如何使用Nginx为FPV机器人项目配置HTTPS反向代理,实现同一设备多端口流量转发
Hey there, let's get your FPV robot's Nginx reverse proxy sorted out exactly as you need it. This is totally straightforward with a basic Nginx config—no fancy Kubernetes or multi-server setup required. Here's a step-by-step guide tailored to your scenario:
1. Prerequisites
First, make sure Nginx is installed on your 1.2.3.4 server. You'll also need an SSL certificate for example.com:
- For production use, grab a free one from Let's Encrypt (run
certbot --nginxand follow the prompts). - For testing, generate a self-signed certificate with OpenSSL:
You can leave most fields blank for testing purposes.mkdir -p /etc/nginx/ssl openssl req -x509 -newkey rsa:4096 -keyout /etc/nginx/ssl/example.com.key -out /etc/nginx/ssl/example.com.crt -days 365 -nodes
2. Create the Nginx Proxy Configuration
Head to Nginx's sites directory and create a new config file:
nano /etc/nginx/sites-available/fpv-proxy.conf
Paste in this config, adjusting the SSL paths if you used Let's Encrypt (they'll be in /etc/letsencrypt/live/example.com/ instead):
# ------------------------------ # Redirect HTTP to HTTPS for both ports # ------------------------------ server { listen 5000; server_name example.com; # Redirect all HTTP traffic on 5000 to HTTPS return 301 https://$server_name:$server_port$request_uri; } server { listen 5001; server_name example.com; # Redirect all HTTP traffic on 5001 to HTTPS return 301 https://$server_name:$server_port$request_uri; } # ------------------------------ # Proxy HTTPS 5000 to internal Flask/Werkzeug (HTTP) # ------------------------------ server { listen 5000 ssl; server_name example.com; # SSL certificate paths ssl_certificate /etc/nginx/ssl/example.com.crt; ssl_certificate_key /etc/nginx/ssl/example.com.key; # Basic secure SSL settings ssl_protocols TLSv1.2 TLSv1.3; ssl_ciphers HIGH:!aNULL:!MD5; location / { # Forward requests to your internal Flask server proxy_pass http://127.0.0.1:5000; # Pass through necessary headers so Flask recognizes the original request proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; } } # ------------------------------ # Proxy HTTPS 5001 to internal Streamserver (HTTP) # ------------------------------ server { listen 5001 ssl; server_name example.com; # Same SSL certificates as above ssl_certificate /etc/nginx/ssl/example.com.crt; ssl_certificate_key /etc/nginx/ssl/example.com.key; ssl_protocols TLSv1.2 TLSv1.3; ssl_ciphers HIGH:!aNULL:!MD5; location / { # Forward requests to your streamserver (it doesn't support HTTPS, so we use HTTP internally) proxy_pass http://127.0.0.1:5001; # Pass through headers proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; # Critical settings for video streaming (prevents buffering/timeouts) proxy_buffering off; proxy_cache off; proxy_send_timeout 3600s; proxy_read_timeout 3600s; } }
3. Enable the Config & Restart Nginx
- Link the config to Nginx's enabled sites directory:
ln -s /etc/nginx/sites-available/fpv-proxy.conf /etc/nginx/sites-enabled/ - Test the config for errors:
You should seenginx -tnginx: configuration file /etc/nginx/nginx.conf test is successful. - Restart Nginx to apply changes:
systemctl restart nginx
4. Verify Everything Works
- Try accessing
http://example.com:5000—it should automatically redirect tohttps://example.com:5000, and your command control should work over the secure connection. - Access
http://example.com:5001—it'll redirect tohttps://example.com:5001, and your video stream should load correctly (Nginx handles the HTTPS encryption externally, while talking plain HTTP to your streamserver internally).
This setup checks all your boxes: secure external connections, plaintext internal forwarding for the streamserver, automatic HTTP-to-HTTPS redirects, and no overcomplicated infrastructure.
内容的提问来源于stack exchange,提问作者Jim JR Harris

