You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Nginx反向代理实现PgAdmin端口映射的配置问题求助

问题排查:Nginx子域名反向代理异常

一、AWS EC2环境配置与问题

容器运行信息

0.0.0.0:80->80/tcp, :::80->80/tcp, 0.0.0.0:443->443/tcp, :::443->443/tcp   ningx_ctnr
443/tcp, 0.0.0.0:5050->80/tcp, :::5050->80/tcp                             pgadmin_ctnr
4000/tcp, 9000/tcp, 0.0.0.0:8000->8000/tcp, :::8000->8000/tcp              django_ctnr
...

安全组配置

EC2实例安全组已开放80、443端口的入站规则。

Nginx配置文件

django.conf

upstream django_app {
  server  ec2_private_IP:8000;
}
server {
  listen  80;
  listen  [::]:80;
  server_name   *.stage.my_domain.es stage.my_domain.es;
  return 301 https://$host$request_uri;
}
server {
  listen  443 ssl;
  listen  [::]:443 ssl;
  server_name   *.stage.my_domain.es stage.my_domain.es;
  ...
  certs and log info
  ... 
  location / {
    ...
    headers info
    ... 
    proxy_redirect  off;
    proxy_pass      http://django_app;
  }
}

pgadmin.conf

upstream pgadmin_app {
  server  ec2_private_IP:80;
}
server {
  listen  80;
  listen  [::]:80;
  server_name   *.pgadmin.stage.my_domain.es pgadmin.stage.my_domain.es;
  return 301 https://$host$request_uri;
}
server {
  listen  443 ssl;
  listen  [::]:443 ssl;
  server_name   *.pgadmin.stage.my_domain.es pgadmin.stage.my_domain.es;
  ...
  certs and log info
  ... 
  location / {
    ...
    headers info
    ... 
    proxy_redirect  off;
    proxy_pass      http://pgadmin_app;
  }
}

问题现象

访问https://stage.my_domain.es可正常反向代理到Django项目,但访问https://pgadmin.stage.my_domain.es时仍反向代理到Django。


二、本地测试复现与推断

修改PgAdmin监听端口

设置环境变量:

PGADMIN_LISTEN_PORT=8001

容器运行结果:

80/tcp, 443/tcp, 0.0.0.0:8001->8001/tcp                                  elitecars_local_pgadmin_ctnr 

修改后的Nginx配置

django.conf

upstream django_app {
  server  pgadmin:8001;
}
server {
  listen  80;
  listen  [::]:80;
  server_name   localhost;
  return 301 https://$host$request_uri;
  ...
}

pgadmin.conf

upstream pgadmin_app {
  server  django:8000;
}
server {
  listen  80;
  listen  [::]:80;
  server_name   pgadmin.localhost;
  return 301 https://$host$request_uri;
  ...
}

Hosts配置

127.0.0.1       localhost pgadmin.localhost *.localhost
...

本地问题现象

访问http://localhost可正常反向代理到PgAdmin,但访问http://pgadmin.localhost无法正常跳转,推断问题出在子域名与server_name的匹配配置。


三、解决思路

1. 修正上游服务的核心错误

  • AWS环境:pgadmin.conf的upstream pgadmin_app指向了ec2_private_IP:80,而这个端口是Nginx容器的监听端口,导致请求被循环代理回Nginx,最终匹配到Django的server块。正确配置应为:
    upstream pgadmin_app {
      server  ec2_private_IP:5050; # 对应pgadmin_ctnr映射的主机端口5050
      # 更优方案:如果容器在同一Docker网络,直接用容器名访问:server pgadmin_ctnr:80;
    }
    
  • 本地测试环境:当前Nginx上游配置完全搞反,需修正为:
    # django.conf
    upstream django_app {
      server django:8000;
    }
    # pgadmin.conf
    upstream pgadmin_app {
      server pgadmin:8001;
    }
    

2. 验证Nginx配置的有效性

  • 执行nginx -t检查配置语法是否合法
  • 执行nginx -s reload确保配置已重载生效
  • 查看Nginx日志(如/var/log/nginx/access.log、error.log),确认请求pgadmin.stage.my_domain.es或pgadmin.localhost匹配到了对应的server块

3. 确认server_name的匹配优先级

Nginx会优先匹配最具体的server_name:

  • 确保pgadmin.conf中的server_name *.pgadmin.stage.my_domain.es pgadmin.stage.my_domain.es比django.conf中的*.stage.my_domain.es更具体,理论上Nginx会优先匹配前者
  • 检查Nginx主配置文件是否正确包含了pgadmin.conf,比如添加include /etc/nginx/conf.d/pgadmin.conf;(路径根据实际情况调整)

4. 其他排查点

  • AWS环境:确认pgadmin.stage.my_domain.es已正确解析到EC2实例的公网IP
  • 本地环境:清除浏览器缓存,或用curl -v http://pgadmin.localhost查看请求头中的Host字段是否正确传递给Nginx
  • Docker网络:如果容器在同一自定义网络,优先使用容器名代替IP访问上游服务,避免IP变动导致的问题

内容的提问来源于stack exchange,提问作者Alberto Sanmartin Martinez

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.30 07:59:56