升级至.NET8后Azure容器Web App出现HTTPS启动错误的咨询
问题描述
我在Azure上运行一个基于Linux的容器Web App,从容器注册表拉取Docker镜像。原本的.NET7 Web App运行正常,升级至.NET8并设置推荐的默认端口8080后,Web App因HTTPS错误无法启动。
相关配置
Dockerfile(相关部分)
FROM mcr.microsoft.com/dotnet/aspnet:8.0 AS base WORKDIR /app EXPOSE 8080 EXPOSE 443
Web App环境变量
"ASPNETCORE_HTTP_PORTS": "8080", "ASPNETCORE_HTTPS_PORTS": "443"
HTTPS Only: 开启
错误日志
2024-01-21T22:48:44.411145098Z {"Timestamp":"2024-01-21T22:48:44.2947105+00:00","Level":"Error","MessageTemplate":"Hosting failed to start","Exception":"System.InvalidOperationException: Unable to configure HTTPS endpoint. No server certificate was specified, and the default developer certificate could not be found or is out of date. To generate a developer certificate run 'dotnet dev-certs https'. To trust the certificate (Windows and macOS only) run 'dotnet dev-certs https --trust'. at Microsoft.AspNetCore.Hosting.ListenOptionsHttpsExtensions.UseHttps(ListenOptions listenOptions, Action`1 configureOptions) at Microsoft.AspNetCore.Server.Kestrel.Core.Internal.AddressBinder.AddressesStrategy.BindAsync(AddressBindContext context, CancellationToken cancellationToken) at Microsoft.AspNetCore.Server.Kestrel.Core.Internal.AddressBinder.BindAsync(ListenOptions[] listenOptions, AddressBindContext context, Func`2 useHttps, CancellationToken cancellationToken) at Microsoft.AspNetCore.Server.Kestrel.Core.KestrelServerImpl.BindAsync(CancellationToken cancellationToken) at Microsoft.AspNetCore.Server.Kestrel.Core.KestrelServerImpl.StartAsync[TContext](IHttpApplication`1 application, CancellationToken cancellationToken) at Microsoft.AspNetCore.Hosting.GenericWebHostService.StartAsync(CancellationToken cancellationToken) at Microsoft.Extensions.Hosting.Internal.Host.<StartAsync>b__15_1(IHostedService service, CancellationToken token) at Microsoft.Extensions.Hosting.Internal.Host.ForeachService[T](IEnumerable`1 services, CancellationToken token, Boolean concurrent, Boolean abortOnFirstException, List`1 exceptions, Func`3 operation)","Properties":{"EventId":{"Id":11,"Name":"HostedServiceStartupFaulted"},"SourceContext":"Microsoft.Extensions.Hosting.Internal.Host"}} 2024-01-21T22:48:44.411193001Z {"Timestamp":"2024-01-21T22:48:44.3617139+00:00","Level":"Fatal","MessageTemplate":"Ouch! Host building terminated unexpectedly","Exception":"System.InvalidOperationException: Unable to configure HTTPS endpoint. No server certificate was specified, and the default developer certificate could not be found or is out of date. To generate a developer certificate run 'dotnet dev-certs https'. To trust the certificate (Windows and macOS only) run 'dotnet dev-certs https --trust'. at Microsoft.AspNetCore.Hosting.ListenOptionsHttpsExtensions.UseHttps(ListenOptions listenOptions, Action`1 configureOptions) at Microsoft.AspNetCore.Server.Kestrel.Core.Internal.AddressBinder.AddressesStrategy.BindAsync(AddressBindContext context, CancellationToken cancellationToken) at Microsoft.AspNetCore.Server.Kestrel.Core.Internal.AddressBinder.BindAsync(ListenOptions[] listenOptions, AddressBindContext context, Func`2 useHttps, CancellationToken cancellationToken) at Microsoft.AspNetCore.Server.Kestrel.Core.KestrelServerImpl.BindAsync(CancellationToken cancellationToken) at Microsoft.AspNetCore.Server.Kestrel.Core.KestrelServerImpl.StartAsync[TContext](IHttpApplication`1 application, CancellationToken cancellationToken) at Microsoft.AspNetCore.Hosting.GenericWebHostService.StartAsync(CancellationToken cancellationToken) at Microsoft.Extensions.Hosting.Internal.Host.