Oracle OCI中Oracle Linux 8.6 VM的Flask应用外网无法访问求助
问题:Oracle Cloud上Flask应用无法通过公网IP访问
我正尝试在Oracle Cloud的Oracle Linux 8.6计算VM上创建可从互联网访问的Python Flask应用。操作步骤参考基于Ubuntu的教程,仅将原教程中的iptables规则:
sudo iptables -I INPUT 6 -m state --state NEW -p tcp --dport 5000 -j ACCEPT sudo netfilter-persistent save
替换为:
sudo firewall-cmd --permanent --zone=public --add-service=http sudo firewall-cmd --reload
其余流程保持一致。示例应用代码如下:
from flask import Flask app = Flask(__name__) @app.route('/') def hello_world(): return 'Hello, World!' if __name__ == "__main__": app.run(host="0.0.0.0", port=int("5000"), debug=True)
该应用通过curl测试私有IP(http://10.0.0.184:5000/)可正常访问,运行日志如下:
* Serving Flask app 'hi' (lazy loading) * Environment: production WARNING: This is a development server. Do not use it in a production deployment. Use a production WSGI server instead. * Debug mode: on * Running on all addresses. WARNING: This is a development server. Do not use it in a production deployment. * Running on http://10.0.0.184:5000/ (Press CTRL+C to quit) * Restarting with stat * Debugger is active! * Debugger PIN: 995-235-083 127.0.0.1 - - [22/Mar/2023 11:58:24] "GET / HTTP/1.1" 200 -
但无法通过互联网访问http://public-IP-of-my-instance:5000。该实例已成功部署Apache web服务器,请问我哪里操作有误?
可能的问题及解决方法
防火墙规则未开放5000端口
你添加的http服务默认对应80端口,但Flask应用跑在5000端口上,当前防火墙规则并未放行该端口的TCP流量。执行以下命令修正:sudo firewall-cmd --permanent --zone=public --add-port=5000/tcp sudo firewall-cmd --reload执行后用
sudo firewall-cmd --list-ports确认5000/tcp已在开放端口列表中。Oracle Cloud安全组未放行5000端口
即使VM本地防火墙放行,Oracle Cloud的虚拟云网络(VCN)安全组也可能阻断了公网到5000端口的流量——Apache能正常访问说明安全组开放了80端口,但5000端口未配置。
操作步骤:- 登录Oracle Cloud控制台,找到目标计算实例
- 进入实例详情页,点击“虚拟云网络”区域对应的安全组
- 在安全组的“入站规则”中添加一条规则:
- 源:
0.0.0.0/0(允许所有公网IP访问) - 协议:TCP
- 端口范围:5000
- 源:
- 保存规则
确认Flask监听范围正确
虽然代码中指定了host="0.0.0.0",但仍需验证进程是否真的监听所有网卡。执行命令:ss -tulpn | grep 5000正常输出应包含
0.0.0.0:5000,类似:tcp LISTEN 0 50 0.0.0.0:5000 0.0.0.0:* users:(("python",pid=xxxx,fd=xx))
内容的提问来源于stack exchange,提问作者Josef Švenda
相关产品推荐
相关产品推荐

