Spring Boot Jar部署Lightsail后无法访问报ERR_CONNECTION_REFUSED
问题说明
将Spring Boot项目打包为Jar包部署在AWS Lightsail服务器,启动日志显示应用启动成功,但公网无法访问服务,Chrome返回ERR_CONNECTION_REFUSED错误。
报错信息
This site can’t be reached {ip} refused to connect.
建议排查方向:
- 检查网络连接
- 检查代理与防火墙配置
错误码:ERR_CONNECTION_REFUSED
应用启动日志
. ____ _ __ _ _ /\\ / ___'_ __ _ _(_)_ __ __ _ \ \ \ \ ( ( )\___ | '_ | '_| | '_ \/ _` | \ \ \ \ \\/ ___)| |_)| | | | | || (_| | ) ) ) ) ' |____| .__|_| |_|_| |_\__, | / / / / =========|_|==============|___/=/_/_/_/ :: Spring Boot :: (v2.7.0) 2022-06-21 05:37:40.476 INFO 7028 --- [ main] com.--Application : Starting MyApplication using Java 17.0.3 on ip-172-26-7-171 with PID 7028 (/home/ubuntu/My.jar started by root in /home/ubuntu) 2022-06-21 05:37:40.483 INFO 7028 --- [ main] com.--Application : The following 1 profile is active: "prod" 2022-06-21 05:37:42.758 INFO 7028 --- [ main] .s.d.r.c.RepositoryConfigurationDelegate : Bootstrapping Spring Data JPA repositories in DEFAULT mode. 2022-06-21 05:37:42.883 INFO 7028 --- [ main] .s.d.r.c.RepositoryConfigurationDelegate : Finished Spring Data repository scanning in 100 ms. Found 1 JPA repository interfaces. 2022-06-21 05:37:44.472 INFO 7028 --- [ main] o.s.b.w.embedded.tomcat.TomcatWebServer : Tomcat initialized with port(s): 80 (http) 2022-06-21 05:37:44.501 INFO 7028 --- [ main] o.apache.catalina.core.StandardService : Starting service [Tomcat] 2022-06-21 05:37:44.502 INFO 7028 --- [ main] org.apache.catalina.core.StandardEngine : Starting Servlet engine: [Apache Tomcat/9.0.63] 2022-06-21 05:37:44.694 INFO 7028 --- [ main] o.a.c.c.C.[Tomcat].[localhost].[/] : Initializing Spring embedded WebApplicationContext 2022-06-21 05:37:44.695 INFO 7028 --- [ main] w.s.c.ServletWebServerApplicationContext : Root WebApplicationContext: initialization completed in 3508 ms 2022-06-21 05:37:45.661 INFO 7028 --- [ main] com.zaxxer.hikari.HikariDataSource : HikariPool-1 - Starting... 2022-06-21 05:37:46.006 INFO 7028 --- [ main] com.zaxxer.hikari.HikariDataSource : HikariPool-1 - Start completed. 2022-06-21 05:37:46.121 INFO 7028 --- [ main] o.hibernate.jpa.internal.util.LogHelper : HHH000204: Processing PersistenceUnitInfo [name: default] 2022-06-21 05:37:46.275 INFO 7028 --- [ main] org.hibernate.Version : HHH000412: Hibernate ORM core version 5.6.9.Final 2022-06-21 05:37:46.658 INFO 7028 --- [ main] o.hibernate.annotations.common.Version : HCANN000001: Hibernate Commons Annotations {5.1.2.Final} 2022-06-21 05:37:46.910 INFO 7028 --- [ main] org.hibernate.dialect.Dialect : HHH000400: Using dialect: org.hibernate.dialect.MySQL55Dialect 2022-06-21 05:37:48.039 INFO 7028 --- [ main] o.h.e.t.j.p.i.JtaPlatformInitiator : HHH000490: Using JtaPlatform implementation: [org.hibernate.engine.transaction.jta.platform.internal.NoJtaPlatform] 2022-06-21 05:37:48.055 INFO 7028 --- [ main] j.LocalContainerEntityManagerFactoryBean : Initialized JPA EntityManagerFactory for persistence unit 'default' 2022-06-21 05:37:48.995 WARN 7028 --- [ main] JpaBaseConfiguration$JpaWebConfiguration : spring.jpa.open-in-view is enabled by default. Therefore, database queries may be performed during view rendering. Explicitly configure spring.jpa.open-in-view to disable this warning 2022-06-21 05:37:49.637 WARN 7028 --- [ main] org.thymeleaf.templatemode.TemplateMode : [THYMELEAF][main] Template Mode 'HTML5' is deprecated. Using Template Mode 'HTML' instead. 