You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Harbor通过Nginx反向代理部分URI出现404错误求助

Harbor反向代理后部分URI 404问题解决

Harbor版本

2.6.2

问题描述

Harbor部署在VMware机器上,直接访问http://192.168.195.160:8092可正常访问,但通过Nginx将http://192.168.195.160:9002/harbor作为反向代理后,部分URI出现404未找到错误。

现有配置

harbor.yml配置

http:
  # port for http, default is 80. If https enabled, this port will redirect to https port
  port: 8092

# https related config
https:
  # https port for harbor, default is 443
  # port: 443
  # The path of cert and key files for nginx
  #certificate: /your/certificate/path
  #private_key: /your/private/key/path

external_url: http://192.168.195.160:9002/harbor


harbor_admin_password: *******

# Harbor DB configuration
database:
  # The password for the root user of Harbor DB. Change this before any production use.
  password: home
  # The maximum number of connections in the idle connection pool. If it <=0, no idle connections are retained.
  max_idle_conns: 100
  # The maximum number of open connections to the database. If it <= 0, then there is no limit on the number of open connections.
  # Note: the default number of connections is 1024 for postgres of harbor.
  max_open_conns: 900

# The default data volume
data_volume: /data


trivy:
  # ignoreUnfixed The flag to display only fixed vulnerabilities
  ignore_unfixed: false
  # skipUpdate The flag to enable or disable Trivy DB downloads from GitHub
  #
  # You might want to enable this flag in test or CI/CD environments to avoid GitHub rate limiting issues.
  # If the flag is enabled you have to download the `trivy-offline.tar.gz` archive manually, extract `trivy.db` and
  # `metadata.json` files and mount them in the `/home/scanner/.cache/trivy/db` path.
  skip_update: false

  offline_scan: false
  #
  # Comma-separated list of what security issues to detect. Possible values are `vuln`, `config` and `secret`. Defaults to `vuln`.
  security_check: vuln
  #
  # insecure The flag to skip verifying registry certificate
  insecure: false


jobservice:
  # Maximum number of job workers in job service
  max_job_workers: 10

notification:
  # Maximum retry count for webhook job
  webhook_job_max_retry: 10

chart:
  # Change the value of absolute_url to enabled can enable absolute url in chart
  absolute_url: disabled

# Log configurations
log:
  # options are debug, info, warning, error, fatal
  level: info
  # configs for logs in local storage
  local:
    # Log files are rotated log_rotate_count times before being removed. If count is 0, old versions are removed rather than rotated.
    rotate_count: 50
    # Log files are rotated only if they grow bigger than log_rotate_size bytes. If size is followed by k, the size is assumed to be in kilobytes.
    # If the M is used, the size is in megabytes, and if G is used, the size is in gigabytes. So size 100, size 100k, size 100M and size 100G
    # are all valid.
    rotate_size: 200M
    # The directory on your host that store log
    location: /var/log/harbor


_version: 2.6.0


proxy:
  http_proxy:
  https_proxy:
  no_proxy:
  components:
    - core
    - jobservice
    - trivy



# enable purge _upload directories
upload_purging:
  enabled: true
  # remove files in _upload directories which exist for a period of time, default is one week.
  age: 168h
  # the interval of the purge operations
  interval: 24h
  dryrun: false


cache:
  # not enabled by default
  enabled: false
  # keep cache for one day by default
  expire_hours: 24

Nginx配置(原配置)

http {
    include       mime.types;
    default_type  application/octet-stream;

    #log_format  main  '$remote_addr - $remote_user [$time_local] "$request" '
    #                  '$status $body_bytes_sent "$http_referer" '
    #                  '"$http_user_agent" "$http_x_forwarded_for"';

    #access_log  logs/access.log  main;

    sendfile        on;
    #tcp_nopush     on;

    keepalive_timeout  65;


    server {
        listen       9002;
        server_name  192.168.195.160;

        #charset koi8-r;

        #access_log  logs/host.access.log  main;
        
        location /harbor {
          proxy_pass http://192.168.195.160:8092;
          proxy_set_header  Host              $http_host;
          proxy_set_header  X-Real-IP         $remote_addr;
          proxy_set_header  X-Forwarded-For   $proxy_add_x_forwarded_for;
          proxy_set_header  X-Forwarded-Proto $scheme;

          proxy_buffering off;
          proxy_request_buffering off;
        }

        #location / {
        #    root   html;
        #    index  index.html index.htm;
        #}

        error_page   500 502 503 504  /50x.html;
        location = /50x.html {
            root   html;
        }

    }
}

解决步骤

1. 修正Nginx反向代理配置

问题核心在于Nginx没有正确处理/harbor前缀的转发,Harbor内部路径基于根路径/,需要将/harbor/xxx转发为/xxx。修改后的Nginx配置如下:

http {
    include       mime.types;
    default_type  application/octet-stream;

    sendfile        on;
    keepalive_timeout  65;

    server {
        listen       9002;
        server_name  192.168.195.160;
        
        # 处理带末尾斜杠的请求,转发时去掉/harbor前缀
        location /harbor/ {
          proxy_pass http://192.168.195.160:8092/;
          proxy_set_header Host $http_host;
          proxy_set_header X-Real-IP $remote_addr;
          proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
          proxy_set_header X-Forwarded-Proto $scheme;

          proxy_buffering off;
          proxy_request_buffering off;
        }

        # 处理不带末尾斜杠的请求,重定向到带斜杠的路径,避免路径匹配问题
        location = /harbor {
          return 302 /harbor/;
        }

        error_page   500 502 503 504  /50x.html;
        location = /50x.html {
            root   html;
        }
    }
}

修改后重启Nginx服务:

nginx -s reload

2. 确认Harbor配置并重启服务

你的harbor.yml中external_url配置已经正确设置为http://192.168.195.160:9002/harbor,但需要重新生成Harbor配置并重启服务,确保前端资源和API路径基于该外部URL生成:

# 进入Harbor安装目录
cd /path/to/harbor
# 重新生成配置
./prepare
# 重启Harbor服务
docker-compose down -v
docker-compose up -d

原理说明

  • Nginx的proxy_pass末尾添加斜杠后,会将location匹配的路径前缀(/harbor/)去掉,再转发到后端Harbor,确保Harbor收到的是根路径开头的请求。
  • external_url配置决定了Harbor前端页面生成的资源路径和API请求路径,必须与反向代理的外部访问路径一致,否则前端会请求错误的路径导致404。

内容的提问来源于stack exchange,提问作者Jimmy He

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.08 16:55:17