ALB转发至WebServer后实现URL隐式跳转的配置指导请求
问题场景与需求
现有环境
- WebServer域名:
example1.com,与应用服务器通过WebPlugin集成,所有通信采用HTTP协议。用户访问http://example1.com/hello时,加载应用服务器/hello目录下的内容。 - 已配置ALB,域名
example2.com,用户访问https://example2.com时,请求会转发至WebServer(example1.com)。
核心需求
当请求从ALB到达WebServer后,需引导用户访问http://example1.com/hello对应的内容,但浏览器地址栏必须显示https://example2.com/hello。
配置方案
1. ALB端:传递真实请求头
确保ALB转发请求时,向WebServer传递以下请求头,让WebServer识别用户实际访问的外部域名和协议:
X-Forwarded-Proto: 设置为httpsX-Forwarded-Host: 设置为example2.com
2. WebServer端配置(以Nginx为例)
根路径跳转配置
当WebServer收到ALB转发的根路径请求(/)时,返回302跳转,目标指向ALB域名的/hello路径:
server { listen 80; server_name example1.com; # 根路径请求跳转至ALB的/hello location = / { set $forward_proto $http_x_forwarded_proto; set $forward_host $http_x_forwarded_host; return 302 $forward_proto://$forward_host/hello; } # 处理/hello路径请求,转发至应用服务器 location /hello { # 传递外部访问的域名和协议给应用服务器 proxy_set_header Host $http_x_forwarded_host; proxy_set_header X-Forwarded-Proto $http_x_forwarded_proto; # 转发到应用服务器的/hello目录 proxy_pass http://应用服务器IP/hello; # 替换响应内容中残留的旧域名/协议 sub_filter 'http://example1.com' 'https://example2.com'; sub_filter_once off; } }
关键要点
- 跳转目标使用
X-Forwarded-Host和X-Forwarded-Proto,确保浏览器地址栏显示https://example2.com/hello。 proxy_set_header Host配置让应用服务器生成链接时使用外部域名example2.com。sub_filter模块需提前开启(Nginx编译时需添加--with-http_sub_module),用于替换响应内容中可能存在的旧域名链接,避免用户跳转回example1.com。
3. WebPlugin适配检查
确认WebPlugin优先读取X-Forwarded-Host和X-Forwarded-Proto来生成页面链接,而非WebServer自身的example1.com和HTTP协议,保证所有页面内链接均指向https://example2.com。
验证步骤
- 访问
https://example2.com,检查地址栏是否自动变更为https://example2.com/hello。 - 确认页面内容与直接访问
http://example1.com/hello完全一致。 - 点击页面内任意链接,验证跳转地址均为
https://example2.com开头。
内容的提问来源于stack exchange,提问作者RRG
相关产品推荐
相关产品推荐

