求助:如何通过Cloudflare为Elastic Beanstalk上的API服务配置HTTPS?
Let’s work through the issues you’re seeing with both your Elastic Beanstalk native domain and custom API domain. Here’s how to diagnose and fix each part step by step:
First: Fix the Elastic Beanstalk Native Domain HTTPS Error
When you hit https://xxxxx.yyyyy.eu-west-1.elasticbeanstalk.com and get an error, it’s likely tied to load balancer configuration or security group missteps:
- Verify ACM certificate region: Ensure your
*.nameofmydomain.comcertificate was created in the eu-west-1 region (matching your EB environment). AWS load balancers can only attach certificates from their own region. - Audit the 443 listener setup:
- Head to your EB environment’s Load Balancer settings, confirm the 443 listener forwards traffic to your EC2 instances on port 80 (the default for most EB apps—adjust if your app uses a different port).
- Double-check that the listener is linked to the correct ACM certificate (match the ARN to the one you created).
- Check security group rules: Make sure your load balancer’s security group allows inbound port 443 traffic from
0.0.0.0/0(all IPs). Also, confirm your EC2 instances’ security group accepts inbound traffic from the load balancer’s security group on the target port (e.g., 80).
Next: Fix the Custom Domain (api.nameofmydomain.com) Issues
Cloudflare adds an extra layer of configuration—here are the critical settings to get right:
- Set Cloudflare’s SSL mode correctly:
- Go to Cloudflare → your domain → SSL/TLS → Overview.
- Switch from Flexible to Full or Full (strict). Flexible mode sends HTTP traffic from Cloudflare to your EB server, which will fail if your load balancer only accepts HTTPS. Full mode uses HTTPS between Cloudflare and your server, aligning with your EB 443 listener setup.
- Confirm CNAME and proxy status:
- Double-check that your CNAME record for
api.nameofmydomain.compoints exactly to your EB native domain (xxxxx.yyyyy.eu-west-1.elasticbeanstalk.com). - If you want Cloudflare to handle SSL and caching, leave the proxy status as Proxied (orange cloud). If you disable it (gray cloud), ensure your ACM wildcard cert covers
api.nameofmydomain.com(which it does) and that your EB load balancer is serving this certificate correctly.
- Double-check that your CNAME record for
- Force HTTPS globally:
- In Cloudflare → SSL/TLS → Edge Certificates, enable Always Use HTTPS to redirect all HTTP traffic to HTTPS. This prevents users from hitting HTTP-related errors when accessing your custom domain.
Quick Additional Checks
- Wait for DNS propagation: DNS changes (like your Cloudflare CNAME) can take up to 24 hours to fully roll out, though it’s often faster. Use
nslookup api.nameofmydomain.comin your terminal to confirm the CNAME resolves to the correct EB domain. - Validate ACM certificate status: In AWS Certificate Manager, confirm your wildcard cert shows as Issued. If it’s stuck in pending validation, double-check that you completed DNS validation (Cloudflare usually auto-adds required TXT records, but manual confirmation may be needed in some cases).
Once you’ve worked through these steps, test both domains again. Your EB native domain should load over HTTPS with AWS’s default certificate (or your wildcard cert if configured), and your custom api.nameofmydomain.com should work smoothly with Cloudflare handling edge SSL.
内容的提问来源于stack exchange,提问作者Thirsty

