You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

OVH域名下如何用子域名映射不同端口实现应用访问?

解决方案:用反向代理实现子域名到非常规端口的转发

嘿,你遇到的这个问题太典型了——反向代理就是专门解决这类场景的神器,完全不用额外公网IP,就能把所有子域名的HTTPS流量(443端口)转发到对应应用的非常规端口上。下面给你详细拆解具体怎么做:

第一步:先搞定子域名解析

不管OVH能不能指定端口,先把所有需要的子域名(git.domain.com、sgbd.domain.com、cloud.domain.com、website.domain.com)都解析到你的公网IP上,和主域名domain.com的解析记录一致就行。后续的端口转发逻辑交给反向代理服务器处理。

第二步:在服务器上部署反向代理工具

推荐两个常用工具,选一个你顺手的就行:

选项1:Nginx(功能强大,生态成熟)

  1. 先在你的服务器上安装Nginx(根据操作系统用对应包管理器,比如Ubuntu用apt install nginx,CentOS用yum install nginx)。
  2. 为每个子域名配置反向代理规则:
    打开Nginx配置目录(通常是/etc/nginx/sites-available/),新建配置文件domain-proxy.conf,内容如下:
    # Git服务反向代理
    server {
        listen 443 ssl;
        server_name git.domain.com;
    
        # SSL证书路径(后续会说明获取方式)
        ssl_certificate /etc/letsencrypt/live/domain.com/fullchain.pem;
        ssl_certificate_key /etc/letsencrypt/live/domain.com/privkey.pem;
    
        location / {
            proxy_pass http://localhost:50000; # 转发到Git服务端口
            proxy_set_header Host $host;
            proxy_set_header X-Real-IP $remote_addr;
            proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
            proxy_set_header X-Forwarded-Proto $scheme;
        }
    }
    
    # SGBD服务反向代理
    server {
        listen 443 ssl;
        server_name sgbd.domain.com;
    
        ssl_certificate /etc/letsencrypt/live/domain.com/fullchain.pem;
        ssl_certificate_key /etc/letsencrypt/live/domain.com/privkey.pem;
    
        location / {
            proxy_pass http://localhost:55000; # 转发到SGBD服务端口
            proxy_set_header Host $host;
            proxy_set_header X-Real-IP $remote_addr;
            proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
            proxy_set_header X-Forwarded-Proto $scheme;
        }
    }
    
    # Cloud服务反向代理
    server {
        listen 443 ssl;
        server_name cloud.domain.com;
    
        ssl_certificate /etc/letsencrypt/live/domain.com/fullchain.pem;
        ssl_certificate_key /etc/letsencrypt/live/domain.com/privkey.pem;
    
        location / {
            proxy_pass http://localhost:60000; # 转发到Cloud服务端口
            proxy_set_header Host $host;
            proxy_set_header X-Real-IP $remote_addr;
            proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
            proxy_set_header X-Forwarded-Proto $scheme;
        }
    }
    
    # 主网站服务反向代理
    server {
        listen 443 ssl;
        server_name domain.com;
    
        ssl_certificate /etc/letsencrypt/live/domain.com/fullchain.pem;
        ssl_certificate_key /etc/letsencrypt/live/domain.com/privkey.pem;
    
        location / {
            proxy_pass http://localhost:65000; # 转发到主网站端口
            proxy_set_header Host $host;
            proxy_set_header X-Real-IP $remote_addr;
            proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
            proxy_set_header X-Forwarded-Proto $scheme;
        }
    }
    
  3. 启用配置:创建软链接到sites-enabled目录(ln -s /etc/nginx/sites-available/domain-proxy.conf /etc/nginx/sites-enabled/),测试配置合法性(nginx -t),没问题就重启Nginx(systemctl restart nginx)。

选项2:Caddy(自动管理SSL,配置极简)

如果你不想折腾证书和复杂配置,Caddy是绝佳选择,它会自动申请和续期Let's Encrypt证书:

  1. 安装Caddy(比如Ubuntu用apt install caddy)。
  2. 编辑Caddyfile(通常在/etc/caddy/Caddyfile),内容如下:
    git.domain.com {
        reverse_proxy localhost:50000
    }
    
    sgbd.domain.com {
        reverse_proxy localhost:55000
    }
    
    cloud.domain.com {
        reverse_proxy localhost:60000
    }
    
    domain.com {
        reverse_proxy localhost:65000
    }
    
  3. 重启Caddy(systemctl restart caddy),它会自动为所有子域名申请SSL证书,无需手动操作。

第三步:获取SSL证书(针对Nginx用户)

推荐用Let's Encrypt的免费通配符证书(覆盖所有子域名),用Certbot工具申请:

  1. 安装Certbot和Nginx插件:apt install certbot python3-certbot-nginx(Ubuntu)。
  2. 申请通配符证书:certbot certonly --manual --preferred-challenges=dns -d *.domain.com -d domain.com,按照提示在OVH域名解析中添加TXT记录完成验证,证书生成后路径默认是/etc/letsencrypt/live/domain.com/。
  3. 测试自动续期:certbot renew --dry-run,Certbot默认会自动续期证书。

关键注意事项

  • 确保服务器本地防火墙允许443端口(路由器已转发,但服务器内部也要开放)。
  • 把所有应用的监听地址改成localhost(而非0.0.0.0),让应用仅在服务器内部可见,避免直接暴露公网,提升安全性。
  • 如果应用本身支持HTTPS,也可将proxy_pass改为https://localhost:xxxx,但通常让反向代理统一处理HTTPS更省心。

配置完成后,你就能直接通过git.domain.com、sgbd.domain.com等子域名访问对应应用,不用再输入端口号,且所有流量走443端口,不会被大多数防火墙拦截。

内容的提问来源于stack exchange,提问作者M. Ozn

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.15 06:52:04