Nginx+Authelia IP过滤配置报错:auth_request指令不允许在此处使用
Nginx结合Authelia实现IP过滤认证的报错解决与配置迁移
问题与报错
配置Nginx结合Authelia实现IP过滤认证时,原本计划通过判断远程IP加载authelia-authrequest.conf执行认证,但启动Nginx时触发报错:
nginx: [emerg] "auth_request" directive is not allowed here in /etc/nginx/conf/auth/authelia/authelia-authrequest.conf:2
报错原因
auth_request是Nginx的location上下文专属指令,不能在if块内部使用。原配置中在location /的if ($is_allowed = 0)块里include包含auth_request的配置文件,违反了Nginx的指令上下文规则,导致启动失败。
修改后的主配置(方案一:location内部分支处理)
将authelia-authrequest.conf的内容直接整合到主配置中,调整逻辑避免if块嵌套使用location级指令:
####BABBYBUDDY#### map $remote_addr $is_allowed { 192.168.1.120 1; default 0; } include /etc/nginx/conf/user-agent/user-agent-babby.domain.tld.conf; server { listen 80; listen 443 ssl http2; server_name babby.domain.tld; if ($scheme != "https") { rewrite ^ https://$host$uri permanent; } include /etc/nginx/conf/ssl/ssl.conf; include /etc/nginx/conf/ssl/domain/cert.domain.tld.conf; include /etc/nginx/conf/error-page/error-page.conf; charset utf-8; include /etc/nginx/conf/auth/authelia/authelia-location.conf; # 拦截不合法User-Agent请求 if ($user_agent = 0) { return 403; } location / { # 允许的IP直接代理到后端,跳过认证 if ($is_allowed = 1) { proxy_pass http://babybuddy:8000; proxy_set_header X-Forwarded-Host $host; proxy_set_header X-Forwarded-Server $host; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; proxy_set_header X-Real-IP $remote_addr; proxy_set_header Host $host; break; } # 非允许IP执行Authelia认证 auth_request /authelia; auth_request_set $target_url $scheme://$http_host$request_uri; auth_request_set $user $upstream_http_remote_user; auth_request_set $groups $upstream_http_remote_groups; auth_request_set $name $upstream_http_remote_name; auth_request_set $email $upstream_http_remote_email; proxy_set_header Remote-User $user; proxy_set_header Remote-Groups $groups; proxy_set_header Remote-Name $name; proxy_set_header Remote-Email $email; error_page 401 =302 https://auth.domain.tld/?rd=$target_url; # 认证通过后代理到后端 proxy_pass http://babybuddy:8000; proxy_set_header X-Forwarded-Host $host; proxy_set_header X-Forwarded-Server $host; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; proxy_set_header X-Real-IP $remote_addr; proxy_set_header Host $host; } }
修改后的主配置(方案二:命名location分发,更符合Nginx规范)
利用map变量将请求分发到不同的命名location,彻底避免if块嵌套问题:
####BABBYBUDDY#### map $remote_addr $is_allowed { 192.168.1.120 1; default 0; } # 根据是否允许IP,定义分发目标的后缀 map $is_allowed $auth_suffix { 1 ""; default "auth"; } include /etc/nginx/conf/user-agent/user-agent-babby.domain.tld.conf; server { listen 80; listen 443 ssl http2; server_name babby.domain.tld; if ($scheme != "https") { rewrite ^ https://$host$uri permanent; } include /etc/nginx/conf/ssl/ssl.conf; include /etc/nginx/conf/ssl/domain/cert.domain.tld.conf; include /etc/nginx/conf/error-page/error-page.conf; charset utf-8; include /etc/nginx/conf/auth/authelia/authelia-location.conf; # 拦截不合法User-Agent请求 if ($user_agent = 0) { return 403; } # 主入口,根据变量分发请求 location / { try_files $uri $uri/ @backend${auth_suffix}; } # 允许IP直接代理的后端 location @backend { proxy_pass http://babybuddy:8000; proxy_set_header X-Forwarded-Host $host; proxy_set_header X-Forwarded-Server $host; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; proxy_set_header X-Real-IP $remote_addr; proxy_set_header Host $host; } # 需要Authelia认证的后端 location @backendauth { auth_request /authelia; auth_request_set $target_url $scheme://$http_host$request_uri; auth_request_set $user $upstream_http_remote_user; auth_request_set $groups $upstream_http_remote_groups; auth_request_set $name $upstream_http_remote_name; auth_request_set $email $upstream_http_remote_email; proxy_set_header Remote-User $user; proxy_set_header Remote-Groups $groups; proxy_set_header Remote-Name $name; proxy_set_header Remote-Email $email; error_page 401 =302 https://auth.domain.tld/?rd=$target_url; proxy_pass http://babybuddy:8000; proxy_set_header X-Forwarded-Host $host; proxy_set_header X-Forwarded-Server $host; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; proxy_set_header X-Real-IP $remote_addr; proxy_set_header Host $host; } }
说明
两种方案都实现了:
- 允许的IP(192.168.1.120)直接访问后端服务,无需认证
- 其他IP需经过Authelia认证后才能访问
- 拦截不合法User-Agent的请求
方案二更符合Nginx的配置最佳实践,避免了location内部if块的潜在问题。
内容的提问来源于stack exchange,提问作者focheur91300
相关产品推荐
相关产品推荐

