You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Strapi后端Nginx代理无响应及无法解析主机问题求助

问题:Strapi通过Nginx代理后无法正常访问,curl提示无法解析主机

我在虚拟机上基于Strapi开发研究用Web系统,前端已通过Nginx(v1.18.0)上线,配置SSL证书后HTTP自动重定向到HTTPS,运行正常。但Strapi仍在localhost:1337以非HTTPS方式运行,浏览器拒绝连接。按照Strapi文档配置Nginx代理后,执行curl请求时出现无法解析主机错误。nginx -t测试显示配置有效,但代理仍无法工作。


相关配置文件

Strapi生产环境配置 (./config/env/production/server.js)

module.exports = ({ env }) => ({    
    host: env('HOST', '127.0.0.1'),    
    port: env.int('PORT', 1337),    
    url: 'https://api.my-domain.com',    
    app: {        
        keys: env.array('APP_KEYS'),    
    },
});

Nginx上游配置 (/etc/nginx/conf.d/upstream.conf)

# Strapi server
upstream strapi {    
    server 127.0.0.1:1337;
}

Nginx Strapi站点配置 (/etc/nginx/sites-available/strapi.conf,测试时添加了return 200 'OK')

server {    
    # Listen HTTP    
    listen 80;    
    server_name api.my-domain.com;    
    # Redirect HTTP to HTTPS    
    return 301 https://$host$request_uri;
}

server {    
    # Listen HTTPS    
    listen 443 ssl;    
    server_name api.my-domain.com;    
    # SSL config    
    ssl_certificate path/to/certificate/fullchain.pem    
    ssl_certificate_key path/to/certificate/privkey.pem

    # Proxy Config    
    location / {        
        proxy_pass http://strapi/;        
        proxy_http_version 1.1;        
        proxy_set_header X-Forwarded-Host $host;        
        proxy_set_header X-Forwarded-Server $host;        
        proxy_set_header X-Real-IP $remote_addr;        
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;        
        proxy_set_header X-Forwarded-Proto $scheme;        
        proxy_set_header Host $http_host;        
        proxy_set_header Upgrade $http_upgrade;        
        proxy_set_header Connection "Upgrade";        
        proxy_pass_request_headers on;        
        return 200 "OK";    
    }
}

Nginx默认域名配置 (/etc/nginx/sites-available/default)

server {        
    listen 443 ssl default_server;        
    listen [::]:443 ssl default_server;        
    include snippets/self-signed.conf;        
    include snippets/ssl-params.conf;        
       
    root /var/www/my-domain/html;        
    # Add index.php to the list if you are using PHP        
    index index.html index.htm index.nginx-debian.html;        
    server_name my-domain.com www.my-domain.com;        
    location / {                
        # First attempt to serve request as file, then                
        try_files $uri $uri/ =404;        
    }
}
server {        
    listen 80 default_server;        
    server_name _;        
    return 301 https://$host$request_uri;
}
server {        
    listen 443 ssl ;        
    listen [::]:443 ssl ;        
    include snippets/self-signed.conf;        
    include snippets/ssl-params.conf;        
    root /var/www/my-domain.com/html;        
    # Add index.php to the list if you are using PHP        
    index index.html index.htm index.nginx-debian.html;        
    server_name my-domain.com; # managed by Certbot        
    location / {                
        # First attempt to serve request as file, then                
        # as directory, then fall back to displaying a 404.                
        try_files $uri $uri/ =404;        
    }       
    ssl_certificate path/to/certificate/fullchain.pem       
    ssl_certificate_key path/to/certificate/privkey.pem
}

环境信息

  • Strapi版本:4.4.3
  • 操作系统:Ubuntu 20.04.5 LTS
  • 数据库:MySQL
  • Node版本:v18.10.0
  • NPM版本:8.19.2
  • Yarn版本:1.22.19

排查与解决步骤

1. 移除测试用的return 200 "OK"

strapi.conf的location /块中同时存在proxy_pass和return 200,Nginx会优先执行return指令,直接返回"OK"而不转发请求到Strapi。删掉这行:

return 200 "OK";

2. 修复SSL配置的语法错误

多个配置文件中SSL证书行末尾缺少分号,这会导致Nginx实际加载配置时出错(部分情况下nginx -t可能未检测出):

# 修正后
ssl_certificate path/to/certificate/fullchain.pem;    
ssl_certificate_key path/to/certificate/privkey.pem;

将strapi.conf和默认配置文件中的对应行都补上分号。

3. 确认域名解析与本地映射

  • 确保api.my-domain.com已正确解析到虚拟机IP,本地测试可在/etc/hosts添加映射:
    echo "你的虚拟机IP api.my-domain.com" >> /etc/hosts
    
  • 执行curl -v https://api.my-domain.com,检查是否能正常连接Nginx,再验证请求是否转发到Strapi。

4. 检查Strapi监听状态

执行以下命令确认Strapi是否在127.0.0.1:1337正常监听:

netstat -tulpn | grep 1337

如果未检测到监听,重启Strapi服务:

yarn start --production

5. 启用Nginx站点配置

确认strapi.conf已软链接到sites-enabled目录:

ln -s /etc/nginx/sites-available/strapi.conf /etc/nginx/sites-enabled/

然后重启Nginx:

systemctl restart nginx

6. 配置Strapi信任代理

在./config/middlewares.js中修改strapi::security配置,开启代理信任:

module.exports = [
  // ...其他中间件
  {
    name: 'strapi::security',
    config: {
      contentSecurityPolicy: {
        useDefaults: true,
        directives: {
          'connect-src': ["'self'", 'https:'],
        },
      },
      proxy: true, // 启用信任代理
    },
  },
  // ...其他中间件
];

内容的提问来源于stack exchange,提问作者Thomas Mildner

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.11 10:05:21