You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Docker环境下NGINX反向代理的基于角色访问控制实现问询

基于角色的Nginx反向代理访问控制方案

方案一:使用Nginx组文件实现(推荐,适合多用户场景)

1. 创建用户密码文件与组文件

  • 用htpasswd生成密码文件(假设挂载到Nginx容器的/etc/nginx/.htpasswd路径):
    # 初始化密码文件并添加user角色用户user1
    htpasswd -c ./nginx/.htpasswd user1
    # 添加admin角色用户admin1
    htpasswd ./nginx/.htpasswd admin1
    
  • 创建组文件./nginx/.htgroups,格式为组名: 用户名列表:
    user: user1
    admin: admin1
    

2. 修改Nginx反向代理配置(default.conf)

在对应location块中指定允许的用户组:

server {
    listen 80;
    server_name localhost;

    # website1 仅允许user组访问
    location /website1 {
        auth_basic "Website1 访问限制";
        auth_basic_user_file /etc/nginx/.htpasswd;
        auth_basic_group_file /etc/nginx/.htgroups;
        auth_basic "user"; # 指定仅开放给user组

        proxy_pass http://website1:80;
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
    }

    # website2 仅允许admin组访问
    location /website2 {
        auth_basic "Website2 访问限制";
        auth_basic_user_file /etc/nginx/.htpasswd;
        auth_basic_group_file /etc/nginx/.htgroups;
        auth_basic "admin"; # 指定仅开放给admin组

        proxy_pass http://website2:80;
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
    }
}

3. 更新docker-compose.yaml挂载文件

确保reverseproxy容器挂载密码文件和组文件:

version: '3.8'
services:
  website1:
    image: website1:latest

  website2:
    image: website2:latest

  reverseproxy:
    image: nginx:latest
    ports:
      - "80:80"
    volumes:
      - ./nginx/default.conf:/etc/nginx/conf.d/default.conf
      - ./nginx/.htpasswd:/etc/nginx/.htpasswd
      - ./nginx/.htgroups:/etc/nginx/.htgroups
    depends_on:
      - website1
      - website2

4. 验证

重启reverseproxy容器:

docker-compose restart reverseproxy
  • 使用user1访问localhost/website1正常,访问localhost/website2会被拒绝
  • 使用admin1访问localhost/website2正常,访问localhost/website1会被拒绝

方案二:硬编码用户角色(适合用户较少场景)

如果不想维护组文件,可直接在Nginx配置中绑定用户与角色:

1. 保持原有密码文件不变

无需修改.htpasswd,直接在Nginx配置中添加角色映射:

# 映射用户名到对应角色
map $remote_user $user_role {
    default "";
    user1 "user";
    admin1 "admin";
}

server {
    listen 80;
    server_name localhost;

    location /website1 {
        auth_basic "Website1 访问限制";
        auth_basic_user_file /etc/nginx/.htpasswd;
        # 非user角色直接返回403
        if ($user_role != "user") {
            return 403;
        }

        proxy_pass http://website1:80;
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
    }

    location /website2 {
        auth_basic "Website2 访问限制";
        auth_basic_user_file /etc/nginx/.htpasswd;
        # 非admin角色直接返回403
        if ($user_role != "admin") {
            return 403;
        }

        proxy_pass http://website2:80;
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
    }
}

后续只需在map块中添加新用户与角色即可。

内容的提问来源于stack exchange,提问作者MrCoads

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.11 17:40:28