You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

NGINX配置WSS(安全WebSocket)连接失败如何排查解决?

问题根因

你当前的NGINX配置中,9190端口没有开启SSL解析能力,客户端发送的WSS(TLS加密的WebSocket)流量被NGINX当成普通明文HTTP流量解析,所以访问日志会出现乱码,同时返回400错误。

修复步骤

1. 修正端口监听配置

给9190端口的listen指令添加ssl参数,启用该端口的TLS解析能力,修改后如下:

listen 9190 ssl;
listen [::]:9190 ssl;

2. 修正反向代理配置

你本地后端的WebSocket服务(127.0.0.1:9090)支持明文WS协议,不需要用HTTPS反向代理,删除多余的proxy_ssl_*配置,修改后location /块如下:

location / {
    proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
    # 后端是明文WS,用http://即可
    proxy_pass http://thruway_websocket;
    proxy_http_version 1.1;
    proxy_set_header Upgrade $http_upgrade;
    proxy_set_header Connection $connection_upgrade;
    proxy_set_header Host $host;
}

3. 完整修正后的配置参考

map $http_upgrade $connection_upgrade {
    default upgrade;
    '' close;
}

upstream thruway_websocket {
    server 127.0.0.1:9090;
}

server {
    listen 9190 ssl;
    listen [::]:9190 ssl;

    server_name test.thruway.local;

    access_log /var/log/nginx/test.thruway.access_log;
    error_log /var/log/nginx/test.thruway.error_log;

    # SSL配置保留即可,对应你之前的Certbot生成的配置
    ssl_certificate /etc/letsencrypt/live/test.thruway.local/fullchain.pem;
    ssl_certificate_key /etc/letsencrypt/live/test.thruway.local/privkey.pem;
    include /etc/letsencrypt/options-ssl-nginx.conf;
    ssl_dhparam /etc/letsencrypt/ssl-dhparams.pem;

    location / {
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_pass http://thruway_websocket;
        proxy_http_version 1.1;
        proxy_set_header Upgrade $http_upgrade;
        proxy_set_header Connection $connection_upgrade;
        proxy_set_header Host $host;
    }
}

后续验证步骤

  1. 执行nginx -t检查配置语法是否正确,确认返回test is successful
  2. 执行systemctl reload nginx重载NGINX配置
  3. 重新用AutobahnJS发起WSS请求即可

内容的提问来源于stack exchange,提问作者Katai

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.10.04 23:36:00