You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Dokku配置Let's Encrypt SSL证书失败问题求助

Dokku应用无法获取Let's Encrypt SSL证书

问题现象

为Dokku应用personal-app申请Let's Encrypt SSL证书时持续失败,报错包含:

  • nginx.service启动失败
  • ACME HTTP-01挑战返回404未授权

已完成验证:

  • 域名DNS A记录配置正确
  • 服务器80端口开放(telnet验证通过)
  • 域名可正常通过SSH和HTTP访问
  • 重建服务器并严格遵循Dokku文档操作,问题仍存在

相关日志

证书获取过程日志

=====> Enabling letsencrypt for personal-app
-----> Enabling ACME proxy for personal-app...
-----> Setting temporary site
Job for nginx.service failed.
See "systemctl status nginx.service" and "journalctl -xe" for details.
-----> Getting letsencrypt certificate for personal-app via HTTP-01
        - Domain 'app.[my-domain].ch'
2024/02/11 14:59:15 [INFO] [app.[my-domain].ch] acme: Obtaining bundled SAN certificate
2024/02/11 14:59:16 [INFO] [app.[my-domain].ch] AuthURL: https://acme-v02.api.letsencrypt.org/acme/authz-v3/314082842777
2024/02/11 14:59:16 [INFO] [app.[my-domain].ch] acme: Could not find solver for: tls-alpn-01
2024/02/11 14:59:16 [INFO] [app.[my-domain].ch] acme: use http-01 solver
2024/02/11 14:59:16 [INFO] [app.[my-domain].ch] acme: Trying to solve HTTP-01
2024/02/11 14:59:19 [INFO] Deactivating auth: https://acme-v02.api.letsencrypt.org/acme/authz-v3/314082842777
2024/02/11 14:59:19 Could not obtain certificates:
        error: one or more domains had a problem:
[app.[my-domain].ch] acme: error: 403 :: urn:ietf:params:acme:error:unauthorized :: 142.132.187.148: Invalid response from http://app.[my-domain].ch/.well-known/acme-challenge/VTYxIcvj1BHEXzQKaTF67Sp8GPYemQqQSNubW-VMKnk: 404
-----> Certificate retrieval failed!
-----> Disabling ACME proxy for personal-app...
 !     Failed to setup letsencrypt
 !     Check log output for further information on failure

systemctl status nginx.service日志

● nginx.service - A high performance web server and a reverse proxy server
     Loaded: loaded (/lib/systemd/system/nginx.service; enabled; vendor preset: enabled)
     Active: active (running) since Sun 2024-02-11 14:50:16 UTC; 50min ago
       Docs: man:nginx(8)
    Process: 39421 ExecStartPre=/usr/sbin/nginx -t -q -g daemon on; master_process on; (code=exited, status=0/SUCCESS)
    Process: 39442 ExecStart=/usr/sbin/nginx -g daemon on; master_process on; (code=exited, status=0/SUCCESS)
    Process: 47531 ExecReload=/usr/sbin/nginx -g daemon on; master_process on; -s reload (code=exited, status=0/SUCCESS)
   Main PID: 39451 (nginx)
      Tasks: 2 (limit: 2261)
     Memory: 4.6M
     CGroup: /system.slice/nginx.service
             ├─39451 nginx: master process /usr/sbin/nginx -g daemon on; master_process on;
             └─47532 nginx: worker process

Feb 11 15:16:06 personal1-1core1gb systemd[1]: Reloading A high performance web server and a reverse proxy server.
Feb 11 15:16:06 personal1-1core1gb systemd[1]: Reloaded A high performance web server and a reverse proxy server.
Feb 11 15:18:58 personal1-1core1gb systemd[1]: Reloading A high performance web server and a reverse proxy server.
Feb 11 15:18:58 personal1-1core1gb systemd[1]: Reloaded A high performance web server and a reverse proxy server.
Feb 11 15:18:58 personal1-1core1gb systemd[1]: Reloading A high performance web server and a reverse proxy server.
Feb 11 15:18:58 personal1-1core1gb nginx[47100]: nginx: [emerg] invalid number of arguments in "access_log" directive in /home/dokku/personal-app/nginx.con>
Feb 11 15:18:58 personal1-1core1gb systemd[1]: nginx.service: Control process exited, code=exited, status=1/FAILURE
Feb 11 15:18:58 personal1-1core1gb systemd[1]: Reload failed for A high performance web server and a reverse proxy server.
Feb 11 15:19:00 personal1-1core1gb systemd[1]: Reloading A high performance web server and a reverse proxy server.
Feb 11 15:19:00 personal1-1core1gb systemd[1]: Reloaded A high performance web server and a reverse proxy server.

