You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

EKS集群中NiFi API调用出现混合内容错误的求助

混合内容错误问题解决指南

问题根源

浏览器通过HTTPS访问NiFi UI,但NiFi返回的页面中部分API调用使用了内部HTTP/HTTPS地址(如localhost:8443),与外部HTTPS协议冲突,触发浏览器的混合内容安全限制。核心原因是NiFi未识别到自身处于反向代理(ELB+Nginx Ingress)之后,生成的API链接不符合外部访问的协议和域名。

解决方案

推荐通过配置NiFi代理环境变量从根源解决,同时调整K8s资源适配外部访问逻辑:

1. 更新NiFi Deployment配置

修改Deployment的env段,添加代理相关配置,让NiFi知晓外部访问地址:

apiVersion: apps/v1
kind: Deployment
metadata:
  name: nifi
  namespace: default
spec:
  selector:
    matchLabels:
      app: nifi
  template:
    metadata:
      labels:
        app: nifi
    spec:
      containers:
      - name: nifi
        image: apache/nifi:1.14.0
        resources:
          limits:
            memory: "1Gi"
            cpu: "500m"
        ports:
        - containerPort: 8080  # 改用HTTP端口,避免内部SSL证书问题
        env:
          - name: SINGLE_USER_CREDENTIALS_USERNAME
            value: "admin"
          - name: SINGLE_USER_CREDENTIALS_PASSWORD
            value: "XXXXX"
          # 配置外部代理信息,让NiFi生成正确的HTTPS API链接
          - name: NIFI_WEB_PROXY_HOST
            value: "nifi.example.com"
          - name: NIFI_WEB_PROXY_PORT
            value: "443"
          - name: NIFI_WEB_HTTP_HOST
            value: "0.0.0.0"
          - name: NIFI_WEB_HTTP_PORT
            value: "8080"
          # 关闭NiFi内部HTTPS服务
          - name: NIFI_WEB_HTTPS_PORT
            value: ""

2. 更新Service配置

调整Service端口适配NiFi的HTTP端口:

apiVersion: v1
kind: Service
metadata:
  name: nifi-svc
  namespace: default
spec:
  selector:
    app: nifi
  ports:
  - port: 8080
    targetPort: 8080

3. 更新Ingress配置

移除不必要的HTTPS后端注解,添加强制HTTPS跳转:

apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  name: nifi-ingress-resource
  annotations:
    kubernetes.io/ingress.class: "nginx"
    nginx.ingress.kubernetes.io/force-ssl-redirect: "true"  # 强制所有请求走HTTPS
spec:
  ingressClassName: nginx
  tls:
  - hosts:
    - nifi.example.com
    # 若使用ELB托管SSL,可省略secretName;否则需配置对应TLS证书secret
    # secretName: nifi-tls-secret
  rules:
  - host: nifi.example.com
    http:
      paths:
      - path: "/"
        pathType: Prefix
        backend:
          service:
            name: nifi-svc
            port:
              number: 8080

4. 应用配置并验证

执行命令更新资源:

kubectl apply -f <updated-deployment.yaml>
kubectl apply -f <updated-service.yaml>
kubectl apply -f <updated-ingress.yaml>

等待Pod重启后,访问https://nifi.example.com测试之前报错的UI操作,确认混合内容错误消失。

备选方案:仅通过Ingress重写响应内容

若不愿修改NiFi配置,可通过Nginx Ingress的内容替换功能强制修正API链接:

# 在Ingress的annotations中添加以下配置
annotations:
  nginx.ingress.kubernetes.io/backend-protocol: "HTTPS"
  nginx.ingress.kubernetes.io/proxy-set-header: "X-Forwarded-Proto https"
  nginx.ingress.kubernetes.io/proxy-set-header: "X-Forwarded-Host nifi.example.com"
  nginx.ingress.kubernetes.io/sub-filter: 's|https://localhost:8443|https://nifi.example.com|g'
  nginx.ingress.kubernetes.io/sub-filter-last-modified: "true"

注意:此方式仅能替换静态响应内容,若NiFi通过JS动态生成API链接,可能无法完全覆盖,稳定性不如配置NiFi代理变量。

内容的提问来源于stack exchange,提问作者RVP

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.06 22:01:01