You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Docker Compose配置Nginx+Certbot获取SSL证书遇连接拒绝问题求助

排查Docker Compose + Nginx + Certbot配置问题

端口与防火墙检查

  • 确认VPS的80、443端口在系统防火墙(ufw/iptables)和云服务商安全组中均已开放,这是ACME挑战和网站访问的基础前提。
  • 执行docker ps查看Nginx容器的端口映射状态,确保80->80、443->443的映射无冲突,容器正常监听目标端口。

Nginx配置(app.conf)校验

  • 必须在HTTP的server块中添加ACME挑战的location配置,缺失此配置会导致Certbot无法获取验证文件:
    location /.well-known/acme-challenge/ {
        root /var/www/certbot;
        allow all;
    }
    
  • 检查server_name字段是否准确设置为rusinas.wtf www.rusinas.wtf,避免域名拼写错误。
  • 核对docker-compose.yml中的挂载路径,确保app.conf、certbot的conf和www目录正确挂载到Nginx容器,示例配置如下:
    volumes:
      - ./app.conf:/etc/nginx/conf.d/app.conf
      - ./certbot/conf:/etc/letsencrypt
      - ./certbot/www:/var/www/certbot
    

Certbot执行逻辑检查

  • 执行脚本需先启动Nginx,待容器完全就绪后再运行Certbot申请证书,否则Certbot运行时Nginx未完成初始化,挑战必然失败。
  • 检查Certbot命令参数,确保webroot路径与Nginx挂载的/var/www/certbot一致,域名参数无错误:
    certbot certonly --webroot -w /var/www/certbot -d rusinas.wtf -d www.rusinas.wtf --email your-email@example.com --agree-tos --no-eff-email
    

DNS解析验证

  • 使用nslookup rusinas.wtf和nslookup www.rusinas.wtf查询域名解析状态,确认域名已正确指向VPS公网IP,排除解析错误或缓存问题。

容器日志查错

  • 查看Nginx容器日志:docker logs <nginx容器名>,排查是否存在配置语法错误、端口监听失败等异常信息。
  • 查看Certbot容器日志:docker logs <certbot容器名>,获取ACME挑战失败的具体原因(如文件无法访问、连接超时等)。

手动测试挑战路径

  • 在VPS的./certbot/www目录下创建测试文件,例如touch ./certbot/www/test-123,通过curl或浏览器访问http://rusinas.wtf/.well-known/acme-challenge/test-123。若能正常获取文件内容,说明Nginx挂载与配置无问题;若无法访问,则需排查路径或配置错误。

内容的提问来源于stack exchange,提问作者Andrew Rusinas

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.03 01:20:08