You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

EC2实例绑定子域名并配置HTTPS遇响应慢等问题求助

问题描述

我正在为运行NodeJS应用的EC2实例配置HTTPS访问,当前通过IP能正常访问实例上的应用,但子域名访问响应极慢。已完成的配置如下:

  • 配置关联SSL/TLS证书的负载均衡器及实例目标组,Node应用运行在3000端口,同一实例注册了3000和80端口两个目标,健康状态均正常。
  • 负载均衡器设置80端口重定向至443并转发至目标组的规则,Route 53中创建了指向负载均衡器DNS的子域名。
  • 负载均衡器入站规则允许所有流量,出站规则允许443、80端口,来源为EC2实例安全组ID;EC2实例入站规则允许443、80、3000端口,来源为负载均衡器安全组ID,出站规则允许所有流量。

实际异常情况:

  • IP访问正常,但子域名响应缓慢。
  • 预期IP地址重定向至HTTPS子域名并展示应用内容,实际IP以HTTP方式加载内容且地址栏显示IP。

附nginx.conf配置:

user nginx;
worker_processes auto; error_log /var/log/nginx/error.log notice; pid /run/nginx.pid;

events { worker_connections 1024; }

http { include /etc/nginx/mime.types; default_type application/octet-stream;

log_format  main  '$remote_addr - $remote_user [$time_local] "$request" '
                  '$status $body_bytes_sent "$http_referer" '
                  '"$http_user_agent" "$http_x_forwarded_for"';

access_log  /var/log/nginx/access.log  main;

sendfile            on;
tcp_nopush          on;
keepalive_timeout   65;

server {
listen 80;
    server_name <subdomain_goes_here>;

    location / {
        proxy_pass <load_balancer_DNS_goes_here>;
        proxy_http_version 1.1;
        proxy_set_header Upgrade $http_upgrade;
        proxy_set_header Connection 'upgrade';
        proxy_set_header Host $host;
        proxy_cache_bypass $http_upgrade;
    }

location /health {
        return 200 'Healthy';
    }

    error_page   500 502 503 504  /50x.html;
    location = /50x.html {
        root   /usr/share/nginx/html;
    }
}
}

附NodeJS应用代码:

require("dotenv").config();
const sendGrid = require("@sendgrid/mail"); sendGrid.setApiKey(process.env.sendGridAPIKey);

const express = require('express'); const app = express();

// Define a route handler for the health check path app.get('/health', (req, res) => { // Respond with a 200 OK status and the text "Healthy" res.status(200).send('Healthy'); });

process.env

const PORT = process.env.PORT || 3000;

//access to html frontend app.use(express.static('frontend')); app.use(express.json())

//access to file app.get('/', (req, res)=>{ res.sendFile(__dirname + '/frontend/contact.html') })

//access to data in contact form app.post('/', (req, res)=>{ console.log(req.body)

const mailOptions = {
    from: 'email@email.com',
    to: 'email@email.com',
    subject: req.body.subject,
    reply_to: req.body.email,
    text: req.body.message
}

sendGrid.send(mailOptions, (error)=>{
    if(error){
        console.logy(error);
        res.send('error');
    } else {
        console.log('Email sent');
        res.send('success');
    }
})
})

app.listen(PORT,'0.0.0.0',()=>{ console.log(`Server running on port ${PORT}`) })

排查与修复方案

1. 解决Nginx循环转发死循环

当前Nginx监听80端口后,把请求转发到负载均衡器DNS,而负载均衡器又将请求转发回EC2实例的80/3000端口,形成循环转发,直接导致子域名访问响应缓慢甚至超时。

修复方式:

  • 修改Nginx的location /块,直接代理本地Node应用的3000端口:
location / {
    proxy_pass http://localhost:3000;
    proxy_http_version 1.1;
    proxy_set_header Upgrade $http_upgrade;
    proxy_set_header Connection 'upgrade';
    proxy_set_header Host $host;
    proxy_set_header X-Real-IP $remote_addr;
    proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
    proxy_set_header X-Forwarded-Proto $scheme;
    proxy_cache_bypass $http_upgrade;
}
  • 重启Nginx服务:sudo systemctl restart nginx

2. 清理冗余的目标组配置

目标组中同时注册EC2的80和3000端口,负载均衡器转发请求时会随机选择端口,若命中80端口会触发循环转发,加剧响应问题。

修复方式:

  • 从目标组中移除80端口的实例注册,只保留3000端口的目标。
  • 确认负载均衡器的443转发规则指向仅包含3000端口的目标组。

3. 配置IP访问重定向

当前IP访问直接走EC2实例的Node应用或Nginx,未配置重定向到HTTPS子域名的规则。

修复方式:

  • 在Nginx中新增针对IP访问的server块:
server {
    listen 80;
    server_name <EC2实例公网IP>;
    return 301 https://<你的子域名>$request_uri;
}
  • 重启Nginx后,IP访问会自动重定向到HTTPS子域名。

4. 修复Node应用代码错误

Node代码中console.logy(error);是拼写错误,应为console.log(error);,否则发送邮件出错时无法正常打印日志,影响问题排查。

5. 优化安全组规则

负载均衡器的出站规则无需限制为EC2实例安全组ID,直接允许所有出站流量即可,避免因规则限制导致转发异常。

内容的提问来源于stack exchange,提问作者Stoiccowboy

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.27 18:26:21