You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Nginx反向代理切换Azure后端后出现502 Bad Gateway故障排查

解决Nginx反向代理Azure Container Apps时的SSL握手重置问题

针对你遇到的Nginx反向代理Azure Container Apps出现SSL握手重置导致502的问题,按以下步骤排查解决:

  • 检查Nginx上游SSL协议与加密套件配置
    Azure Container Apps可能禁用了TLS 1.0/1.1等旧协议,而Nginx默认可能仍在尝试使用这些协议发起握手。在对应location块中添加强制使用TLS 1.2+的配置:

    proxy_ssl_protocols TLSv1.2 TLSv1.3;
    proxy_ssl_ciphers HIGH:!aNULL:!MD5;
    

    同时确保Nginx信任后端的SSL证书,可指定系统默认CA证书路径:

    proxy_ssl_trusted_certificate /etc/ssl/certs/ca-certificates.crt;
    proxy_ssl_verify on;
    

    测试阶段可临时添加proxy_ssl_verify off;跳过验证,确认问题后再恢复证书验证。

  • 核对上游地址与请求头配置
    确保proxy_pass指向完整的HTTPS地址,包含正确的域名和端口(非443需明确指定),例如:

    proxy_pass https://your-container-app-name.azurecontainerapps.io;
    

    添加正确的Host请求头,部分后端服务会验证Host字段:

    proxy_set_header Host your-container-app-name.azurecontainerapps.io;
    
  • 检查Azure Container Apps的网络与Ingress设置

    • 确认Container Apps的Ingress未限制IP访问,允许Nginx所在Azure Web App的出站IP进入白名单;
    • 检查Container Apps的TLS配置,确保启用的SSL协议、加密套件与Nginx配置匹配,无冲突。
  • 启用详细日志与手动验证SSL握手
    在Nginx的http块中开启debug级日志,查看握手细节:

    error_log /var/log/nginx/error.log debug;
    

    在Nginx服务器上执行openssl s_client -connect your-container-app-name.azurecontainerapps.io:443,手动测试SSL握手是否成功,快速定位是网络问题还是SSL配置问题。

  • 调整代理超时时间
    如果Container Apps启动或握手响应较慢,适当调大Nginx的代理超时参数:

    proxy_connect_timeout 120s;
    proxy_send_timeout 120s;
    proxy_read_timeout 120s;
    

    若Nginx版本过旧(低于1.13),建议升级以支持TLS 1.3等现代协议。

内容的提问来源于stack exchange,提问作者nerdalert

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.28 04:10:16