通过AWS ELB访问Tomcat中REST应用报403,请求未达应用层求助
Hey there, let's dig into this tricky issue you're facing. You've got two apps running on Tomcat in a Docker container on EC2—static Angular content works fine via ELB, but your REST app is throwing 403s, even though Tomcat's access logs show the request came in (but your app logs/filters don't see it). Here's what could be going on, and how to troubleshoot it:
Possible Root Causes
- ELB Security/Network Restrictions: Your ELB's security group or VPC Network ACL might only allow
GETrequests (for static content) but block other HTTP methods likePOST,PUT, orDELETEthat your REST app uses. This would trigger a 403 before the request even reaches your app code. - Tomcat RemoteIpValve Misconfiguration: If you're using an Application Load Balancer (ALB), it forwards client IPs via
X-Forwarded-*headers. If Tomcat'sRemoteIpValveisn't set up correctly, your REST app's security rules (like IP whitelisting) might be seeing the ELB's internal IP instead of the real client IP—and rejecting it. Since you access EC2 directly, you bypass this and hit the allowed IP range. - Tomcat-Level Security Constraints: Your REST app's
web.xmlmight have<security-constraint>rules that restrict access to certain paths/IPs. Tomcat would intercept the request before it reaches your app's filters or logs, hence the 403 with no app-side trace. - ELB Listener/Target Group Issues: Your ALB's listener rules might be misrouting REST requests (e.g., sending them to the wrong target group) or have attached WAF rules that block REST traffic. Static content paths might be correctly mapped, so they work.
- Docker/Tomcat Binding Glitch: While less likely (since direct EC2 access works), double-check that Tomcat's connector in
server.xmlisn't bound only tolocalhostor the EC2 internal IP—though this should break both apps, not just REST.
Troubleshooting Recommendations
- Audit ELB Security Groups & Network ACLs:
- Confirm your ELB's security group allows all required HTTP methods (GET, POST, PUT, DELETE) to port 8080 on your EC2 instances.
- Check VPC Network ACLs to ensure inbound/outbound traffic between ELB and EC2 is allowed for all necessary methods and ports.
- Fix Tomcat's RemoteIpValve:
- Open your custom
server.xmland verify theRemoteIpValveis configured to recognize ALB's forwarded headers. Add or adjust it like this:<Valve className="org.apache.catalina.valves.RemoteIpValve" remoteIpHeader="X-Forwarded-For" protocolHeader="X-Forwarded-Proto" internalProxies="10\.\d+\.\d+\.\d+|192\.168\.\d+\.\d+|172\.1[6-9]\.\d+\.\d+|172\.2[0-9]\.\d+\.\d+|172\.3[0-1]\.\d+\.\d+" /> - Make sure
internalProxiesincludes your ELB's internal IP range so Tomcat trusts it as a proxy.
- Open your custom
- Check REST App's web.xml Security Rules:
- Look for
<security-constraint>or<ip-address>restrictions in your REST app'sweb.xml. If there's an IP whitelist, add your ELB's internal IP (or temporarily use0.0.0.0/0for testing) to see if the 403 goes away.
- Look for
- Validate ELB Listener & Target Group Setup:
- Confirm ALB listener rules correctly route paths like
/voteride-ws/*to your EC2 target group. - Check if WAF rules are attached to the ELB—temporarily disable them to rule out accidental blocking.
- Verify your target group uses port 8080 and has healthy EC2 instances.
- Confirm ALB listener rules correctly route paths like
- Enable Tomcat Security Debug Logs:
- Update your
logging.propertiesto enable debug logs for Tomcat's security layer:org.apache.catalina.security.level = FINE org.apache.catalina.security.handlers = java.util.logging.ConsoleHandler - This will log exactly why Tomcat is rejecting the request (e.g., security constraint violation, IP block).
- Update your
- Test from EC2 & ELB Internal IP:
- SSH into your EC2 instance and run
curl http://localhost:8080/voteride-ws/your-endpointto confirm the REST app works locally. - Then use the ELB's internal IP to test the same endpoint—if it returns 403, the issue is definitely related to proxy/IP handling.
- SSH into your EC2 instance and run
Your Dockerfile for Reference
FROM tomcat:8.0 LABEL maintainer="rossmillsiphone@gmail.com" ADD voteride-web.war /usr/local/tomcat/webapps/ ADD voteride-ws.war /usr/local/tomcat/webapps/ ADD mysql-connector-java-5.1.9.jar /usr/local/tomcat/lib/ ADD server.xml /usr/local/tomcat/conf/ ADD context.xml /usr/local/tomcat/conf/ ADD email.properties /usr/local/tomcat/lib/ ADD logging.properties /usr/local/tomcat/conf EXPOSE 8080 CMD ["catalina.sh", "run"]
内容的提问来源于stack exchange,提问作者Ross H Mills III
相关产品推荐
相关产品推荐

