You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何使用Let's Encrypt保护经Nginx代理的S3静态站点?

Securing Proxied S3 Static Sites with Let's Encrypt

Hey there! Let's break down how to get SSL certificates from Let's Encrypt for all your Nginx-proxied S3 static sites. This setup will get you encrypted HTTPS connections, automatic certificate renewal, and keep your sites secure.

Step 1: Install Certbot & the Nginx Plugin

First, you'll need Certbot (the official Let's Encrypt tool) and its Nginx plugin, which handles most of the configuration heavy lifting for you.

For Ubuntu/Debian-based systems:

sudo apt update
sudo apt install certbot python3-certbot-nginx

For CentOS/RHEL-based systems:

sudo dnf install certbot python3-certbot-nginx

Step 2: Prepare Your Nginx Configuration

Before grabbing certificates, make sure each of your domain's Nginx server blocks (for port 80/HTTP) is set up to allow Let's Encrypt's validation requests. Let's Encrypt uses the HTTP-01 challenge to verify you own the domain, which requires access to the /.well-known/acme-challenge/ path.

Here's a sample HTTP server block for one of your domains:

server {
    listen 80;
    server_name your-domain.com www.your-domain.com;

    # Allow ACME challenge files to be accessed
    location /.well-known/acme-challenge/ {
        root /var/www/html;
        allow all;
    }

    # Proxy all other traffic to your S3 bucket's public URL
    location / {
        proxy_pass https://your-s3-bucket-name.s3.amazonaws.com/;
        proxy_set_header Host your-s3-bucket-name.s3.amazonaws.com;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;
    }
}
  • Make sure /var/www/html exists (create it with sudo mkdir -p /var/www/html if not) and has proper permissions (sudo chown www-data:www-data /var/www/html).
  • Repeat this server block for every domain you want to secure, updating the server_name and proxy_pass values accordingly.

After updating your config, test it for errors and reload Nginx:

sudo nginx -t
sudo systemctl reload nginx

Step 3: Obtain SSL Certificates

Now use Certbot's Nginx plugin to fetch and install certificates for your domains.

For individual domains:

sudo certbot --nginx -d your-domain.com -d www.your-domain.com

Add additional -d flags for every subdomain or alias you need (e.g., -d blog.your-domain.com).

For wildcard certificates (covers all subdomains of a root domain):

If you manage multiple subdomains under a single root domain, a wildcard certificate will simplify things. You'll need to use the DNS-01 challenge here (since HTTP-01 can't validate wildcards). If you use AWS Route 53 for DNS, use this command:

sudo certbot certonly --dns-route53 -d *.your-domain.com -d your-domain.com

Certbot will automatically create the required DNS records to validate your domain ownership.

When prompted:

  • Enter your email address for renewal reminders.
  • Agree to the terms of service.
  • Choose whether to share your email with the Electronic Frontier Foundation (optional).
  • Select whether to redirect all HTTP traffic to HTTPS (recommended—choose option 2).

Step 4: Verify the Setup

After Certbot finishes, restart Nginx to apply the changes:

sudo systemctl restart nginx

Visit your domain in a browser—you should see a green padlock indicating a valid SSL certificate. You can also use tools like openssl s_client -connect your-domain.com:443 to check certificate details.

Step 5: Set Up Automatic Certificate Renewal

Let's Encrypt certificates expire after 90 days, but Certbot automatically sets up a systemd timer or cron job to renew them. Test the renewal process with a dry run to make sure everything works:

sudo certbot renew --dry-run

If the dry run succeeds, you're all set—Certbot will handle renewals in the background automatically.

Key Notes

  • Ensure your S3 bucket's public URL uses HTTPS (https://your-bucket.s3.amazonaws.com) to avoid unencrypted traffic between Nginx and S3.
  • If you have firewall rules, make sure ports 80 (for HTTP validation) and 443 (for HTTPS traffic) are open to the internet.
  • For non-Route 53 DNS providers, Certbot has plugins for most major services—check the Certbot docs for your provider's specific plugin.

内容的提问来源于stack exchange,提问作者user5431121

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.15 03:45:39