You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

NGINX NodeJS反代环境下子域名无跳转映射子路径配置问题求助

问题根因

  • 你当前使用的Let's Encrypt证书仅覆盖example.domain和www.example.domain,未包含admin.example.domain,所以HTTPS访问子域名时会触发证书不安全告警。
  • 新增的admin子域名server块存在语法错误:server_name admin.example.domain行末尾缺失分号,会导致配置加载异常。
  • 代理配置缺少必要的请求头和重定向规则,Node服务识别到请求域名为admin.example.domain后,结合路径拼接逻辑会触发额外跳转,最终出现admin.example.domain/admin的错误路径。

解决方案

步骤1:扩容SSL证书覆盖子域名

执行Certbot命令为现有证书新增admin.example.domain域名:

certbot certonly --expand -d example.domain -d www.example.domain -d admin.example.domain

按提示完成验证后,新证书会自动覆盖原有文件,同时覆盖三个域名的HTTPS访问。

步骤2:补充子域名DNS解析

由于你未配置泛解析,需要在Webhuset.no的DNS管理后台单独为admin.example.domain添加A/AAAA记录,指向你的Hetzner服务器公网IP。

步骤3:修改Nginx配置

替换你之前新增的admin子域名server块为以下配置,同时补充80端口统一跳转HTTPS的规则:

# 80端口全量跳转HTTPS
server {
    listen 80;
    listen [::]:80;
    server_name example.domain www.example.domain admin.example.domain;
    return 301 https://$host$request_uri;
}

# 原有主域名server块保持不变,只新增下面的admin子域名server块
server {
    server_name admin.example.domain;
    listen [::]:443 ssl ipv6only=on;
    listen 443 ssl;
    ssl_certificate /etc/letsencrypt/live/example.domain/fullchain.pem;
    ssl_certificate_key /etc/letsencrypt/live/example.domain/privkey.pem;
    include /etc/letsencrypt/options-ssl-nginx.conf;
    ssl_dhparam /etc/letsencrypt/ssl-dhparams.pem;

    location / {
        # 末尾加斜杠保证路径拼接正确,admin.example.domain/xxx 会映射到 127.0.0.1:3000/admin/xxx
        proxy_pass http://127.0.0.1:3000/admin/;
        proxy_http_version 1.1;
        proxy_set_header Upgrade $http_upgrade;
        proxy_set_header Connection 'upgrade';
        # 主动指定Host为主域名,避免Node服务识别子域名触发异常跳转
        proxy_set_header Host example.domain;
        proxy_cache_bypass $http_upgrade;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;
        # 重写上游返回的重定向路径,移除路径前缀的/admin
        proxy_redirect ^/admin/(.*)$ /$1;
    }
}

步骤4:生效配置

执行以下命令验证配置语法正确性,无误后重载Nginx生效:

nginx -t
systemctl reload nginx

内容的提问来源于stack exchange,提问作者Marius

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.09.27 23:06:04