2022-06-21 05:37:50.173 INFO 7028 --- [ main] o.s.s.web.DefaultSecurityFilterChain : Will secure any request with [org.springframework.security.web.session.DisableEncodeUrlFilter@3d1f558a, org.springframework.security.web.context.request.async.WebAsyncManagerIntegrationFilter@6abdec0e, org.springframework.security.web.context.SecurityContextPersistenceFilter@3762c4fc, org.springframework.security.web.header.HeaderWriterFilter@4b4ee511, org.springframework.security.web.csrf.CsrfFilter@38f77cd9, org.springframework.security.web.authentication.logout.LogoutFilter@2ae62bb6, org.springframework.security.web.authentication.UsernamePasswordAuthenticationFilter@5762658b, org.springframework.security.web.authentication.ui.DefaultLoginPageGeneratingFilter@6ca372ef, org.springframework.security.web.authentication.ui.DefaultLogoutPageGeneratingFilter@28f4f300, org.springframework.security.web.authentication.www.BasicAuthenticationFilter@6aa3bfc, org.springframework.security.web.savedrequest.RequestCacheAwareFilter@59fbb34, org.springframework.security.web.servletapi.SecurityContextHolderAwareRequestFilter@1b6924cb, org.springframework.security.web.authentication.AnonymousAuthenticationFilter@2b5c4f17, org.springframework.security.web.session.SessionManagementFilter@5a034157, org.springframework.security.web.access.ExceptionTranslationFilter@4483d35, org.springframework.security.web.access.intercept.FilterSecurityInterceptor@6fc1020a] 2022-06-21 05:37:50.300 INFO 7028 --- [ main] o.s.b.w.embedded.tomcat.TomcatWebServer : Tomcat started on port(s): 80 (http) with context path '' 2022-06-21 05:37:50.332 INFO 7028 --- [ main] com.--Application : Started MyApplication in 10.965 seconds (JVM running for 12.248)
现有配置
Lightsail防火墙规则

服务器端口监听状态
/home/ubuntu# lsof -i -nP | grep LISTEN | awk '{print $(NF-1)" "$1}' | sort -u *:22 sshd 127.0.0.1:33060 ssh 127.0.0.1:80 java 127.0.0.53:53 systemd-r
问题根因
和Lightsail平台侧防火墙配置无关,当前规则已经放行了80端口的公网入流量。问题出在应用本身的监听配置:Spring Boot内置Tomcat只绑定了本地回环地址127.0.0.1,只有服务器本机可以访问80端口,所有外部请求都会被直接拒绝,才会返回ERR_CONNECTION_REFUSED错误。正常对外提供服务的进程需要绑定0.0.0.0地址,才能接收所有网卡的请求。
修复步骤
- 修改Spring Boot配置
打开prod环境对应的配置文件(application-prod.properties或application-prod.yml),找到server.address配置项:- 如果配置值为
127.0.0.1,直接删除该配置项,或者将值改为0.0.0.0 - properties格式配置示例:
server.address=0.0.0.0 server.port=80
- 如果配置值为
- 重新打包应用,上传到服务器后重启进程
- 验证修复结果:再次执行端口监听查询命令,当输出中出现
*:80 java或者0.0.0.0:80 java时,说明服务已经正确绑定公网网卡,此时用公网IP即可正常访问。 - 额外校验:如果完成上述操作后还是无法访问,检查服务器本机防火墙规则:
执行ufw status查看ufw防火墙状态,如果是启用状态,执行ufw allow 80/tcp放行80端口的TCP流量即可。
内容的提问来源于stack exchange,提问作者Yeon
相关产品推荐
相关产品推荐

