You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用AWS ELB与ACM配置Node.js HTTPS时遇502错误及目标组异常

AWS ELB与ACM配置Node.js HTTPS时502错误及目标组不健康问题排查

配置详情

ELB配置

  • VPC:与EC2实例处于同一VPC
  • 子网:子网1(10.0.1.0/24,与EC2实例同子网)、子网2(10.0.3.0/24,测试新建子网)
  • 安全组:入站及出站全量开放(测试用)
  • 监听器(http:80):规则1匹配[example].com或www.[example].com,301重定向至https://www.[example].com:443/#{path}?#{query};默认规则未修改
  • 监听器(https:443):规则1匹配[example].com,301重定向至https://www.[example].com:443/#{path}?#{query};默认规则未修改

ELB目标组

  • 目标组1:实例类型、HTTP1协议,关联EC2实例,端口80,状态健康
  • 目标组2:实例类型、HTTP1协议,关联EC2实例,端口443,状态不健康,详情为"健康检查失败"

ELB日志摘要

  • type: h2
  • target:port: EC2实例私有IPv4地址
  • request_processing_time: -1
  • target_processing_time: -1
  • response_processing_time: -1
  • elb_status_code: 502
  • target_status_code: -
  • request: GET https://www.[example].com:443/HTTP/2.0

Route 53配置

  • [example].com(A记录):简单路由至www.[example].com.
  • www.[example].com(A记录):简单路由至dualstack.[ELB的DNS名称].
  • ACM提供的*.[example].com和www.[example].com的CNAME记录:分别路由至ACM提供的CNAME值
  • NS、SOA记录为Route 53默认配置

ACM配置

  • *.[example].com、[example].com、www.[example].com均已成功签发证书

EC2配置

  • VPC:与ELB同VPC(10.0.0.0/16)
  • 子网:与ELB的子网1(10.0.1.0/24)一致
  • 已分配弹性公网IP
  • 安全组:入站及出站全量开放(测试用)

路由表(所有子网共用)

  • 10.0.0.0/16 指向local
  • 0.0.0.0/0 指向IGW

ACLs

  • 入站及出站全量开放(测试用)

EC2上的iptables规则

# iptables -t nat -A PREROUTING -p tcp --dport 80 -j REDIRECT --to-ports 8000
# iptables -t nat -A PREROUTING -p tcp --dport 443 -j REDIRECT --to-ports 8443

EC2上的Node.js代码(index.js)

const fs = require('fs');
const http = require('http');
const https = require('https');

const express = require('express');
const app = express();
const path = require('path');

app.get('/', (req, res) => {
    res.send("Hello World!");
});

const httpServer = http.createServer(app);
const httpsServer = https.createServer(app);

httpServer.listen(8000, () => {
    console.log("App is listening on port 8000");
});

httpsServer.listen(8443, () => {
    console.log("App is listening on port 8443");
});

问题现象

  • 浏览器访问https://www.[example.com]、http://[example].com(重定向后)均返回502 Bad Gateway
  • 访问EC2弹性公网IP、公网IPv4 DNS、DNS名称均可正常显示页面
  • EC2命令行curl访问http://www.[example].com返回301,访问https://www.[example].com返回502

已尝试操作

  • 查阅AWS官方相关文档但未解决问题
  • 将HTTPS目标组的健康检查协议改为HTTP,状态仍为不健康

恳请各位提供排查思路,若需更多信息请告知,谢谢!

内容的提问来源于stack exchange,提问作者Koki

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.21 09:15:37