You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

单IP下配置Django+React前后端HTTPS及Nginx代理遇阻求助

解决子域名HTTPS配置问题(Let's Encrypt + Nginx + Docker)

第一步:确认DNS解析有效性

  • 执行命令nslookup api.my-table.it或dig api.my-table.it,检查子域名A记录是否指向DigitalOcean Droplet的公网IP
  • DNS修改后生效周期通常为10分钟至24小时,若刚修改需等待;可多次用本地命令验证解析状态
  • 若域名托管在GoDaddy,需直接在GoDaddy后台添加api子域名的A记录指向Droplet IP;若已将域名DNS服务器切换至DigitalOcean,则在DigitalOcean面板配置子域名A记录

第二步:修正Docker-Compose配置

当前配置缺少证书存储目录挂载,导致Nginx无法读取Let's Encrypt生成的证书,修改如下:

version: "3.9"

services:
  # ... db、redis、my_table、celery服务保持不变
  nginx: 
    build: ./nginx
    ports: 
      - 80:80
      - 443:443
    restart: always
    volumes:
      - ./nginx/conf/:/etc/nginx/conf.d/:ro
      - ./certbot/www:/var/www/certbot/:ro
      - ./certbot/conf:/etc/nginx/ssl/:ro  # 新增:挂载证书目录到Nginx
    depends_on:
      - my_table

  certbot:
    image: certbot/certbot:latest
    volumes:
      - ./certbot/www/:/var/www/certbot/:rw
      - ./certbot/conf:/etc/letsencrypt/:rw  # 新增:存储证书到本地目录

volumes:
  my_table_postgres_db:
  redis_data:

第三步:修复Nginx配置错误

  1. 补全80端口server块的缺失开头:
server {  # 补上之前缺失的server块声明
    listen 80;
    listen [::]:80;

    server_name api.my-table.it www.api.my-table.it;
    server_tokens off;

    location /.well-known/acme-challenge/ {
        root /var/www/certbot;
    }

    location / {
        return 301 https://api.my-table.it$request_uri;
    }
}
  1. 调整443端口的证书路径,并补充反向代理及基础SSL配置:
server {
    listen 443 ssl http2;
    listen [::]:443 ssl http2;

    server_name api.my-table.it;

    ssl_certificate /etc/nginx/ssl/live/api.my-table.it/fullchain.pem;
    ssl_certificate_key /etc/nginx/ssl/live/api.my-table.it/privkey.pem;
    
    # 推荐添加的基础SSL配置
    ssl_protocols TLSv1.2 TLSv1.3;
    ssl_ciphers HIGH:!aNULL:!MD5;
    
    location / {
        proxy_pass http://my_table:5000;
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;
    }
}

第四步:手动获取Let's Encrypt证书

DNS确认生效后,执行以下命令:

# 停止Nginx避免端口冲突
docker-compose stop nginx

# 用webroot模式申请证书
docker-compose run --rm certbot certonly --webroot -w /var/www/certbot -d api.my-table.it -d www.api.my-table.it

# 重启所有服务
docker-compose up -d

第五步:验证配置与证书

  • 检查Nginx配置合法性:docker-compose exec nginx nginx -t
  • 访问https://api.my-table.it,确认浏览器显示安全连接
  • 查看证书状态:docker-compose exec certbot certbot certificates

常见排查点

  • 确认Droplet防火墙已开放80、443端口
  • 若certbot提示连接失败,优先检查DNS解析是否完成、端口是否可访问
  • Nginx启动失败时,查看日志定位问题:docker-compose logs nginx

内容的提问来源于stack exchange,提问作者Matteo Possamai

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.30 07:57:04