You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

部署于AWS ECS的Spring Boot应用Thymeleaf重定向至HTTP而非HTTPS问题求助

解决方案

1. 让Spring Boot识别负载均衡的转发协议头

AWS负载均衡器会把HTTPS请求转换成HTTP转发给ECS容器,Spring Boot默认会用转发后的HTTP协议生成重定向URL,需要配置让它信任负载均衡传递的X-Forwarded-Proto头:

在application.properties中添加配置:

# 启用框架级转发头处理(适用于Spring Boot 2.2+)
server.forward-headers-strategy=framework

# 若使用旧版Spring Boot,用以下Tomcat专属配置
server.tomcat.remote-ip-header=x-forwarded-for
server.tomcat.protocol-header=x-forwarded-proto

如果集成了Spring Security,还需要让Security也识别这些头,添加配置类:

import org.springframework.context.annotation.Configuration;
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
import org.springframework.security.config.annotation.web.configuration.WebSecurityConfigurerAdapter;

@Configuration
public class SecurityConfig extends WebSecurityConfigurerAdapter {
    @Override
    protected void configure(HttpSecurity http) throws Exception {
        http
            .requiresChannel()
                .requestMatchers(r -> r.getHeader("X-Forwarded-Proto") != null)
                .requiresSecure();
    }
}

2. 确认负载均衡器的转发头配置

进入AWS控制台,检查负载均衡器对应的目标组:

  • 路径:EC2 -> 负载均衡器 -> 目标组 -> 选中你的目标组 -> 编辑属性
  • 确保转发头选项中已启用X-Forwarded-Proto、X-Forwarded-Port、X-Forwarded-For(默认通常开启,需确认状态)

3. 强制所有请求使用HTTPS(可选兜底)

如果上述配置仍有问题,可以在Spring Security中强制所有请求走HTTPS:

@Configuration
public class SecurityConfig extends WebSecurityConfigurerAdapter {
    @Override
    protected void configure(HttpSecurity http) throws Exception {
        http
            .requiresChannel()
                .anyRequest().requiresSecure();
    }
}

或者在application.properties中添加:

security.require-ssl=true

4. 验证域名与SSL配置

  • 确认Route53的域名解析记录指向负载均衡器的HTTPS端点(443端口)
  • 检查负载均衡器已绑定AWS Certificate Manager(ACM)的有效SSL证书,确保外部请求确实通过HTTPS进入负载均衡器

内容的提问来源于stack exchange,提问作者Nitin Bisht

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.11 16:18:20