You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

在Nginx上配置带SSL的Laravel Reverb遇WebSocket连接失败

问题排查:Laravel Reverb 反向代理后WebSocket连接失败

我正在将beyondcode/laravel-websockets替换为laravel/reverb,本地无SSL环境下Reverb与Laravel Echo可正常运行。使用的是laravel-chirper-react-realtime项目,已配置config/reverb.php的TLS选项,并尝试通过Nginx反向代理,但出现WebSocket连接失败的错误。


1. config/reverb.php 配置

'servers' => [
    'reverb' => [
        'host' => env('REVERB_SERVER_HOST', '0.0.0.0'),
        'port' => env('REVERB_SERVER_PORT', 8080),
        'hostname' => env('REVERB_HOST'),
        'options' => [
            'tls' => [
                    'local_cert'=>'/chirper_cert/cert1.pem' // 采用Certbot证书,权限设为777但无效
            ],
        ],
        'scaling' => [
            'enabled' => env('REVERB_SCALING_ENABLED', false),
            'channel' => env('REVERB_SCALING_CHANNEL', 'reverb'),
        ],
        'pulse_ingest_interval' => env('REVERB_PULSE_INGEST_INTERVAL', 15),
    ],
],

2. Nginx反向代理配置

server {
    root /var/www/laravel-chirper-react-realtime/public;
    add_header X-Frame-Options "SAMEORIGIN";
    add_header X-Content-Type-Options "nosniff";
    index index.php;
    charset utf-8;
    server_name example.com;

    location / {
            try_files $uri $uri/ /index.php?$query_string;
    }

    location = /favicon.ico { access_log off; log_not_found off; }
    location = /robots.txt  { access_log off; log_not_found off; }
    error_page 404 /index.php;

    location ~ \.php$ {
            fastcgi_pass unix:/var/run/php/php8.3-fpm.sock;
            fastcgi_param SCRIPT_FILENAME $realpath_root$fastcgi_script_name;
            include fastcgi_params;
    }
    # WebSocket代理配置
    location /ws/ {
        proxy_pass             http://127.0.0.1:8080;
        proxy_set_header Host  $host;
        proxy_read_timeout     60;
        proxy_connect_timeout  60;
        proxy_redirect         off;

        # 支持WebSocket
        proxy_http_version 1.1;
        proxy_set_header Upgrade $http_upgrade;
        proxy_set_header Connection 'upgrade';
        proxy_set_header Host $host;
        proxy_cache_bypass $http_upgrade;
    }

    listen [::]:443 ssl; # 由Certbot管理
    listen 443 ssl; # 由Certbot管理
    ssl_certificate /etc/letsencrypt/live/example.com/fullchain.pem; # 由Certbot管理
    ssl_certificate_key /etc/letsencrypt/live/example.com/privkey.pem; # 由Certbot管理
    include /etc/letsencrypt/options-ssl-nginx.conf; # 由Certbot管理
    ssl_dhparam /etc/letsencrypt/ssl-dhparams.pem; # 由Certbot管理
}

3. 错误信息

WebSocket connection to 'wss://example:8080/app/fl2qodkdxamxyygnpbur?protocol=7&client=js&version=8.4.0-rc2&flash=false' failed

排查步骤

  • 修正WebSocket连接地址
    错误地址存在两个问题:域名应为example.com而非example;不应直接访问8080端口,需通过Nginx的443端口走/ws/路径。正确地址应为wss://example.com/ws/app/...,检查前端Laravel Echo配置,确保wsHost设为example.com,wsPort设为443,wsPath设为/ws/app。

  • 调整Reverb配置
    由于Nginx已做SSL终止,Reverb无需自行处理TLS,删除config/reverb.php中的tls配置,让Reverb以HTTP模式运行;同时确保REVERB_HOST环境变量设为example.com,与Nginx的server_name一致。

  • 优化Nginx代理配置
    将proxy_pass改为http://127.0.0.1:8080/(末尾加斜杠),避免路径拼接错误;可添加proxy_set_header X-Real-IP $remote_addr;和proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;,确保Reverb能获取真实客户端IP。

  • 验证服务与端口状态
    执行php artisan reverb:start确认Reverb服务正常运行并监听8080端口;检查防火墙是否开放8080端口(仅限本地访问,外部无需直接连接该端口)。

  • 证书权限修正
    若Reverb无需自行使用证书,可忽略/chirper_cert/cert1.pem;若后续需直接启用Reverb的SSL,将证书文件权限设为644、目录权限设为755,避免使用不安全的777权限。

内容的提问来源于stack exchange,提问作者Jhordy Said Barrera

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.28 06:24:53