journalctl -xe日志

-- A start job for unit dokku-retire.service has begun execution.
--
-- The job identifier is 3677.
Feb 11 15:35:40 personal1-1core1gb dokku[48365]: -----> Retiring old containers and images
Feb 11 15:35:40 personal1-1core1gb systemd[1]: dokku-retire.service: Succeeded.
-- Subject: Unit succeeded
-- Defined-By: systemd
-- Support: http://www.ubuntu.com/support
--
-- The unit dokku-retire.service has successfully entered the 'dead' state.
Feb 11 15:35:40 personal1-1core1gb systemd[1]: Finished Dokku retire service.
-- Subject: A start job for unit dokku-retire.service has finished successfully
-- Defined-By: systemd
-- Support: http://www.ubuntu.com/support
--
-- A start job for unit dokku-retire.service has finished successfully.
--
-- The job identifier is 3677.
Feb 11 15:37:52 personal1-1core1gb sshd[48598]: Invalid user public_django_project from 68.183.148.142 port 33464
Feb 11 15:37:52 personal1-1core1gb sshd[48598]: pam_unix(sshd:auth): check pass; user unknown
Feb 11 15:37:52 personal1-1core1gb sshd[48598]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=68.183.148.142
Feb 11 15:37:54 personal1-1core1gb sshd[48598]: Failed password for invalid user public_django_project from 68.183.148.142 port 33464 ssh2
Feb 11 15:37:55 personal1-1core1gb sshd[48598]: Connection closed by invalid user public_django_project 68.183.148.142 port 33464 [preauth]
Feb 11 15:40:49 personal1-1core1gb systemd[1]: Starting Dokku retire service...
-- Subject: A start job for unit dokku-retire.service has begun execution
-- Defined-By: systemd
-- Support: http://www.ubuntu.com/support
--
-- A start job for unit dokku-retire.service has begun execution.
--
-- The job identifier is 3765.
Feb 11 15:40:49 personal1-1core1gb dokku[48629]: -----> Retiring old containers and images
Feb 11 15:40:49 personal1-1core1gb systemd[1]: dokku-retire.service: Succeeded.
-- Subject: Unit succeeded
-- Defined-By: systemd
-- Support: http://www.ubuntu.com/support
--
-- The unit dokku-retire.service has successfully entered the 'dead' state.
Feb 11 15:40:49 personal1-1core1gb systemd[1]: Finished Dokku retire service.
-- Subject: A start job for unit dokku-retire.service has finished successfully
-- Defined-By: systemd
-- Support: http://www.ubuntu.com/support
--
-- A start job for unit dokku-retire.service has finished successfully.
--
-- The job identifier is 3765.

已完成排查

  • 防火墙配置:确认80端口允许外部连接(telnet验证通过)

分析与解决步骤

  1. 核心问题定位:从nginx状态日志可明确,/home/dokku/personal-app/nginx.conf中的access_log指令参数格式错误,导致nginx重载失败。这直接破坏了ACME代理的临时站点配置,使得HTTP-01挑战请求无法被正确路由,返回404错误。

  2. 修复操作:

    • 查看并修正应用的nginx配置文件:
      cat /home/dokku/personal-app/nginx.conf
      
      找到access_log行,确保格式符合nginx标准:access_log /path/to/log/file [日志格式];
    • 验证nginx配置有效性:
      nginx -t
      
      确认无语法错误后,重载nginx服务:
      systemctl reload nginx
      
    • 重新尝试获取SSL证书:
      dokku letsencrypt:enable personal-app
      
  3. 额外检查项:

    • 更新Dokku letsencrypt插件到最新版本,避免版本bug:
      dokku plugin:install https://github.com/dokku/dokku-letsencrypt.git letsencrypt
      
    • 若应用使用自定义nginx配置模板,检查模板中的access_log指令是否存在格式问题,防止重新部署时覆盖正确配置。

内容的提问来源于stack exchange,提问作者GiftChees

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.30 13:39:59