如何在Varnish中配置HTTPS?支持客户端HTTPS并转发至HTTPS后端
Hey there! Let's walk through how to configure Varnish to handle incoming HTTPS requests and forward them to your HTTPS backend. Important note upfront: Varnish doesn't natively support SSL/TLS termination, so we need a separate tool to handle the encryption layer. The official recommended tool is Hitch, but I'll also cover using Nginx as an alternative if that's more your speed.
Hitch is built specifically to pair with Varnish, so it's the most seamless option.
Step 1: Install Hitch
First, get Hitch installed on your server—package names vary by distro:
- Debian/Ubuntu:
sudo apt install hitch - RHEL/CentOS:
sudo dnf install hitch(useyumfor older versions)
Step 2: Configure Hitch
Edit the main Hitch config file (usually /etc/hitch/hitch.conf) to set up SSL termination and forward traffic to Varnish:
# Listen on port 443 for incoming HTTPS requests frontend = { host = "*" port = "443" } # Forward decrypted traffic to Varnish's default backend port (6081) backend = "[127.0.0.1]:6081" # Path to your combined SSL certificate + private key (concatenate cert + intermediate CA if needed) pem-file = "/path/to/your/full-certificate.pem" # Enforce modern TLS versions for security tls-protos = TLSv1.2 TLSv1.3 # Optional: Enable OCSP stapling to improve client performance ocsp-stapling = on
Make sure your .pem file includes your server certificate first, followed by any intermediate CA certificates (in order). If you prefer to keep the private key separate, add private-key-file = "/path/to/your/private-key.key" instead of including it in the pem file.
Step 3: Configure Varnish
First, update Varnish to listen on port 6081 (the port Hitch will forward to). Depending on your distro:
- Edit
/etc/default/varnishor/etc/systemd/system/varnish.serviceto setVARNISH_LISTEN_PORT=6081 - Reload systemd if needed:
sudo systemctl daemon-reload
Then update your VCL file (typically /etc/varnish/default.vcl) to define your HTTPS backend:
vcl 4.1; backend default { .host = "your-backend-domain.com"; .port = "443"; .ssl = true; # Enable HTTPS for connections to the backend .ssl_verify = false; # Set to true if you want to validate the backend's SSL cert # Optional: If your backend uses a self-signed cert, add its CA file: # .ssl_ca_cert = "/path/to/backend-ca-cert.pem"; } sub vcl_recv { # Pass the original HTTPS protocol to the backend (helps backend apps detect HTTPS) set req.http.X-Forwarded-Proto = "https"; }
Step 4: Restart Services
sudo systemctl restart hitch sudo systemctl restart varnish
If you're already familiar with Nginx, it works just as well for SSL termination.
Step 1: Install Nginx
# Debian/Ubuntu sudo apt install nginx # RHEL/CentOS sudo dnf install nginx
Step 2: Configure Nginx SSL Termination
Create a new server block (e.g., /etc/nginx/sites-available/your-domain.conf):
server { listen 443 ssl; server_name your-domain.com; # Path to your SSL cert and private key ssl_certificate /path/to/your/full-certificate.pem; ssl_certificate_key /path/to/your/private-key.key; # Lock down TLS settings for security ssl_protocols TLSv1.2 TLSv1.3; ssl_ciphers HIGH:!aNULL:!MD5; # Forward all traffic to Varnish on port 6081 location / { proxy_pass http://127.0.0.1:6081; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; } }
Enable the site and validate the config:
sudo ln -s /etc/nginx/sites-available/your-domain.conf /etc/nginx/sites-enabled/ sudo nginx -t
Step 3: Configure Varnish
Same as the Hitch method: set Varnish to listen on port 6081, and use the same VCL config to define your HTTPS backend.
Step 4: Restart Services
sudo systemctl restart nginx sudo systemctl restart varnish
Test that everything works with a simple curl command:
curl -v https://your-domain.com
Look for X-Varnish and Via headers in the response to confirm Varnish is handling the request. You can also check Varnish logs in real-time with varnishlog to debug any issues.
- Use Let's Encrypt for free, auto-renewable SSL certificates (tools like
certbotintegrate seamlessly with both Hitch and Nginx). - To handle HTTP traffic, add a redirect from port 80 to 443 in your TLS terminator (Nginx can do this with a separate port 80 server block, or Hitch with an additional frontend).
- If you need to validate the backend's SSL certificate, set
.ssl_verify = truein your VCL and provide the appropriate CA cert file.
内容的提问来源于stack exchange,提问作者vego

