Ubuntu18.04下Nginx反向SSL代理配置异常求助
Hey there, let's walk through fixing your two main problems: HTTP requests landing on the Nginx default page instead of redirecting to HTTPS, and HTTPS returning a 404 error. The root causes are mostly mismatched domain configurations and leftover default Nginx settings. Here's how to fix it:
1. Fix Server Name Mismatch
Looking at your web_service.conf, the server_name is set to www.web.server.com web.server.com—but you're trying to access web.service.com. This means Nginx can't match your request to your custom server block, so it falls back to the default one.
Update the server_name lines in your web_service.conf to match your actual domain:
# HTTP redirect server block server { listen 80; server_name web.service.com; # Match your actual domain here return 301 https://$host$request_uri; } # HTTPS server block server { listen 443 ssl; server_name web.service.com; # Replace with your real domain ssl_session_cache builtin:1000 shared:SSL:10m; # Keep your existing SSL ciphers, protocols, certificate paths... location / { proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; proxy_pass http://webservice:8080; proxy_read_timeout 90; proxy_redirect http://webservice:8080 https://web.service.com; } }
Pro tip: If you need to support the
wwwprefix, addwww.web.service.comto theserver_namelist (e.g.,server_name web.service.com www.web.service.com;).
2. Remove Default Nginx Configuration
The official Nginx image comes with a default.conf in /etc/nginx/conf.d/ that defines a default server block for port 80. This is why your HTTP requests are landing on the welcome page—when Nginx can't match your request to your custom server block, it uses this default one.
Modify your Nginx Dockerfile to delete this default config when building the image:
FROM nginx:latest # Copy your custom config into the container COPY web_service.conf /etc/nginx/conf.d/ # Delete the default config to prevent conflicts RUN rm /etc/nginx/conf.d/default.conf
3. Verify Docker Network Connectivity
Since all your services are in the default Docker Compose bridge network, the nginx container should be able to reach webservice:8080, but let's confirm:
- Shell into the Nginx container:
docker exec -it nginx bash - Test the connection to your web service:
curl http://webservice:8080
If you get a valid response, the network is working. If not, double-check that yourweb_servicecontainer is running correctly (usedocker-compose logs web_serviceto check logs).
4. Rebuild & Test
After making these changes, rebuild your Nginx image and restart the services:
docker-compose down docker-compose build nginx docker-compose up -d
Now test again:
- Visiting
http://web.service.comshould automatically redirect to HTTPS - Visiting
https://web.service.comshould load your web service's content correctly
Bonus: Improve SSL Security
Your current ssl_protocols uses outdated versions (SSLv3, TLSv1) which are insecure. Update them to modern, secure protocols:
ssl_protocols TLSv1.2 TLSv1.3;
You should also update your ssl_ciphers to a modern, secure set—for example:
ssl_ciphers ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384;
内容的提问来源于stack exchange,提问作者Lawrence Colombo