<StartAsync>b__15_1(IHostedService service, CancellationToken token) at Microsoft.Extensions.Hosting.Internal.Host.ForeachService[T](IEnumerable`1 services, CancellationToken token, Boolean concurrent, Boolean abortOnFirstException, List`1 exceptions, Func`3 operation) at Microsoft.Extensions.Hosting.Internal.Host.StartAsync(CancellationToken cancellationToken) at Microsoft.Extensions.Hosting.HostingAbstractionsHostExtensions.RunAsync(IHost host, CancellationToken token) at Microsoft.Extensions.Hosting.HostingAbstractionsHostExtensions.RunAsync(IHost host, CancellationToken token) at Microsoft.Extensions.Hosting.HostingAbstractionsHostExtensions.Run(IHost host) at Program.<Main>$(String[] args) in /src/testProject.Core/Program.cs:line 247"} /home/LogFiles/2024_01_21_lw1sdlwk0007NS_docker.log 2024-01-21T22:48:42.076Z INFO - Status: Image is up to date for mcr.microsoft.com/appsvc/middleware:stage5 2024-01-21T22:48:42.145Z INFO - Pull Image successful, Time taken: 1 Seconds 2024-01-21T22:48:42.370Z INFO - Starting container for site 2024-01-21T22:48:42.378Z INFO - docker run -d -p 5227:8181 --name testProject-api_0_1334c363_middleware -e WEBSITE_CORS_ALLOWED_ORIGINS=https://testProject-api.azurewebsites.net -e WEBSITE_CORS_SUPPORT_CREDENTIALS=True -e DOCKER_CUSTOM_IMAGE_NAME=projecttestcr.azurecr.io/testProjectapi:458 -e WEBSITES_ENABLE_APP_SERVICE_STORAGE=false -e WEBSITE_SITE_NAME=testProject-api -e WEBSITE_AUTH_ENABLED=False -e WEBSITE_ROLE_INSTANCE_ID=0 -e WEBSITE_HOSTNAME=testProject-api.azurewebsites.net -e WEBSITE_INSTANCE_ID=1234e06e53eec8d5c5f366b3597570d9375ce0ef48cc72401db89ecd02d82bd0 mcr.microsoft.com/appsvc/middleware:stage5 /Host.ListenUrl=http://0.0.0.0:8181 /Host.DestinationHostUrl=http://172.16.254.3:8080 /Host.UseFileLogging=true 2024-01-21T22:48:42.381Z INFO - Logging is not enabled for thi2024-01-21T22:48:47.449Z INFO - Initiating warmup request to container testProject-api_0_1334c363 for site testProject-api 2024-01-21T22:48:47.575Z ERROR - Container testProject-api_0_1334c363 for site testProject-api has exited, failing site start 2024-01-21T22:48:47.577Z INFO - Initiating warmup request to container testProject-api_0_1334c363_middleware for site testProject-api 2024-01-21T22:48:57.980Z INFO - Container testProject-api_0_1334c363_middleware for site testProject-api initialized successfully and is ready to serve requests. 2024-01-21T22:48:58.017Z ERROR - Container testProject-api_0_1334c363 didn't respond to HTTP pings on port: 8080, failing site start. See container logs for debugging. 2024-01-21T22:48:58.163Z INFO - Stopping site testProject-api because it failed during startup.Ending Log Tail of existing logs ---Starting Live Log Stream --- 2024-01-21T22:51:26 No new trace in the past 1 min(s).
解决方案
核心问题是Azure App Service Linux容器环境中,.NET 8应用尝试绑定HTTPS端口443但找不到有效证书。实际上Azure会在前端完成HTTPS终止,容器内部只需监听HTTP端口即可,按以下步骤调整:
- 移除HTTPS端口环境变量:删除
ASPNETCORE_HTTPS_PORTS,仅保留ASPNETCORE_HTTP_PORTS: "8080" - 调整Dockerfile(可选):移除
EXPOSE 443,因为容器内部不再需要监听HTTPS端口 - 保留HTTPS Only设置:无需关闭Azure Portal中的"HTTPS Only"开关,Azure会自动将外部HTTPS请求转发到容器内部的HTTP 8080端口
- 验证应用代码:确保代码中没有强制在容器内部配置HTTPS证书的逻辑,
app.UseHttpsRedirection()可以保留,不会影响运行
内容的提问来源于stack exchange,提问作者messerke
相关产品推荐
相关产品推荐

