单IP多域名映射及Nginx用户自定义域名绑定方案咨询
Absolutely, this is not only feasible—it’s the core mechanism behind custom domain support on platforms like Shopify. Let’s walk through exactly how to implement this with your existing Nginx + Let’s Encrypt setup on Ubuntu.
Step 1: Guide the user to update their DNS records
First, the user needs to configure their domain’s DNS (via their registrar or DNS provider) to point www.someone.com to your subdomain:
- Create a CNAME record for
www.someone.comthat targetsa.xyz.com. This tells DNS resolvers to route traffic for their www subdomain to your subdomain. - If they also want their root domain (
someone.com) to point to your service, note that root domains can’t use CNAME records. They’ll need to use an ANAME/ALIAS record (if their provider supports it) or an A record pointing directly to your server’s public IP. CNAME is preferred for www since it avoids IP update headaches later.
Step 2: Update your Nginx configuration
You have two options here, depending on how much control you need:
Option 1: Add the custom domain as an alias (simplest)
If you don’t need separate rules for www.someone.com, just add it as an alias to your existing a.xyz.com server block:
server { listen 443 ssl; # Add www.someone.com to the server_name list server_name a.xyz.com www.someone.com; # Keep your existing SSL config, root, location blocks, etc. ssl_certificate /etc/letsencrypt/live/xyz.com/fullchain.pem; ssl_certificate_key /etc/letsencrypt/live/xyz.com/privkey.pem; include /etc/letsencrypt/options-ssl-nginx.conf; ssl_dhparam /etc/letsencrypt/ssl-dhparams.pem; # ... rest of your a.xyz.com config } # Don't forget the HTTP redirect block for the custom domain server { listen 80; server_name www.someone.com; return 301 https://$host$request_uri; }
Option 2: Reverse proxy for full control
If you need to apply specific rules (like modifying headers, rate limiting, or logging) for the custom domain, set up a reverse proxy server block:
# HTTP to HTTPS redirect server { listen 80; server_name www.someone.com; return 301 https://$host$request_uri; } # HTTPS server block for the custom domain server { listen 443 ssl; server_name www.someone.com; # SSL cert for the custom domain (see Step 3 below) ssl_certificate /etc/letsencrypt/live/www.someone.com/fullchain.pem; ssl_certificate_key /etc/letsencrypt/live/www.someone.com/privkey.pem; include /etc/letsencrypt/options-ssl-nginx.conf; ssl_dhparam /etc/letsencrypt/ssl-dhparams.pem; # Proxy all requests to your subdomain location / { proxy_pass https://a.xyz.com; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; } }
Step 3: Get an SSL certificate for the custom domain
Your existing wildcard cert (*.xyz.com) only covers subdomains of xyz.com, so you’ll need a separate cert for www.someone.com. Use Certbot to generate it automatically:
sudo certbot --nginx -d www.someone.com
If the user wants to cover their root domain too, add -d someone.com to the command. Certbot will handle domain validation via your Nginx config and auto-update the SSL settings in your server blocks.
How this compares to Shopify’s implementation
Shopify does exactly this under the hood, just automated:
- When a merchant adds a custom domain, Shopify asks them to create a CNAME record pointing to their Shopify subdomain (e.g.,
shopname.myshopify.com). - Shopify automatically provisions an SSL certificate for the custom domain (using Let’s Encrypt or their own managed cert service).
- Their server fleet adds a new Nginx (or equivalent) server block to proxy traffic from the custom domain to the merchant’s shop subdomain.
The core logic is identical—you’re just doing the manual version of what Shopify automates for their users.
Quick checks to ensure everything works
- Verify DNS propagation: Use
dig www.someone.comornslookup www.someone.comto confirm the CNAME record is active. - Test the config: Run
sudo nginx -tto check for syntax errors, then reload Nginx withsudo systemctl reload nginx. - Test HTTPS: Visit
https://www.someone.comand confirm it loads youra.xyz.comcontent with a valid SSL certificate.
内容的提问来源于stack exchange,提问作者Manish Yadav

