You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Docker环境下Apache反向代理SSL部署Mosquitto连接故障排查

配置错误分析及修复方案

核心错误点

1. Mosquitto与Docker端口不匹配

你的mosquitto.conf里配置的WebSocket监听端口是9108,但docker-compose里映射的是9100:9100,容器内部的Mosquitto根本没在9100端口提供WebSocket服务,导致Apache代理的目标端口无效。

修复(二选一):

  • 修改mosquitto.conf的listener配置,把端口改成9100:
    listener 9100
    protocol websockets
    
  • 或修改docker-compose的端口映射为9108:9108,同时同步Apache代理的目标端口为ws://localhost:9108/

2. Apache代理缺少WebSocket支持配置

仅用ProxyPass和ProxyPassReverse无法正确处理WebSocket连接,需补充握手和连接保持相关配置:

<VirtualHost *:443>
    ServerName mosquitto.example.com

    # 保留原有SSL配置
    SSLEngine on
    SSLCertificateFile /home/example/ssl.cert
    SSLCertificateKeyFile /home/example/ssl.key
    SSLProtocol all -SSLv2 -SSLv3 -TLSv1 -TLSv1.1
    SSLCACertificateFile /home/example/ssl.ca

    # WebSocket代理增强配置
    ProxyRequests Off
    ProxyPreserveHost On
    ProxyPass / ws://localhost:9100/
    ProxyPassReverse / ws://localhost:9100/

    # 处理WebSocket握手规则
    RewriteEngine On
    RewriteCond %{HTTP:Upgrade} =websocket [NC]
    RewriteRule /(.*) ws://localhost:9100/$1 [P,L]
    RewriteCond %{HTTP:Upgrade} !=websocket [NC]
    RewriteRule /(.*) http://localhost:9100/$1 [P,L]

    # 延长连接超时时间
    ProxyTimeout 3600
</VirtualHost>

3. Mosquitto_pub命令参数错误

你重复使用了-p参数:-p 443是指定端口,-p admin1234是错误的密码写法,密码需用--password(或-P);另外必须显式指定WebSocket协议,默认TCP协议无法通过代理连接。

正确命令:

.\mosquitto_pub -h mosquitto.example.com -p 443 -u admin --password admin1234 -t 'test/topic' -m 'helloWorld' --protocol websockets

附加问题:无需指定-p 443的配置方法

WSS(WebSocket over SSL)的默认端口就是443,只要客户端使用WSS协议连接,即可省略端口参数。调整命令如下:

.\mosquitto_pub -h mosquitto.example.com -u admin --password admin1234 -t 'test/topic' -m 'helloWorld' --protocol websockets

此时mosquitto_pub会自动使用WSS默认端口443,无需手动指定。

内容的提问来源于stack exchange,提问作者Rui Oliveira

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.29 22:11:24