You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Ubuntu18.04下Nginx反向SSL代理配置异常求助

Troubleshooting & Fixes for Nginx SSL Reverse Proxy Issues

Hey there, let's walk through fixing your two main problems: HTTP requests landing on the Nginx default page instead of redirecting to HTTPS, and HTTPS returning a 404 error. The root causes are mostly mismatched domain configurations and leftover default Nginx settings. Here's how to fix it:

1. Fix Server Name Mismatch

Looking at your web_service.conf, the server_name is set to www.web.server.com web.server.com—but you're trying to access web.service.com. This means Nginx can't match your request to your custom server block, so it falls back to the default one.

Update the server_name lines in your web_service.conf to match your actual domain:

# HTTP redirect server block
server {
    listen 80;
    server_name web.service.com; # Match your actual domain here
    return 301 https://$host$request_uri;
}

# HTTPS server block
server {
    listen 443 ssl;
    server_name web.service.com; # Replace with your real domain
    ssl_session_cache builtin:1000 shared:SSL:10m;
    # Keep your existing SSL ciphers, protocols, certificate paths...
    location / {
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;
        proxy_pass http://webservice:8080;
        proxy_read_timeout 90;
        proxy_redirect http://webservice:8080 https://web.service.com;
    }
}

Pro tip: If you need to support the www prefix, add www.web.service.com to the server_name list (e.g., server_name web.service.com www.web.service.com;).

2. Remove Default Nginx Configuration

The official Nginx image comes with a default.conf in /etc/nginx/conf.d/ that defines a default server block for port 80. This is why your HTTP requests are landing on the welcome page—when Nginx can't match your request to your custom server block, it uses this default one.

Modify your Nginx Dockerfile to delete this default config when building the image:

FROM nginx:latest
# Copy your custom config into the container
COPY web_service.conf /etc/nginx/conf.d/
# Delete the default config to prevent conflicts
RUN rm /etc/nginx/conf.d/default.conf

3. Verify Docker Network Connectivity

Since all your services are in the default Docker Compose bridge network, the nginx container should be able to reach webservice:8080, but let's confirm:

  1. Shell into the Nginx container: docker exec -it nginx bash
  2. Test the connection to your web service: curl http://webservice:8080
    If you get a valid response, the network is working. If not, double-check that your web_service container is running correctly (use docker-compose logs web_service to check logs).

4. Rebuild & Test

After making these changes, rebuild your Nginx image and restart the services:

docker-compose down
docker-compose build nginx
docker-compose up -d

Now test again:

  • Visiting http://web.service.com should automatically redirect to HTTPS
  • Visiting https://web.service.com should load your web service's content correctly

Bonus: Improve SSL Security

Your current ssl_protocols uses outdated versions (SSLv3, TLSv1) which are insecure. Update them to modern, secure protocols:

ssl_protocols TLSv1.2 TLSv1.3;

You should also update your ssl_ciphers to a modern, secure set—for example:

ssl_ciphers ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384;

内容的提问来源于stack exchange,提问作者Lawrence Colombo

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.06 08:37:36