Nginx反向代理隐藏URL参数时遇BlobNotFound错误排查
你的Nginx配置出现BlobNotFound错误,核心原因是路径转发的匹配逻辑不够明确,导致实际转发到Azure Blob Storage的路径可能不符合预期。虽然看起来proxy_pass的路径设置正确,但Nginx默认的前缀替换逻辑可能因为location的匹配规则出现偏差。
修正后的配置
将配置改为使用rewrite明确控制路径转换,确保请求的文件路径能正确映射到Blob存储的路径:
location /documents { # 明确将/documents/后的路径部分映射到publicfiles/MyFiles/下 rewrite ^/documents/(.*)$ /publicfiles/MyFiles/$1 break; set $delimeter ""; if ($is_args) { set $delimeter "&"; } set $args "$args${delimeter}sp=rl&st=2024-02-15T14:18:59Z&se=2025-02-15T22:18:59Z&spr=https&sv=2022-11-02&sr=c&sig=TxTaaaaaaaaaaaaaaaaaaaaaaaaaaNgU%3D"; proxy_pass https://testtestsitweu.blob.core.windows.net; proxy_ssl_name testtestsitweu.blob.core.windows.net; proxy_ssl_server_name on; # 补充必要的HTTP头部配置,确保请求符合Azure要求 proxy_set_header Host $proxy_host; proxy_http_version 1.1; proxy_set_header Connection ""; }
关键修改说明
使用rewrite明确路径映射:
原配置依赖Nginx默认的前缀替换(将/documents替换为空),但这种方式在处理嵌套路径时容易出现模糊匹配。通过rewrite ^/documents/(.*)$ /publicfiles/MyFiles/$1 break;,可以精准地将/documents/file.pdf转换为/publicfiles/MyFiles/file.pdf,完全匹配你直接访问的Blob路径。调整proxy_pass路径:
去掉proxy_pass末尾的/,改为直接指向Blob存储的根域名,让rewrite后的完整路径拼接到域名后,避免路径拼接时出现意外的斜杠或缺失。补充HTTP头部配置:
添加proxy_set_header Host $proxy_host确保请求的Host头正确指向Blob存储域名;设置proxy_http_version 1.1和proxy_set_header Connection "",符合Azure Blob Storage对HTTP/1.1的要求,避免因协议版本或连接头部问题导致请求异常。
额外排查步骤
如果修正后仍有问题,可以通过以下方式进一步定位:
- 在Nginx配置中添加自定义日志,记录实际转发的路径和参数:
查看日志确认转发的路径是否为log_format proxy_debug '$remote_addr - $remote_user [$time_local] "$request" ' '$status $body_bytes_sent "$http_referer" ' '"$http_user_agent" "$proxy_host" "$request_uri" "$args"'; access_log /var/log/nginx/proxy_debug.log proxy_debug;/publicfiles/MyFiles/file.pdf,参数是否与直接访问的完全一致。 - 检查Azure Blob存储中文件的实际路径是否与
publicfiles/MyFiles/file.pdf完全一致(注意大小写,Azure Blob路径区分大小写)。
内容的提问来源于stack exchange,提问作者ilhan

