如何通过SSH隧道本地访问AWS Lightsail实例上的多站点应用
方案一:本地Host映射+SSH端口转发(推荐,贴近公网访问逻辑)
这种方式能实现site1:8888、site2:8888这类访问,完全复用服务器上已有的Vhost配置,无需修改服务器代码或配置。
建立SSH隧道
执行以下命令,将本地8888端口转发到Lightsail实例的80端口(如果服务器用HTTPS,换成443,本地端口可改用8443):ssh -L 8888:127.0.0.1:80 your-ssh-user@your-lightsail-public-ip保持SSH会话开启,隧道才会持续生效。
修改本地Hosts文件
将各站点域名指向本地127.0.0.1:- Linux/macOS:编辑
/etc/hosts,添加一行:127.0.0.1 site1 site2 site3 - Windows:编辑
C:\Windows\System32\drivers\etc\hosts(需管理员权限),添加同上内容。
- Linux/macOS:编辑
访问测试
在本地浏览器输入http://site1:8888,请求会通过SSH隧道转发到Lightsail实例的80端口,服务器的Vhost会根据Host: site1头匹配对应站点,返回正确内容。
如果服务器用HTTPS,隧道命令改成:
ssh -L 8443:127.0.0.1:443 your-ssh-user@your-lightsail-public-ip
访问时用https://site1:8443,由于证书域名不匹配,浏览器会提示不安全,直接忽略警告即可(仅本地开发场景使用)。
方案二:基于路径的访问(127.0.0.1:8888/site1)
如果不想修改本地Hosts,可通过在服务器或本地配置反向代理实现路径式访问。
服务器端配置(以Nginx为例)
在服务器的默认Vhost配置(对应localhost或127.0.0.1的配置文件)中添加以下location块:
server { listen 80; server_name localhost 127.0.0.1; # 映射site1路径到对应Vhost location /site1/ { proxy_pass http://site1/; proxy_set_header Host site1; # 关键:传递正确的Host头给后端Vhost proxy_set_header X-Forwarded-For $remote_addr; } # 同理配置site2 location /site2/ { proxy_pass http://site2/; proxy_set_header Host site2; proxy_set_header X-Forwarded-For $remote_addr; } }
保存配置后重启Nginx:
sudo systemctl restart nginx
然后建立SSH隧道(和方案一相同),在本地浏览器访问http://127.0.0.1:8888/site1即可对应到服务器上的site1站点。
本地代理配置(可选,适合不想改服务器的情况)
如果不想动服务器配置,可在本地用Nginx/Caddy做反向代理:
以Nginx为例,本地配置文件添加:
server { listen 8888; server_name 127.0.0.1; location /site1/ { # 先建立SSH隧道:ssh -L 8899:127.0.0.1:80 your-ssh-user@your-lightsail-ip proxy_pass http://site1:8899/; proxy_set_header Host site1; } location /site2/ { proxy_pass http://site2:8899/; proxy_set_header Host site2; } }
同时本地Hosts仍需添加127.0.0.1 site1 site2,启动本地Nginx后,访问http://127.0.0.1:8888/site1即可。
内容的提问来源于stack exchange,提问作者Rohit

