You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Nginx配置问题:主域名与通配符子域名无法分别指向不同项目

解决方案

要实现主域名与通配符子域名分别指向不同Next.js项目,需从SSL证书、Nginx配置两方面调整:

1. 生成支持通配符的SSL证书

原证书仅覆盖example.com,需重新生成包含主域名与所有子域名的证书:

sudo certbot certonly --nginx -d example.com -d *.example.com

执行后Certbot会自动更新证书文件,确保后续Nginx配置使用的证书支持*.example.com。

2. 配置独立的Nginx Server块

创建两个独立的server块,分别处理主域名和通配符子域名的请求:

主域名(example.com)配置

server {
    server_name example.com;

    location / {
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_pass http://localhost:9002;
        proxy_http_version 1.1;
        proxy_set_header Upgrade $http_upgrade;
        proxy_set_header Connection 'upgrade';
        proxy_set_header Host $host;
        proxy_set_header X-Forwarded-Proto $scheme;
        proxy_set_header Accept-Encoding "";
        proxy_set_header Proxy "";
        proxy_cache_bypass $http_upgrade;
    }

    location /api/ {
        rewrite ^/api/(.*) /$1 break;
        proxy_pass http://localhost:3333/;
        proxy_http_version 1.1;
        proxy_set_header Upgrade $http_upgrade;
        proxy_set_header Connection 'upgrade';
        proxy_set_header Host $host;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;
        proxy_set_header Accept-Encoding "";
        proxy_set_header Proxy "";
        proxy_cache_bypass $http_upgrade;
    }

    listen [::]:443 ssl;
    listen 443 ssl;
    ssl_certificate /etc/letsencrypt/live/example.com/fullchain.pem;
    ssl_certificate_key /etc/letsencrypt/live/example.com/privkey.pem;
    include /etc/letsencrypt/options-ssl-nginx.conf;
    ssl_dhparam /etc/letsencrypt/ssl-dhparams.pem;
}

# HTTP跳转HTTPS
server {
    if ($host = example.com) {
        return 301 https://$host$request_uri;
    }

    listen 80;
    listen [::]:80;
    server_name example.com;
    return 404;
}

通配符子域名(*.example.com)配置

替换proxy_pass后的端口为你的子域名项目端口(示例为9003):

server {
    server_name *.example.com;

    location / {
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_pass http://localhost:9003;
        proxy_http_version 1.1;
        proxy_set_header Upgrade $http_upgrade;
        proxy_set_header Connection 'upgrade';
        proxy_set_header Host $host;
        proxy_set_header X-Forwarded-Proto $scheme;
        proxy_set_header Accept-Encoding "";
        proxy_set_header Proxy "";
        proxy_cache_bypass $http_upgrade;
    }

    # 若子域名项目需/api转发,按需添加以下配置
    # location /api/ {
    #     rewrite ^/api/(.*) /$1 break;
    #     proxy_pass http://localhost:xxx/;
    #     # 复制上述proxy相关配置
    # }

    listen [::]:443 ssl;
    listen 443 ssl;
    ssl_certificate /etc/letsencrypt/live/example.com/fullchain.pem;
    ssl_certificate_key /etc/letsencrypt/live/example.com/privkey.pem;
    include /etc/letsencrypt/options-ssl-nginx.conf;
    ssl_dhparam /etc/letsencrypt/ssl-dhparams.pem;
}

# HTTP跳转HTTPS
server {
    if ($host ~ ^.*\.example\.com$) {
        return 301 https://$host$request_uri;
    }

    listen 80;
    listen [::]:80;
    server_name *.example.com;
    return 404;
}

3. 验证配置并重启Nginx

sudo nginx -t
sudo systemctl restart nginx

关键说明

  • Nginx会优先匹配精确的server_name(如example.com),再匹配通配符后缀的*.example.com,确保请求路由正确。
  • 确保两个server块未设置default_server,避免匹配逻辑冲突。

内容的提问来源于stack exchange,提问作者Hkm Sadek

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.18 20:00:38