Docker部署Node.js应用已忽略TLS仍遇自签名SSL证书503错误
问题:Node.js容器部署到SUSE15后调用API返回503错误
我正在开展一项POC测试,让Node.js容器调用另一IP的Web应用。该应用在本地开发环境运行正常,但部署到SUSE15后,API调用出现问题并返回503错误。
我使用的API调用代码:
const httpsAgent = new https.Agent({ rejectUnauthorized: false, }) axios.defaults.httpsAgent = httpsAgent; class ansibleService { public async findJobStatusById(jobId: number){ try{ let res = await axios.get(URL+'/api/v2/jobs/'+jobId ,{headers: {'Authorization': 'Basic '+basicAuth}}, {httpsAgent}); console.log("status code: ", res.status) console.log(res.data); return res.data }catch(err){ console.log(err) return err } } }
已做的尝试:
由于仅为POC测试,尝试忽略TLS证书验证,已在代码中添加rejectUnauthorized: false,并设置环境变量NODE_TLS_REJECT_UNAUTHORIZED=0,但应用仍返回503错误。
详细错误信息:
'</head><body id="ERR_SECURE_CONNECT_FAIL">\n' + '<div id="titles">\n' + '<h1>ERROR</h1>\n' + '<h2>The requested URL could not be retrieved</h2>\n' + '</div>\n' + '<hr>\n' + '\n' + '<div id="content">\n' + '<p>The following error was encountered while trying to retrieve the URL: <a href="https://10.194.113.123/api/v2/jobs/11507">https://10.194.113.123/api/v2/jobs/11507</a></p>\n' + '\n' + '<blockquote id="error">\n' + '<p><b>Failed to establish a secure connection to 10.194.113.123</b></p>\n' + '</blockquote>\n' + '\n' + '<div id="sysmsg">\n' + '<p>The system returned:</p>\n' + '<blockquote id="data">\n' + '<pre>(71) Protocol error (TLS code: X509_V_ERR_DEPTH_ZERO_SELF_SIGNED_CERT)</pre>\n' + '<p>Self-signed SSL Certificate: /CN=abc.corpdev.com</p>\n' + '</blockquote>\n' + '</div>\n' + '\n' + '<p>This proxy and the remote host failed to negotiate a mutually acceptable security settings for handling your request. It is possible that the remote host does not support secure connections, or the proxy is not satisfied with the host security credentials.</p>\n'
问题分析与解决建议
核心原因
错误信息显示503由代理服务器返回,并非目标API直接返回。核心问题是SUSE15环境中的代理服务器拦截了HTTPS请求,且不接受目标服务器的自签名证书——你在Node.js中关闭证书验证,但请求先经过代理,代理卡在了证书校验环节。
解决步骤
检查并清理代理配置
- 确认容器是否继承了SUSE15宿主机的
HTTP_PROXY/HTTPS_PROXY环境变量,这会导致请求走代理。 - 若无需代理,在Docker运行时清除代理变量,同时将目标IP加入
NO_PROXY:
或在Dockerfile中提前配置:docker run -e HTTP_PROXY="" -e HTTPS_PROXY="" -e NO_PROXY="10.194.113.123" your-node-imageENV HTTP_PROXY="" ENV HTTPS_PROXY="" ENV NO_PROXY="10.194.113.123"
- 确认容器是否继承了SUSE15宿主机的
修正Axios参数错误
你的Axios请求参数格式有误,httpsAgent被单独作为第三个参数传递,会被忽略。需合并到同一个配置对象中:let res = await axios.get(URL+'/api/v2/jobs/'+jobId, { headers: {'Authorization': 'Basic '+basicAuth}, httpsAgent: httpsAgent });若必须使用代理
- 将目标服务器的自签名证书导入到SUSE15宿主机的系统信任存储(参考SUSE证书管理文档)。
- 或配置代理服务器(如Squid)允许该自签名证书的请求,跳过证书校验。
内容的提问来源于stack exchange,提问作者Yuk_dev
相关产品推荐
相关产品推荐

