Azure Ubuntu服务器Backstage无法获取目录实体及CORS问题求助
问题描述
在Azure Ubuntu 20服务器上全新部署Backstage应用,按官方入门步骤操作后:
- 初始配置中frontend、backend的baseUrl及CORS origin均设为
http://0.0.0.0:对应端口,能通过公网IP访问应用,但出现Cannot fetch catalog entities错误。 - 将公网IP添加到
/etc/hosts及app-config.yaml的baseUrl和CORS origin后,运行yarn dev出现EADDRNOTAVAIL错误。 - 已为VM网络安全组添加3000、7007、22端口入站规则,但调整配置后仍遭CORS策略拦截,控制台有对应报错。
初始配置如下:
app: title: Scaffolded Backstage App baseUrl: http://0.0.0.0:3000 organization: name: My Company backend: # Used for enabling authentication, secret is shared by all backend plugins # See https://backstage.io/docs/auth/service-to-service-auth for # information on the format # auth: # keys: # - secret: ${BACKEND_SECRET} baseUrl: http://0.0.0.0:7007 listen: port: 7007 # Uncomment the following host directive to bind to specific interfaces # host: localhost csp: connect-src: ["'self'", 'http:', 'https:'] # Content-Security-Policy directives follow the Helmet format: https://helmetjs.github.io/#reference # Default Helmet Content-Security-Policy values can be removed by setting the key to false cors: origin: http://0.0.0.0:3000 methods: [GET, HEAD, PATCH, POST, PUT, DELETE] credentials: true
解决方案
1. 修正Backend监听配置
Azure服务器的公网IP并非本地网卡绑定的IP,直接将backend.listen.host设为公网IP会导致EADDRNOTAVAIL错误。需保持监听所有接口:
- 显式设置
backend.listen.host: 0.0.0.0,确保Backend能接收来自所有网络接口的请求。
2. 调整app-config.yaml核心配置
将<你的Azure公网IP>替换为实际的服务器公网IP,修改后的配置如下:
app: title: Scaffolded Backstage App baseUrl: http://<你的Azure公网IP>:3000 organization: name: My Company backend: baseUrl: http://<你的Azure公网IP>:7007 listen: port: 7007 host: 0.0.0.0 csp: connect-src: ["'self'", "http://<你的Azure公网IP>:7007", 'http:', 'https:'] # 补充Backend公网IP,确保CSP允许前端发起跨域请求 cors: origin: http://<你的Azure公网IP>:3000 methods: [GET, HEAD, PATCH, POST, PUT, DELETE] credentials: true
3. 验证网络规则
- 确认Azure网络安全组的入站规则中,3000、7007端口允许你的本地IP地址(测试阶段可临时设为
0.0.0.0/0)。 - 检查服务器本地防火墙(如
ufw)是否放行目标端口,执行命令:sudo ufw allow 3000/tcp sudo ufw allow 7007/tcp sudo ufw reload
4. 重启服务并清除缓存
yarn cache clean yarn dev
完成以上步骤后,通过公网IP访问http://<你的Azure公网IP>:3000即可正常获取Catalog实体,且不会触发CORS拦截。
内容的提问来源于stack exchange,提问作者RAnand
相关产品推荐
相关产品推荐

