You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Nginx+Authelia IP过滤配置报错:auth_request指令不允许在此处使用

Nginx结合Authelia实现IP过滤认证的报错解决与配置迁移

问题与报错

配置Nginx结合Authelia实现IP过滤认证时,原本计划通过判断远程IP加载authelia-authrequest.conf执行认证,但启动Nginx时触发报错:

nginx: [emerg] "auth_request" directive is not allowed here in /etc/nginx/conf/auth/authelia/authelia-authrequest.conf:2

报错原因

auth_request是Nginx的location上下文专属指令,不能在if块内部使用。原配置中在location /的if ($is_allowed = 0)块里include包含auth_request的配置文件,违反了Nginx的指令上下文规则,导致启动失败。

修改后的主配置(方案一:location内部分支处理)

将authelia-authrequest.conf的内容直接整合到主配置中,调整逻辑避免if块嵌套使用location级指令:

####BABBYBUDDY####
map $remote_addr $is_allowed {
    192.168.1.120 1;
    default 0;
}

include /etc/nginx/conf/user-agent/user-agent-babby.domain.tld.conf;

server {
    listen 80;
    listen 443 ssl http2;
    server_name babby.domain.tld;

    if ($scheme != "https") {
        rewrite ^ https://$host$uri permanent;
    }

    include /etc/nginx/conf/ssl/ssl.conf;
    include /etc/nginx/conf/ssl/domain/cert.domain.tld.conf;
    include /etc/nginx/conf/error-page/error-page.conf;
    charset utf-8;

    include /etc/nginx/conf/auth/authelia/authelia-location.conf;

    # 拦截不合法User-Agent请求
    if ($user_agent = 0) { return 403; }

    location / {
        # 允许的IP直接代理到后端,跳过认证
        if ($is_allowed = 1) {
            proxy_pass http://babybuddy:8000;
            proxy_set_header X-Forwarded-Host $host;
            proxy_set_header X-Forwarded-Server $host;
            proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
            proxy_set_header X-Forwarded-Proto $scheme;
            proxy_set_header X-Real-IP $remote_addr;
            proxy_set_header Host $host;
            break;
        }

        # 非允许IP执行Authelia认证
        auth_request /authelia;
        auth_request_set $target_url $scheme://$http_host$request_uri;
        auth_request_set $user $upstream_http_remote_user;
        auth_request_set $groups $upstream_http_remote_groups;
        auth_request_set $name $upstream_http_remote_name;
        auth_request_set $email $upstream_http_remote_email;

        proxy_set_header Remote-User $user;
        proxy_set_header Remote-Groups $groups;
        proxy_set_header Remote-Name $name;
        proxy_set_header Remote-Email $email;

        error_page 401 =302 https://auth.domain.tld/?rd=$target_url;

        # 认证通过后代理到后端
        proxy_pass http://babybuddy:8000;
        proxy_set_header X-Forwarded-Host $host;
        proxy_set_header X-Forwarded-Server $host;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header Host $host;
    }
}

修改后的主配置(方案二:命名location分发,更符合Nginx规范)

利用map变量将请求分发到不同的命名location,彻底避免if块嵌套问题:

####BABBYBUDDY####
map $remote_addr $is_allowed {
    192.168.1.120 1;
    default 0;
}

# 根据是否允许IP,定义分发目标的后缀
map $is_allowed $auth_suffix {
    1 "";
    default "auth";
}

include /etc/nginx/conf/user-agent/user-agent-babby.domain.tld.conf;

server {
    listen 80;
    listen 443 ssl http2;
    server_name babby.domain.tld;

    if ($scheme != "https") {
        rewrite ^ https://$host$uri permanent;
    }

    include /etc/nginx/conf/ssl/ssl.conf;
    include /etc/nginx/conf/ssl/domain/cert.domain.tld.conf;
    include /etc/nginx/conf/error-page/error-page.conf;
    charset utf-8;

    include /etc/nginx/conf/auth/authelia/authelia-location.conf;

    # 拦截不合法User-Agent请求
    if ($user_agent = 0) { return 403; }

    # 主入口,根据变量分发请求
    location / {
        try_files $uri $uri/ @backend${auth_suffix};
    }

    # 允许IP直接代理的后端
    location @backend {
        proxy_pass http://babybuddy:8000;
        proxy_set_header X-Forwarded-Host $host;
        proxy_set_header X-Forwarded-Server $host;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header Host $host;
    }

    # 需要Authelia认证的后端
    location @backendauth {
        auth_request /authelia;
        auth_request_set $target_url $scheme://$http_host$request_uri;
        auth_request_set $user $upstream_http_remote_user;
        auth_request_set $groups $upstream_http_remote_groups;
        auth_request_set $name $upstream_http_remote_name;
        auth_request_set $email $upstream_http_remote_email;

        proxy_set_header Remote-User $user;
        proxy_set_header Remote-Groups $groups;
        proxy_set_header Remote-Name $name;
        proxy_set_header Remote-Email $email;

        error_page 401 =302 https://auth.domain.tld/?rd=$target_url;

        proxy_pass http://babybuddy:8000;
        proxy_set_header X-Forwarded-Host $host;
        proxy_set_header X-Forwarded-Server $host;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header Host $host;
    }
}

说明

两种方案都实现了:

  • 允许的IP(192.168.1.120)直接访问后端服务,无需认证
  • 其他IP需经过Authelia认证后才能访问
  • 拦截不合法User-Agent的请求

方案二更符合Nginx的配置最佳实践,避免了location内部if块的潜在问题。

内容的提问来源于stack exchange,提问作者focheur91300

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.01 01:55:35