Harbor通过Nginx反向代理部分URI出现404错误求助
Harbor反向代理后部分URI 404问题解决
Harbor版本
2.6.2
问题描述
Harbor部署在VMware机器上,直接访问http://192.168.195.160:8092可正常访问,但通过Nginx将http://192.168.195.160:9002/harbor作为反向代理后,部分URI出现404未找到错误。
现有配置
harbor.yml配置
http: # port for http, default is 80. If https enabled, this port will redirect to https port port: 8092 # https related config https: # https port for harbor, default is 443 # port: 443 # The path of cert and key files for nginx #certificate: /your/certificate/path #private_key: /your/private/key/path external_url: http://192.168.195.160:9002/harbor harbor_admin_password: ******* # Harbor DB configuration database: # The password for the root user of Harbor DB. Change this before any production use. password: home # The maximum number of connections in the idle connection pool. If it <=0, no idle connections are retained. max_idle_conns: 100 # The maximum number of open connections to the database. If it <= 0, then there is no limit on the number of open connections. # Note: the default number of connections is 1024 for postgres of harbor. max_open_conns: 900 # The default data volume data_volume: /data trivy: # ignoreUnfixed The flag to display only fixed vulnerabilities ignore_unfixed: false # skipUpdate The flag to enable or disable Trivy DB downloads from GitHub # # You might want to enable this flag in test or CI/CD environments to avoid GitHub rate limiting issues. # If the flag is enabled you have to download the `trivy-offline.tar.gz` archive manually, extract `trivy.db` and # `metadata.json` files and mount them in the `/home/scanner/.cache/trivy/db` path. skip_update: false offline_scan: false # # Comma-separated list of what security issues to detect. Possible values are `vuln`, `config` and `secret`. Defaults to `vuln`. security_check: vuln # # insecure The flag to skip verifying registry certificate insecure: false jobservice: # Maximum number of job workers in job service max_job_workers: 10 notification: # Maximum retry count for webhook job webhook_job_max_retry: 10 chart: # Change the value of absolute_url to enabled can enable absolute url in chart absolute_url: disabled # Log configurations log: # options are debug, info, warning, error, fatal level: info # configs for logs in local storage local: # Log files are rotated log_rotate_count times before being removed. If count is 0, old versions are removed rather than rotated. rotate_count: 50 # Log files are rotated only if they grow bigger than log_rotate_size bytes. If size is followed by k, the size is assumed to be in kilobytes. # If the M is used, the size is in megabytes, and if G is used, the size is in gigabytes. So size 100, size 100k, size 100M and size 100G # are all valid. rotate_size: 200M # The directory on your host that store log location: /var/log/harbor _version: 2.6.0 proxy: http_proxy: https_proxy: no_proxy: components: - core - jobservice - trivy # enable purge _upload directories upload_purging: enabled: true # remove files in _upload directories which exist for a period of time, default is one week. age: 168h # the interval of the purge operations interval: 24h dryrun: false cache: # not enabled by default enabled: false # keep cache for one day by default expire_hours: 24
Nginx配置(原配置)
http { include mime.types; default_type application/octet-stream; #log_format main '$remote_addr - $remote_user [$time_local] "$request" ' # '$status $body_bytes_sent "$http_referer" ' # '"$http_user_agent" "$http_x_forwarded_for"'; #access_log logs/access.log main; sendfile on; #tcp_nopush on; keepalive_timeout 65; server { listen 9002; server_name 192.168.195.160; #charset koi8-r; #access_log logs/host.access.log main; location /harbor { proxy_pass http://192.168.195.160:8092; proxy_set_header Host $http_host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; proxy_buffering off; proxy_request_buffering off; } #location / { # root html; # index index.html index.htm; #} error_page 500 502 503 504 /50x.html; location = /50x.html { root html; } } }
解决步骤
1. 修正Nginx反向代理配置
问题核心在于Nginx没有正确处理/harbor前缀的转发,Harbor内部路径基于根路径/,需要将/harbor/xxx转发为/xxx。修改后的Nginx配置如下:
http { include mime.types; default_type application/octet-stream; sendfile on; keepalive_timeout 65; server { listen 9002; server_name 192.168.195.160; # 处理带末尾斜杠的请求,转发时去掉/harbor前缀 location /harbor/ { proxy_pass http://192.168.195.160:8092/; proxy_set_header Host $http_host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; proxy_buffering off; proxy_request_buffering off; } # 处理不带末尾斜杠的请求,重定向到带斜杠的路径,避免路径匹配问题 location = /harbor { return 302 /harbor/; } error_page 500 502 503 504 /50x.html; location = /50x.html { root html; } } }
修改后重启Nginx服务:
nginx -s reload
2. 确认Harbor配置并重启服务
你的harbor.yml中external_url配置已经正确设置为http://192.168.195.160:9002/harbor,但需要重新生成Harbor配置并重启服务,确保前端资源和API路径基于该外部URL生成:
# 进入Harbor安装目录 cd /path/to/harbor # 重新生成配置 ./prepare # 重启Harbor服务 docker-compose down -v docker-compose up -d
原理说明
- Nginx的
proxy_pass末尾添加斜杠后,会将location匹配的路径前缀(/harbor/)去掉,再转发到后端Harbor,确保Harbor收到的是根路径开头的请求。 external_url配置决定了Harbor前端页面生成的资源路径和API请求路径,必须与反向代理的外部访问路径一致,否则前端会请求错误的路径导致404。
内容的提问来源于stack exchange,提问作者Jimmy He
相关产品推荐
相关产品推荐

