使用jwilder/nginx-proxy搭配Cloudflare SSL(源密钥)时HTTPS请求出现500内部服务器错误的求助
Let’s dig into why your HTTPS requests are throwing a 500 error while HTTP works perfectly. I’ve spotted several potential issues in your configs and have actionable fixes to resolve this:
1. Fix Duplicate Volume Definition in Nginx-Proxy Compose
First, your reverse proxy’s docker-compose has a duplicate private: entry under volumes. This can cause unexpected volume mapping issues that break SSL certificate loading. Correct that section:
volumes: certs: private: nginx-conf:
2. Verify VIRTUAL_PROTO Matches Backend Nginx’s Actual Protocol
You’ve set VIRTUAL_PROTO: https for your LEMP nginx container, but this tells jwilder/nginx-proxy to connect to your backend over HTTPS. If your LEMP nginx isn’t properly configured to listen on 443 with a valid SSL certificate, this will fail with a 500 error.
Two Options Here:
Option A: Switch Backend to HTTP (Simpler)
If you don’t need end-to-end HTTPS between nginx-proxy and your LEMP stack, changeVIRTUAL_PROTO: httpstoVIRTUAL_PROTO: http. This makes nginx-proxy forward requests over HTTP to your LEMP nginx’s exposed 80 port.Option B: Properly Configure HTTPS on LEMP Nginx
If you want end-to-end HTTPS, ensure your LEMP nginx has a valid Cloudflare Origin CA certificate configured:- Mount your Cloudflare Origin CA key to the LEMP nginx container (right now you only mount certs, not private keys):
Add this volume to your LEMP nginx service:- ../nginx_proxy_dock/private:/etc/ssl/private - Update your LEMP nginx config (in
./nginx/conf.d/) with an SSL server block:server { listen 443 ssl; server_name certbot.xxxxxx.net; ssl_certificate /etc/ssl/certs/certbot.xxxxxx.net.crt; ssl_certificate_key /etc/ssl/private/certbot.xxxxxx.net.key; root /var/www/html; index index.php index.html; location ~ \.php$ { fastcgi_pass php:9000; fastcgi_index index.php; fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name; include fastcgi_params; } }
- Mount your Cloudflare Origin CA key to the LEMP nginx container (right now you only mount certs, not private keys):
3. Validate Network Connectivity
Make sure your nginx-proxy and LEMP nginx containers can communicate over the webproxy network. Test this with:
docker exec nginx-proxy ping lemp_nginx
If the ping fails, double-check that both containers are properly attached to the webproxy external network (your config looks correct here, but it’s worth verifying with docker network inspect webproxy).
4. Check Logs for Exact Error Details
Logs will tell you the precise cause of the 500 error—don’t skip this step!
- View nginx-proxy logs:
docker logs nginx-proxy - View LEMP nginx logs:
docker logs lemp_nginx
Look for errors like SSL handshake failures, missing certificates, or connection timeouts to the backend.
5. Confirm Cloudflare SSL Mode Settings
Ensure Cloudflare’s SSL mode is set to Full or Full (Strict) (not Flexible), and that your origin server (nginx-proxy/LEMP) is using a valid Cloudflare Origin CA certificate. Flexible mode will cause issues if your backend expects HTTPS traffic.
Final Steps After Fixes
Once you’ve applied the above changes, restart all containers to apply the configs:
# Restart nginx-proxy cd path/to/nginx-proxy-compose docker-compose down && docker-compose up -d # Restart LEMP stack cd path/to/lemp-compose docker-compose down && docker-compose up -d
内容的提问来源于stack exchange,提问作者mr.StandAloneZ

