You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Nginx作为负载均衡器时出现502错误的问题排查

Nginx反向代理502错误排查

环境信息

  • 两台CentOS7 Linode计算实例:
    • 私有IP:192.168.150.22,标识:load_balancer(负载均衡节点)
    • 私有IP:192.168.150.95,标识:app01(应用节点)

Nginx配置(load_balancer实例)

nginx.conf内容如下:

events {
    worker_connections 1024;
}

http {
    upstream backend {
        server 192.168.150.95:5000;
    }

    server {
        listen 80;
        location / {
            proxy_pass http://backend;
        }
    }
}

应用状态与问题现象

  • app01实例上,Node.js Web应用运行在5000端口,目录位于/opt/app
  • 可通过curl 192.168.150.95:5000正常访问应用,但通过浏览器访问load_balancer实例时,Nginx返回502错误页面

防火墙规则

load_balancer实例

执行firewall-cmd --list-all输出:

public (active)
  target: default
  icmp-block-inversion: no
  interfaces: eth0
  sources:
  services: dhcpv6-client ssh
  ports: 80/tcp 5000/tcp
  protocols:
  masquerade: no
  forward-ports:
  source-ports:
  icmp-blocks:
  rich rules:

app01实例

执行firewall-cmd --list-all输出:

public (active)
  target: default
  icmp-block-inversion: no
  interfaces: eth0
  sources:
  services: dhcpv6-client ssh
  ports: 5000/tcp
  protocols:
  masquerade: no
  forward-ports:
  source-ports:
  icmp-blocks:
  rich rules:

Nginx错误日志(load_balancer实例)

执行tail error.log -n 5输出:

2023/07/15 07:46:35 [crit] 7610#7610: *1 connect() to 192.168.150.95:5000 failed (13: Permission denied) while connecting to upstream, client: x.x.x.x, server: , request: "GET /favicon.ico HTTP/1.1", upstream: "http://192.168.150.95:5000/favicon.ico", host: "y.y.y.y", referrer: "http://y.y.y.y/"
2023/07/15 07:49:39 [crit] 7610#7610: *4 connect() to 192.168.150.95:5000 failed (13: Permission denied) while connecting to upstream, client: x.x.x.x, server: , request: "GET /.git/config HTTP/1.1", upstream: "http://192.168.150.95:5000/.git/config", host: "y.y.y.y"
2023/07/15 07:49:39 [crit] 7610#7610: *6 connect() to 192.168.150.95:5000 failed (13: Permission denied) while connecting to upstream, client: x.x.x.x, server: , request: "GET /.git/config HTTP/1.1", upstream: "http://192.168.150.95:5000/.git/config", host: "y.y.y.y"
2023/07/15 07:49:43 [crit] 7610#7610: *8 connect() to 192.168.150.95:5000 failed (13: Permission denied) while connecting to upstream, client: x.x.x.x, server: , request: "GET /.git/config HTTP/1.1", upstream: "http://192.168.150.95:5000/.git/config", host: "y.y.y.y"
2023/07/15 07:49:44 [crit] 7610#7610: *10 connect() to 192.168.150.95:5000 failed (13: Permission denied) while connecting to upstream, client: x.x.x.x, server: , request: "GET /.git/config HTTP/1.1", upstream: "http://192.168.150.95:5000/.git/config", host: "y.y.y.y"

问题分析与解决方法

错误日志中的Permission denied明确指向CentOS7默认启用的SELinux阻止了Nginx发起上游连接请求。

解决步骤

  1. 临时测试(重启后失效)
    临时关闭SELinux验证问题:

    setenforce 0
    

    测试访问,若恢复正常则确认是SELinux导致。

  2. 永久生效(推荐方案)
    添加SELinux规则,允许Nginx发起网络连接:

    setsebool -P httpd_can_network_connect on
    

    参数-P表示规则永久生效,重启系统后不会丢失。

  3. 验证规则状态
    检查规则是否生效:

    getsebool httpd_can_network_connect
    

    正常输出应为httpd_can_network_connect --> on

最后重启Nginx服务:

systemctl restart nginx

再次访问load_balancer实例即可正常转发请求到app01的应用。


内容的提问来源于stack exchange,提问作者Abu Zakaria

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.15 21:46:02