You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure ACI中Flask-SocketIO服务Nginx HTTPS配置问题排查

问题排查与修复方案

1. 证书错误(net::ERR_CERT_AUTHORITY_INVALID)核心原因

这个错误是客户端(浏览器)不认可Nginx配置的TLS证书颁发机构,常见场景:

  • 使用了自签名证书,未在客户端导入信任
  • 证书的域名/IP与ACI的公网访问地址不匹配
  • 证书链不完整(缺少中间证书)

修复建议

  • 测试环境:可在浏览器中手动信任证书(弹出提示时选「高级」-「继续访问」),但生产环境禁止这么做
  • 生产环境:使用公开可信CA(如Let's Encrypt)颁发的证书,确保证书的Subject Alternative Name(SAN)包含ACI的公网域名或IP

2. Nginx配置关键检查点(适配Flask-SocketIO)

以下是标准配置模板,对比你的配置找差异:

server {
    listen 443 ssl;
    # 替换为你的ACI公网域名/IP
    server_name your-aci-public-domain-or-ip;

    # TLS证书路径,需与ACI挂载路径一致
    ssl_certificate /etc/nginx/certs/fullchain.pem;
    ssl_certificate_key /etc/nginx/certs/privkey.pem;

    # 代理普通HTTP请求到Flask服务
    location / {
        # 若Flask在Sidecar容器,替换为容器名(如flask-service)而非localhost
        proxy_pass http://flask-service:5000;
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;
    }

    # WebSocket代理核心配置,Flask-SocketIO依赖这些头
    location /socket.io {
        proxy_pass http://flask-service:5000/socket.io;
        proxy_http_version 1.1;
        proxy_set_header Upgrade $http_upgrade;
        proxy_set_header Connection "upgrade";
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;
        # 超时配置防止WebSocket连接被断开
        proxy_connect_timeout 7d;
        proxy_send_timeout 7d;
        proxy_read_timeout 7d;
    }
}

# 强制HTTP跳转HTTPS,彻底避免混合内容
server {
    listen 80;
    server_name your-aci-public-domain-or-ip;
    return 301 https://$host$request_uri;
}

你的配置可能存在的问题

  • 缺少/socket.io路径的专属代理:Flask-SocketIO的WebSocket连接通过该路径建立,必须配置WebSocket升级头
  • proxy_pass目标错误:ACI容器组内的容器需通过容器名称通信,而非localhost(比如Flask容器名为flask-service,则用http://flask-service:5000)
  • TLS证书路径错误:需确保aci-deploy.yml中证书文件挂载路径与Nginx配置一致

3. ACI部署配置(aci-deploy.yml)检查点

  • 端口映射:必须暴露443(HTTPS)和80(HTTP跳转)端口
  • 证书挂载:通过volumeMounts和volumes将证书文件(如Azure存储账户中的证书)挂载到Nginx容器指定路径
  • 容器间通信:Flask与Nginx需在同一容器组内,Flask容器仅需暴露5000端口(无需对外公开,容器组内访问即可)

示例配置片段:

containers:
  - name: nginx-sidecar
    image: nginx:alpine
    ports:
      - port: 443
        protocol: TCP
      - port: 80
        protocol: TCP
    volumeMounts:
      - name: cert-volume
        mountPath: /etc/nginx/certs
      - name: nginx-config
        mountPath: /etc/nginx/conf.d
  - name: flask-service
    image: your-flask-socketio-image
    ports:
      - port: 5000
        protocol: TCP
volumes:
  - name: cert-volume
    azureFile:
      shareName: cert-share
      storageAccountName: your-storage-account
      storageAccountKey: your-storage-key
  - name: nginx-config
    azureFile:
      shareName: nginx-config-share
      storageAccountName: your-storage-account
      storageAccountKey: your-storage-key

4. 客户端连接代码修正

确保客户端使用wss://协议连接,避免混合内容错误:

const socket = io('https://your-aci-public-domain-or-ip', {
    transports: ['websocket']
});

内容的提问来源于stack exchange,提问作者noam suissa

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.08 01:48:15