You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Docker容器中Nginx作为Apache反向代理配置故障排查

Fixing Nginx Reverse Proxy for Apache in Your Docker Container

Let’s break down what’s causing your site to fail when Nginx runs, and fix it step by step:

Core Issues Identified

  1. Mismatched Proxy Targets: Your Apache is listening on port 81 (HTTP), but Nginx is trying to proxy to https://127.0.0.1:8443 and https://127.0.0.1:80—neither of these ports are used by your Apache instance.
  2. Static File Path Mismatch: Nginx’s static file root points to /root_path, while Apache’s DocumentRoot is /root_folder—this breaks direct static file serving.
  3. Missing SSL Configuration (for 443): Nginx is set to listen on port 443, but there’s no SSL certificate defined, which will prevent it from starting or handling HTTPS requests properly.
  4. Potential Docker Port Mapping Gaps: Your Dockerfile exposes 80 and 443, but you may not be mapping these ports correctly when running the container.

Step 1: Fix Apache Configuration (Keep It Simple)

Your Apache config is mostly fine, but confirm it’s listening on 81 and remove unused comments for clarity:

<VirtualHost *:81>
    ServerAdmin webmaster@localhost
    DocumentRoot /root_folder

    ErrorLog ${APACHE_LOG_DIR}/error.log
    CustomLog ${APACHE_LOG_DIR}/access.log combined
</VirtualHost>

Restart Apache to apply changes:

service apache2 restart

Verify it’s listening on 81:

ss -tulpn | grep apache2

Step 2: Correct Nginx Reverse Proxy Config

Update your /etc/nginx/sites-enabled/reverse-proxy.conf to fix proxy targets, static file paths, and SSL (if needed):

Option A: Use HTTP (No SSL, Listen on Port 80)

If you don’t need HTTPS yet, use this config:

server {
    listen 80;
    server_name 10.1.2.181;

    add_header X-Frame-Options "SAMEORIGIN";

    # Proxy cache settings (keep if needed)
    proxy_cache cacheone;
    proxy_cache_revalidate on;
    proxy_cache_min_uses 3;
    proxy_cache_use_stale error timeout updating http_500 http_502 http_503 http_504;
    proxy_cache_lock on;

    location / {
        proxy_pass http://127.0.0.1:81; # Point to Apache's HTTP port
        # Pass client info to Apache
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;
    }

    # Serve static files directly from Apache's document root
    location ~* ^.+\.(jpg|jpeg|gif|png|ico|svg|css|zip|tgz|gz|rar|bz2|exe|pdf|doc|xls|ppt|txt|odt|ods|odp|odf|tar|bmp|rtf|js|mp3|avi|mpeg|flv|html|htm)$ {
        root /root_folder;
        expires max;
        try_files $uri @fallback;
    }

    # Fallback to Apache if static file isn't found
    location @fallback {
        proxy_pass http://127.0.0.1:81;
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;
    }

    # Block sensitive files
    location ~ /\.ht {return 404;}
    location ~ /\.svn/ {return 404;}
    location ~ /\.git/ {return 404;}
    location ~ /\.hg/ {return 404;}
    location ~ /\.bzr/ {return 404;}
}

Option B: Use HTTPS (Listen on Port 443)

If you have an SSL certificate, add the paths to your config:

server {
    listen 443 ssl;
    server_name 10.1.2.181;

    # Add your SSL certificate paths here
    ssl_certificate /path/to/your/certificate.crt;
    ssl_certificate_key /path/to/your/private.key;

    add_header X-Frame-Options "SAMEORIGIN";

    # Proxy cache settings
    proxy_cache cacheone;
    proxy_cache_revalidate on;
    proxy_cache_min_uses 3;
    proxy_cache_use_stale error timeout updating http_500 http_502 http_503 http_504;
    proxy_cache_lock on;

    location / {
        proxy_pass http://127.0.0.1:81;
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;
    }

    # Static file serving (same as HTTP option)
    location ~* ^.+\.(jpg|jpeg|gif|png|ico|svg|css|zip|tgz|gz|rar|bz2|exe|pdf|doc|xls|ppt|txt|odt|ods|odp|odf|tar|bmp|rtf|js|mp3|avi|mpeg|flv|html|htm)$ {
        root /root_folder;
        expires max;
        try_files $uri @fallback;
    }

    location @fallback {
        proxy_pass http://127.0.0.1:81;
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;
    }

    # Block sensitive files
    location ~ /\.ht {return 404;}
    location ~ /\.svn/ {return 404;}
    location ~ /\.git/ {return 404;}
    location ~ /\.hg/ {return 404;}
    location ~ /\.bzr/ {return 404;}
}

Validate & Restart Nginx

Test the config for errors:

nginx -t

If no errors, restart Nginx:

service nginx restart

Step 3: Fix Docker Port Mapping

Ensure you’re mapping the correct container port to your host when running the container:

  • For HTTP (port 80):
    docker run -d -p 80:80 -p 2222:2222 your-image-name
    
  • For HTTPS (port 443):
    docker run -d -p 443:443 -p 2222:2222 your-image-name
    

Step 4: Verify Services Are Running

Inside the container, confirm both services are active:

service apache2 status
service nginx status

Check that ports 81 (Apache) and 80/443 (Nginx) are listening:

ss -tulpn

内容的提问来源于stack exchange,提问作者User_1

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.13 08:52:01