Docker容器中Nginx作为Apache反向代理配置故障排查
Let’s break down what’s causing your site to fail when Nginx runs, and fix it step by step:
Core Issues Identified
- Mismatched Proxy Targets: Your Apache is listening on port
81(HTTP), but Nginx is trying to proxy tohttps://127.0.0.1:8443andhttps://127.0.0.1:80—neither of these ports are used by your Apache instance. - Static File Path Mismatch: Nginx’s static file
rootpoints to/root_path, while Apache’sDocumentRootis/root_folder—this breaks direct static file serving. - Missing SSL Configuration (for 443): Nginx is set to listen on port
443, but there’s no SSL certificate defined, which will prevent it from starting or handling HTTPS requests properly. - Potential Docker Port Mapping Gaps: Your Dockerfile exposes
80and443, but you may not be mapping these ports correctly when running the container.
Step 1: Fix Apache Configuration (Keep It Simple)
Your Apache config is mostly fine, but confirm it’s listening on 81 and remove unused comments for clarity:
<VirtualHost *:81> ServerAdmin webmaster@localhost DocumentRoot /root_folder ErrorLog ${APACHE_LOG_DIR}/error.log CustomLog ${APACHE_LOG_DIR}/access.log combined </VirtualHost>
Restart Apache to apply changes:
service apache2 restart
Verify it’s listening on 81:
ss -tulpn | grep apache2
Step 2: Correct Nginx Reverse Proxy Config
Update your /etc/nginx/sites-enabled/reverse-proxy.conf to fix proxy targets, static file paths, and SSL (if needed):
Option A: Use HTTP (No SSL, Listen on Port 80)
If you don’t need HTTPS yet, use this config:
server { listen 80; server_name 10.1.2.181; add_header X-Frame-Options "SAMEORIGIN"; # Proxy cache settings (keep if needed) proxy_cache cacheone; proxy_cache_revalidate on; proxy_cache_min_uses 3; proxy_cache_use_stale error timeout updating http_500 http_502 http_503 http_504; proxy_cache_lock on; location / { proxy_pass http://127.0.0.1:81; # Point to Apache's HTTP port # Pass client info to Apache proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; } # Serve static files directly from Apache's document root location ~* ^.+\.(jpg|jpeg|gif|png|ico|svg|css|zip|tgz|gz|rar|bz2|exe|pdf|doc|xls|ppt|txt|odt|ods|odp|odf|tar|bmp|rtf|js|mp3|avi|mpeg|flv|html|htm)$ { root /root_folder; expires max; try_files $uri @fallback; } # Fallback to Apache if static file isn't found location @fallback { proxy_pass http://127.0.0.1:81; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; } # Block sensitive files location ~ /\.ht {return 404;} location ~ /\.svn/ {return 404;} location ~ /\.git/ {return 404;} location ~ /\.hg/ {return 404;} location ~ /\.bzr/ {return 404;} }
Option B: Use HTTPS (Listen on Port 443)
If you have an SSL certificate, add the paths to your config:
server { listen 443 ssl; server_name 10.1.2.181; # Add your SSL certificate paths here ssl_certificate /path/to/your/certificate.crt; ssl_certificate_key /path/to/your/private.key; add_header X-Frame-Options "SAMEORIGIN"; # Proxy cache settings proxy_cache cacheone; proxy_cache_revalidate on; proxy_cache_min_uses 3; proxy_cache_use_stale error timeout updating http_500 http_502 http_503 http_504; proxy_cache_lock on; location / { proxy_pass http://127.0.0.1:81; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; } # Static file serving (same as HTTP option) location ~* ^.+\.(jpg|jpeg|gif|png|ico|svg|css|zip|tgz|gz|rar|bz2|exe|pdf|doc|xls|ppt|txt|odt|ods|odp|odf|tar|bmp|rtf|js|mp3|avi|mpeg|flv|html|htm)$ { root /root_folder; expires max; try_files $uri @fallback; } location @fallback { proxy_pass http://127.0.0.1:81; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; } # Block sensitive files location ~ /\.ht {return 404;} location ~ /\.svn/ {return 404;} location ~ /\.git/ {return 404;} location ~ /\.hg/ {return 404;} location ~ /\.bzr/ {return 404;} }
Validate & Restart Nginx
Test the config for errors:
nginx -t
If no errors, restart Nginx:
service nginx restart
Step 3: Fix Docker Port Mapping
Ensure you’re mapping the correct container port to your host when running the container:
- For HTTP (port 80):
docker run -d -p 80:80 -p 2222:2222 your-image-name - For HTTPS (port 443):
docker run -d -p 443:443 -p 2222:2222 your-image-name
Step 4: Verify Services Are Running
Inside the container, confirm both services are active:
service apache2 status service nginx status
Check that ports 81 (Apache) and 80/443 (Nginx) are listening:
ss -tulpn
内容的提问来源于stack exchange,提问作者User_1

