Docker环境下Nginx反向代理SonarQube无法更新设置求助
I ran into exactly this issue recently: SonarQube and Nginx were deployed via Docker, SonarQube was accessible through the Nginx reverse proxy, but any update action in the UI (installing plugins, updating account info, etc.) failed. The error message said Ajax requests couldn't pass cookies or auth tokens, and clicking the plugin install button would send a POST request to http://localhost:8089/sonarqube/api/plugins/install without any success.
What's Missing in Your Config?
The problem stems from two key gaps:
- Your Nginx proxy isn't passing critical request headers that SonarQube needs to identify the real client context.
- SonarQube doesn't know its external public URL (since it's behind a proxy), so it generates incorrect paths for cookies and API requests.
Fixed Configuration
1. Updated Nginx Config
Add proxy headers to forward the original request details to SonarQube:
worker_processes 1; events { worker_connections 1024; } http { sendfile on; server { listen 8080; # Match the port exposed in Docker Compose for Nginx location /sonarqube { proxy_pass http://sonarqube:9000; proxy_read_timeout 90s; proxy_redirect http://sonarqube:9000 http://localhost:8089; # Critical headers to add: proxy_set_header Host $host; proxy_set_header X-Forwarded-For $remote_addr; proxy_set_header X-Forwarded-Proto $scheme; proxy_set_header X-Forwarded-Host $host:$server_port; proxy_set_header X-Forwarded-Port $server_port; } } }
These headers ensure SonarQube gets the real client IP, protocol, and external host information, which is essential for handling authentication and session cookies correctly.
2. Fixed Docker Compose for SonarQube
You already found the key fix with sonar.core.serverBaseUrl, but make sure it's a full valid URL (include the protocol like http://):
version: "3.5" services: nginx: build: context: . dockerfile: Dockerfile.nginx ports: - "8089:8080" networks: - sonarnet sonarqube: build: context: . dockerfile: Dockerfile.sonarqube expose: - "9000" networks: - sonarnet environment: - SONARQUBE_JDBC_URL=jdbc:postgresql://db:5432/sonar - SONARQUBE_JDBC_USERNAME=sonar - SONARQUBE_JDBC_PASSWORD=sonar - sonar.forceAuthentication=true - sonar.web.context=/sonarqube # Fixed: Full public URL of your SonarQube instance - sonar.core.serverBaseUrl=http://localhost:8089/sonarqube volumes: - sonarqubeConf:/opt/sonarqube/conf - sonarqubeLogs:/opt/sonarqube/logs db: image: postgres networks: - sonarnet environment: - POSTGRES_USER=sonar - POSTGRES_PASSWORD=sonar volumes: - postgresql:/var/lib/postgresql - postgresqlData:/var/lib/postgresql/data networks: sonarnet: driver: bridge volumes: sonarqubeConf: sonarqubeLogs: postgresql: postgresqlData:
Setting sonar.core.serverBaseUrl tells SonarQube exactly what its public-facing URL is, so it generates correct API endpoints and cookie paths that match what the browser expects.
Why This Works
Without these settings, SonarQube would use its internal container URL (http://sonarqube:9000/sonarqube) for generating API requests and cookies. When the browser tries to send requests to this internal URL (or mismatched paths), the cookies (which are bound to localhost:8089) aren't sent, leading to authentication failures for Ajax actions.
After applying both changes, your SonarQube UI should be able to handle plugin installs, account updates, and other authenticated actions without issues.
内容的提问来源于stack exchange,提问作者user3426603

