通过Nginx连接Hyperledger Fabric网络时遭遇gRPC RST_STREAM协议错误的排查求助
Let's break down your issues step by step and walk through the fixes:
1. Resolve Nginx Server Name Conflict (Critical First Step)
Your error log shows conflicting server name "XXXX" on [::]:80, ignored — this means your two Nginx config files are trying to use the same server_name and listen on port 80. Nginx will only load the first matching server block, so your second config's gRPC routing (the /channels location with grpc_pass) isn't even being applied. That's a root cause of your gRPC failure.
Fix: Merge Configs or Resolve Port/Server Name Duplication
The cleanest solution is to merge both configs into a single server block, since they're handling paths for the same domain. Make sure to enable HTTP/2 (required for gRPC) on the listen directives:
upstream rca-org1 { server XXXX:7054; } upstream couchdb { server XXXX:5984; } upstream network { server XXXX:7051; } server { listen 80 http2 default_server; listen [::]:80 http2; server_name XXXX; access_log /path/to/nginx/access.log; # Serve frontend static files location / { root /app/build; index index.html; try_files $uri /index.html; } # Proxy API requests to RCA location /api { proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; proxy_set_header Host $http_host; proxy_redirect off; proxy_pass http://rca-org1; } # Proxy wallet requests to CouchDB location /wallet { proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; proxy_set_header Host $http_host; proxy_redirect off; proxy_pass http://couchdb; } # Proxy gRPC requests to Fabric network location /channels { proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; proxy_set_header Host $http_host; proxy_redirect off; grpc_pass grpc://network; } # Serve static/media assets location ~/(static|media)/ { root /app/build/; } }
- Why HTTP/2? gRPC relies entirely on HTTP/2 for transport. Without adding
http2to yourlistendirectives, Nginx will reject gRPC's initial connection handshake (thePRI * HTTP/2.0request in your access log, which returns 400).
2. Validate Nginx HTTP/2 Support
Double-check your Nginx version and build flags to ensure it supports HTTP/2:
nginx -V
Look for --with-http_v2_module in the output. If it's missing, you'll need to rebuild Nginx with this module or use a pre-built image that includes it.
3. Verify K8s Internal Service Reachability
Since all components are in a K8s cluster, confirm Nginx can reach your upstream services:
- Test HTTP services from the Nginx pod:
curl http://rca-org1:7054 curl http://couchdb:5984 - Test gRPC connectivity (install
grpcurlin the Nginx pod first if needed):grpcurl -plaintext network:7051 list - Also check if K8s NetworkPolicies are blocking traffic between Nginx and your Fabric/backend pods.
4. Double-Check Node.js Fabric Client Configuration
Ensure your Node.js API's Fabric connection points to Nginx's K8s service address (e.g., http://nginx-service:80/channels) instead of directly to the Fabric peer. The fabric-network client uses gRPC under the hood, so as long as the Nginx proxy is correctly handling HTTP/2, this should resolve the RST_STREAM error.
内容的提问来源于stack exchange,提问作者Ivan

