Nginx反向代理实现Ingress与Egress流量URI转换的配置问题咨询
Got it, let's work through your Nginx proxy configuration issue step by step. You're trying to handle both ingress URI rewriting (from /test/ to / for the backend) and egress URI rewriting (changing backend responses back to /test/ for the client), plus you're hitting a 502 error. Let's fix this.
1. Fix the Ingress URI Rewriting
Your original configuration is missing the key part: targeting the /test/ path and properly rewriting it to / for the backend. Here's what you need to adjust:
- Instead of a
location /block (which matches all requests), use alocation /test/block to only catch requests coming from the internet with the/test/URI. - Add a trailing
/to theproxy_passvalue—this tells Nginx to replace the matched/test/portion of the URI with/when forwarding to the backend.
2. Handle Egress URI Rewriting
To rewrite the backend's response (which uses / paths) back to /test/ for the client, you'll use Nginx's sub_filter module (most official Nginx images include this by default). This replaces all instances of relative paths in the response (like href="/" or src="/") with /test/ so the client sees the original URI structure.
3. Resolve the 502 Bad Gateway Error
The 502 usually means Nginx can't reach your backend container. Common fixes:
- Avoid hardcoding Docker IPs: Docker assigns dynamic internal IPs to containers on restart. Instead, put both containers on the same custom Docker network and use container names for DNS resolution—this is far more stable.
- Check backend listening address: Ensure your backend service inside the container listens on
0.0.0.0:12345(not justlocalhost:12345). If it's only bound to localhost, other containers can't reach it. - Verify network connectivity: Confirm both containers are attached to the same Docker network so they can communicate.
Full Working Nginx Configuration
Replace your current Nginx config with this:
server { listen 8888; # Use "_" to match any incoming host, or replace with your EC2's public IP/domain server_name _; location /test/ { # Replace "backend-container" with your actual backend container's name # (or use its stable IP if you're not using a custom network) proxy_pass http://backend-container:12345/; # Pass critical request headers to the backend so it knows the original request details proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; # Rewrite all backend response URIs back to /test/ sub_filter 'href="/' 'href="/test/'; sub_filter 'src="/' 'src="/test/'; sub_filter 'action="/' 'action="/test/'; # Ensure we replace every match, not just the first one sub_filter_once off; } }
Docker Network Setup (To Avoid IP Headaches)
Create a shared network and attach both containers to it:
# Create a custom network for your app docker network create app-network # Run Nginx, attached to the network and mapping port 8888 to EC2 docker run -d --name nginx-proxy --network app-network -p 8888:8888 nginx # Run your backend container on the same network docker run -d --name backend-container --network app-network your-backend-image
Final Checks
- Restart your Nginx container to apply the new configuration.
- Verify your backend service listens on
0.0.0.0:12345(rundocker exec backend-container netstat -tulpnto check). - Test the flow: send a request to
http://your-ec2-public-ip:8888/test/—it should forward to the backend with the URI rewritten to/, and the response should show/test/paths for all links and assets.
内容的提问来源于stack exchange,提问作者FLATeric

