Laravel Octane(Swoole)配置Apache虚拟主机HTTPS遇代理错误求助
问题描述
我正在为运行于Laravel Octane(基于Swoole)的Laravel 11网站配置SSL,已生成Let's Encrypt证书,并在Octane配置文件中设置swoole.ssl为true。启动Octane服务器后,访问域名HTTP版本出现502代理错误,HTTPS版本则出现浏览器通用错误。请问我的Apache虚拟主机配置缺失了什么才能正常通过HTTPS提供服务?
当前Apache虚拟主机配置
<VirtualHost *:80> ProxyPreserveHost On ProxyPass / http://127.0.0.1:8000/ ProxyPassReverse / http://127.0.0.1:8000/ ServerName my-site.domain.com ServerAdmin admin@localhost DocumentRoot /var/www/icicle/current/public; <Directory /var/www/icicle/current/public> Options Indexes FollowSymLinks MultiViews AllowOverride All Require all granted </Directory> </VirtualHost> <VirtualHost *:443> ServerName my-site.domain.com ServerAdmin admin@localhost DocumentRoot /var/www/icicle/current/public SSLEngine on SSLCertificateFile /etc/letsencrypt/live/my-site.domain.com/fullchain.pem SSLCertificateKeyFile /etc/letsencrypt/live/my-site.domain.com/privkey.pem ProxyPreserveHost On ProxyPass / http://127.0.0.1:8000/ ProxyPassReverse / http://127.0.0.1:8000/ <Directory /var/www/icicle/current/public> Options Indexes FollowSymLinks MultiViews AllowOverride All Require all granted </Directory> </VirtualHost>
当前Octane配置片段
'swoole' => [ 'ssl' => true, 'options' => [ 'ssl_cert_file' => '/etc/letsencrypt/live/my-site.domain.com/cert.pem', 'ssl_key_file' => '/etc/letsencrypt/live/my-site.domain.com/privkey.pem', ] ],
解决方案
你的配置存在几个关键问题,修复后即可正常运行:
1. 修正Octane的SSL证书路径
Let's Encrypt提供的cert.pem仅包含域名证书,缺少中间证书链,会导致浏览器不信任证书。需要将ssl_cert_file改为包含完整证书链的fullchain.pem:
'swoole' => [ 'ssl' => true, 'options' => [ 'ssl_cert_file' => '/etc/letsencrypt/live/my-site.domain.com/fullchain.pem', 'ssl_key_file' => '/etc/letsencrypt/live/my-site.domain.com/privkey.pem', ] ],
2. 调整Apache HTTPS虚拟主机的代理配置
由于Octane已开启SSL,Swoole在8000端口提供的是HTTPS服务而非HTTP,因此需要:
- 开启
SSLProxyEngine以支持代理到HTTPS后端 - 将
ProxyPass和ProxyPassReverse的目标改为https://127.0.0.1:8000/
修改后的HTTPS虚拟主机配置:
<VirtualHost *:443> ServerName my-site.domain.com ServerAdmin admin@localhost DocumentRoot /var/www/icicle/current/public SSLEngine on SSLCertificateFile /etc/letsencrypt/live/my-site.domain.com/fullchain.pem SSLCertificateKeyFile /etc/letsencrypt/live/my-site.domain.com/privkey.pem # 开启SSL代理支持 SSLProxyEngine On # 允许与内部SSL后端建立连接(跳过证书校验,因为是本地服务) SSLProxyVerify none SSLProxyCheckPeerCN off SSLProxyCheckPeerName off SSLProxyCheckPeerExpire off ProxyPreserveHost On # 修改为HTTPS代理目标 ProxyPass / https://127.0.0.1:8000/ ProxyPassReverse / https://127.0.0.1:8000/ <Directory /var/www/icicle/current/public> Options Indexes FollowSymLinks MultiViews AllowOverride All Require all granted </Directory> </VirtualHost>
3. 修复HTTP虚拟主机的语法错误并配置HTTPS跳转
HTTP虚拟主机中DocumentRoot末尾多了一个分号,属于语法错误,会导致Apache加载配置失败。同时,应该将所有HTTP请求301重定向到HTTPS,而非直接代理:
<VirtualHost *:80> ServerName my-site.domain.com ServerAdmin admin@localhost DocumentRoot /var/www/icicle/current/public # 替换代理配置为HTTPS永久跳转 Redirect permanent / https://my-site.domain.com/ <Directory /var/www/icicle/current/public> Options Indexes FollowSymLinks MultiViews AllowOverride All Require all granted </Directory> </VirtualHost>
4. 重启服务生效
完成上述修改后,依次重启Apache和Octane服务:
# 重启Apache sudo systemctl restart apache2 # 重启Octane(根据你的启动方式调整,例如使用supervisor) sudo supervisorctl restart octane
内容的提问来源于stack exchange,提问作者Ryan H
相关产品推荐
相关产品推荐

