Docker环境下NGINX反向代理的基于角色访问控制实现问询
基于角色的Nginx反向代理访问控制方案
方案一:使用Nginx组文件实现(推荐,适合多用户场景)
1. 创建用户密码文件与组文件
- 用
htpasswd生成密码文件(假设挂载到Nginx容器的/etc/nginx/.htpasswd路径):# 初始化密码文件并添加user角色用户user1 htpasswd -c ./nginx/.htpasswd user1 # 添加admin角色用户admin1 htpasswd ./nginx/.htpasswd admin1 - 创建组文件
./nginx/.htgroups,格式为组名: 用户名列表:user: user1 admin: admin1
2. 修改Nginx反向代理配置(default.conf)
在对应location块中指定允许的用户组:
server { listen 80; server_name localhost; # website1 仅允许user组访问 location /website1 { auth_basic "Website1 访问限制"; auth_basic_user_file /etc/nginx/.htpasswd; auth_basic_group_file /etc/nginx/.htgroups; auth_basic "user"; # 指定仅开放给user组 proxy_pass http://website1:80; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; } # website2 仅允许admin组访问 location /website2 { auth_basic "Website2 访问限制"; auth_basic_user_file /etc/nginx/.htpasswd; auth_basic_group_file /etc/nginx/.htgroups; auth_basic "admin"; # 指定仅开放给admin组 proxy_pass http://website2:80; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; } }
3. 更新docker-compose.yaml挂载文件
确保reverseproxy容器挂载密码文件和组文件:
version: '3.8' services: website1: image: website1:latest website2: image: website2:latest reverseproxy: image: nginx:latest ports: - "80:80" volumes: - ./nginx/default.conf:/etc/nginx/conf.d/default.conf - ./nginx/.htpasswd:/etc/nginx/.htpasswd - ./nginx/.htgroups:/etc/nginx/.htgroups depends_on: - website1 - website2
4. 验证
重启reverseproxy容器:
docker-compose restart reverseproxy
- 使用user1访问
localhost/website1正常,访问localhost/website2会被拒绝 - 使用admin1访问
localhost/website2正常,访问localhost/website1会被拒绝
方案二:硬编码用户角色(适合用户较少场景)
如果不想维护组文件,可直接在Nginx配置中绑定用户与角色:
1. 保持原有密码文件不变
无需修改.htpasswd,直接在Nginx配置中添加角色映射:
# 映射用户名到对应角色 map $remote_user $user_role { default ""; user1 "user"; admin1 "admin"; } server { listen 80; server_name localhost; location /website1 { auth_basic "Website1 访问限制"; auth_basic_user_file /etc/nginx/.htpasswd; # 非user角色直接返回403 if ($user_role != "user") { return 403; } proxy_pass http://website1:80; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; } location /website2 { auth_basic "Website2 访问限制"; auth_basic_user_file /etc/nginx/.htpasswd; # 非admin角色直接返回403 if ($user_role != "admin") { return 403; } proxy_pass http://website2:80; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; } }
后续只需在map块中添加新用户与角色即可。
内容的提问来源于stack exchange,提问作者MrCoads
相关产品推荐
相关产品推荐

