WSO2 5.9配置端口443反向代理时自定义配置被覆盖问题咨询
I’ve dealt with this exact headache before—WSO2’s configuration system overwrites manual edits to catalina-server.xml because it generates that file dynamically from deployment.toml on startup. Your initial proxyPort placement in the [server] section was misplaced; we need to target the Tomcat HTTPS Connector directly in the TOML config to make the setting stick.
Here’s the corrected configuration to add to your deployment.toml:
[server] hostname = "mydomain.com" node_ip = "xxx.xxx.xxx.xxx" # Remove the port from base_path since 443 is the default HTTPS port base_path = "https://$ref{server.hostname}" # Configure the Tomcat HTTPS Connector with proxyPort [tomcat.connector.https] port = 9443 # Keep WSO2's internal HTTPS port unchanged proxyPort = 443 scheme = "https" secure = true
Why this works:
- The
[tomcat.connector.https]section maps directly to the HTTPS Connector entry incatalina-server.xml. When WSO2 starts up, it will generate the Connector with theproxyPort="443"attribute included, so your reverse proxy setup will be respected. - Updating
base_pathto omit the port ensures all internal links, redirects, and metadata point to your domain on port 443 instead of the default 9443.
Quick Verification:
After restarting the server, check <WSO2_HOME>/repository/conf/tomcat/catalina-server.xml. Look for the HTTPS Connector element—it should now show:
<Connector port="9443" proxyPort="443" scheme="https" secure="true" ... />
Remember: Never edit catalina-server.xml directly in WSO2 5.x+; all Tomcat-related configurations must be managed via deployment.toml to avoid being overwritten on startup.
内容的提问来源于stack exchange,提问作者Brygom

