.1:8000/
    ProxyPassReverse / http://127.0.0.1:8000/

    ServerName my-site.domain.com
    ServerAdmin admin@localhost
    DocumentRoot /var/www/icicle/current/public;

    <Directory /var/www/icicle/current/public>
        Options Indexes FollowSymLinks MultiViews
        AllowOverride All
        Require all granted
    </Directory>
</VirtualHost>

<VirtualHost *:443>
    ServerName my-site.domain.com
    ServerAdmin admin@localhost
    DocumentRoot /var/www/icicle/current/public

    SSLEngine on
    SSLCertificateFile /etc/letsencrypt/live/my-site.domain.com/fullchain.pem
    SSLCertificateKeyFile /etc/letsencrypt/live/my-site.domain.com/privkey.pem

    ProxyPreserveHost On

    ProxyPass / http://127.0.0.1:8000/
    ProxyPassReverse / http://127.0.0.1:8000/

    <Directory /var/www/icicle/current/public>
        Options Indexes FollowSymLinks MultiViews
        AllowOverride All
        Require all granted
    </Directory>
</VirtualHost>

当前Octane配置片段

'swoole' => [
    'ssl' => true,
    'options' => [
        'ssl_cert_file' => '/etc/letsencrypt/live/my-site.domain.com/cert.pem',
        'ssl_key_file' => '/etc/letsencrypt/live/my-site.domain.com/privkey.pem',
    ]
],
解决方案

你的配置存在几个关键问题,修复后即可正常运行:

1. 修正Octane的SSL证书路径

Let's Encrypt提供的cert.pem仅包含域名证书,缺少中间证书链,会导致浏览器不信任证书。需要将ssl_cert_file改为包含完整证书链的fullchain.pem:

'swoole' => [
    'ssl' => true,
    'options' => [
        'ssl_cert_file' => '/etc/letsencrypt/live/my-site.domain.com/fullchain.pem',
        'ssl_key_file' => '/etc/letsencrypt/live/my-site.domain.com/privkey.pem',
    ]
],

2. 调整Apache HTTPS虚拟主机的代理配置

由于Octane已开启SSL,Swoole在8000端口提供的是HTTPS服务而非HTTP,因此需要:

  • 开启SSLProxyEngine以支持代理到HTTPS后端
  • 将ProxyPass和ProxyPassReverse的目标改为https://127.0.0.1:8000/

修改后的HTTPS虚拟主机配置:

<VirtualHost *:443>
    ServerName my-site.domain.com
    ServerAdmin admin@localhost
    DocumentRoot /var/www/icicle/current/public

    SSLEngine on
    SSLCertificateFile /etc/letsencrypt/live/my-site.domain.com/fullchain.pem
    SSLCertificateKeyFile /etc/letsencrypt/live/my-site.domain.com/privkey.pem

    # 开启SSL代理支持
    SSLProxyEngine On
    # 允许与内部SSL后端建立连接(跳过证书校验,因为是本地服务)
    SSLProxyVerify none
    SSLProxyCheckPeerCN off
    SSLProxyCheckPeerName off
    SSLProxyCheckPeerExpire off

    ProxyPreserveHost On

    # 修改为HTTPS代理目标
    ProxyPass / https://127.0.0.1:8000/
    ProxyPassReverse / https://127.0.0.1:8000/

    <Directory /var/www/icicle/current/public>
        Options Indexes FollowSymLinks MultiViews
        AllowOverride All
        Require all granted
    </Directory>
</VirtualHost>

3. 修复HTTP虚拟主机的语法错误并配置HTTPS跳转

HTTP虚拟主机中DocumentRoot末尾多了一个分号,属于语法错误,会导致Apache加载配置失败。同时,应该将所有HTTP请求301重定向到HTTPS,而非直接代理:

<VirtualHost *:80>
    ServerName my-site.domain.com
    ServerAdmin admin@localhost
    DocumentRoot /var/www/icicle/current/public

    # 替换代理配置为HTTPS永久跳转
    Redirect permanent / https://my-site.domain.com/

    <Directory /var/www/icicle/current/public>
        Options Indexes FollowSymLinks MultiViews
        AllowOverride All
        Require all granted
    </Directory>
</VirtualHost>

4. 重启服务生效

完成上述修改后,依次重启Apache和Octane服务:

# 重启Apache
sudo systemctl restart apache2

# 重启Octane(根据你的启动方式调整,例如使用supervisor)
sudo supervisorctl restart octane

内容的提问来源于stack exchange,提问作者Ryan H

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.26 03:13:16