AWS三层架构中NGINX转发请求至内部ALB的配置咨询
NGINX 转发配置说明
需修改的配置文件
默认情况下你需要修改NGINX的站点配置文件,常用路径如下:
- RHEL/CentOS/Amazon Linux 系列:
/etc/nginx/conf.d/目录下自定义的.conf后缀配置文件,比如default.conf - Debian/Ubuntu 系列:
/etc/nginx/sites-available/目录下的站点配置文件,修改完成后需要软链到/etc/nginx/sites-enabled/目录生效
配置示例
场景1:全链路HTTP访问
如果你的内部ALB监听的是HTTP 80端口,直接用以下配置即可:
server { listen 80; server_name _; # 匹配外部ALB发过来的所有域名请求,也可以填外部ALB的DNS域名 location / { # 替换为你的内部ALB的VPC DNS地址,注意末尾不要漏写斜杠 proxy_pass http://<内部ALB的DNS地址>/; # 传递必要的请求头,保证后端Apache能拿到正确的客户端信息 proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; # 调整超时时间适配AWS ALB的默认超时设置 proxy_connect_timeout 60s; proxy_send_timeout 60s; proxy_read_timeout 60s; } }
场景2:内部ALB使用HTTPS 443端口
如果内部ALB配置了SSL证书监听HTTPS端口,使用以下配置:
server { listen 80; server_name _; location / { # 替换为你的内部ALB的VPC DNS地址,协议改为https proxy_pass https://<内部ALB的DNS地址>/; # 同上传递请求头 proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; # 如果内部ALB用的是AWS颁发的私有证书,可关闭SSL验证避免报错,生产环境建议配置CA证书验证 proxy_ssl_verify off; # 超时配置同上 proxy_connect_timeout 60s; proxy_send_timeout 60s; proxy_read_timeout 60s; } }
生效步骤
- 配置修改完成后,运行
nginx -t命令验证配置语法是否正确,返回success说明配置无误 - 运行
systemctl reload nginx重载NGINX配置,无需重启服务即可生效
注意事项
- 确保NGINX所在EC2的安全组,放行到内部ALB对应端口(80/443)的出站流量
- 确保内部ALB的安全组,放行NGINX所在EC2的私有IP段到对应端口的入站流量
- NGINX所在EC2需使用VPC默认DNS服务器,保证能正常解析内部ALB的私有DNS地址
内容的提问来源于stack exchange,提问作者Chandan Gowda
相关产品推荐
相关产品推荐

