EC2实例绑定子域名并配置HTTPS遇响应慢等问题求助
问题描述
我正在为运行NodeJS应用的EC2实例配置HTTPS访问,当前通过IP能正常访问实例上的应用,但子域名访问响应极慢。已完成的配置如下:
- 配置关联SSL/TLS证书的负载均衡器及实例目标组,Node应用运行在3000端口,同一实例注册了3000和80端口两个目标,健康状态均正常。
- 负载均衡器设置80端口重定向至443并转发至目标组的规则,Route 53中创建了指向负载均衡器DNS的子域名。
- 负载均衡器入站规则允许所有流量,出站规则允许443、80端口,来源为EC2实例安全组ID;EC2实例入站规则允许443、80、3000端口,来源为负载均衡器安全组ID,出站规则允许所有流量。
实际异常情况:
- IP访问正常,但子域名响应缓慢。
- 预期IP地址重定向至HTTPS子域名并展示应用内容,实际IP以HTTP方式加载内容且地址栏显示IP。
附nginx.conf配置:
user nginx; worker_processes auto; error_log /var/log/nginx/error.log notice; pid /run/nginx.pid; events { worker_connections 1024; } http { include /etc/nginx/mime.types; default_type application/octet-stream; log_format main '$remote_addr - $remote_user [$time_local] "$request" ' '$status $body_bytes_sent "$http_referer" ' '"$http_user_agent" "$http_x_forwarded_for"'; access_log /var/log/nginx/access.log main; sendfile on; tcp_nopush on; keepalive_timeout 65; server { listen 80; server_name <subdomain_goes_here>; location / { proxy_pass <load_balancer_DNS_goes_here>; proxy_http_version 1.1; proxy_set_header Upgrade $http_upgrade; proxy_set_header Connection 'upgrade'; proxy_set_header Host $host; proxy_cache_bypass $http_upgrade; } location /health { return 200 'Healthy'; } error_page 500 502 503 504 /50x.html; location = /50x.html { root /usr/share/nginx/html; } } }
附NodeJS应用代码:
require("dotenv").config(); const sendGrid = require("@sendgrid/mail"); sendGrid.setApiKey(process.env.sendGridAPIKey); const express = require('express'); const app = express(); // Define a route handler for the health check path app.get('/health', (req, res) => { // Respond with a 200 OK status and the text "Healthy" res.status(200).send('Healthy'); }); process.env const PORT = process.env.PORT || 3000; //access to html frontend app.use(express.static('frontend')); app.use(express.json()) //access to file app.get('/', (req, res)=>{ res.sendFile(__dirname + '/frontend/contact.html') }) //access to data in contact form app.post('/', (req, res)=>{ console.log(req.body) const mailOptions = { from: 'email@email.com', to: 'email@email.com', subject: req.body.subject, reply_to: req.body.email, text: req.body.message } sendGrid.send(mailOptions, (error)=>{ if(error){ console.logy(error); res.send('error'); } else { console.log('Email sent'); res.send('success'); } }) }) app.listen(PORT,'0.0.0.0',()=>{ console.log(`Server running on port ${PORT}`) })
排查与修复方案
1. 解决Nginx循环转发死循环
当前Nginx监听80端口后,把请求转发到负载均衡器DNS,而负载均衡器又将请求转发回EC2实例的80/3000端口,形成循环转发,直接导致子域名访问响应缓慢甚至超时。
修复方式:
- 修改Nginx的
location /块,直接代理本地Node应用的3000端口:
location / { proxy_pass http://localhost:3000; proxy_http_version 1.1; proxy_set_header Upgrade $http_upgrade; proxy_set_header Connection 'upgrade'; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; proxy_cache_bypass $http_upgrade; }
- 重启Nginx服务:
sudo systemctl restart nginx
2. 清理冗余的目标组配置
目标组中同时注册EC2的80和3000端口,负载均衡器转发请求时会随机选择端口,若命中80端口会触发循环转发,加剧响应问题。
修复方式:
- 从目标组中移除80端口的实例注册,只保留3000端口的目标。
- 确认负载均衡器的443转发规则指向仅包含3000端口的目标组。
3. 配置IP访问重定向
当前IP访问直接走EC2实例的Node应用或Nginx,未配置重定向到HTTPS子域名的规则。
修复方式:
- 在Nginx中新增针对IP访问的server块:
server { listen 80; server_name <EC2实例公网IP>; return 301 https://<你的子域名>$request_uri; }
- 重启Nginx后,IP访问会自动重定向到HTTPS子域名。
4. 修复Node应用代码错误
Node代码中console.logy(error);是拼写错误,应为console.log(error);,否则发送邮件出错时无法正常打印日志,影响问题排查。
5. 优化安全组规则
负载均衡器的出站规则无需限制为EC2实例安全组ID,直接允许所有出站流量即可,避免因规则限制导致转发异常。
内容的提问来源于stack exchange,提问作者Stoiccowboy
相关产品推荐
相关产品推荐

