OVH域名下如何用子域名映射不同端口实现应用访问?
解决方案:用反向代理实现子域名到非常规端口的转发
嘿,你遇到的这个问题太典型了——反向代理就是专门解决这类场景的神器,完全不用额外公网IP,就能把所有子域名的HTTPS流量(443端口)转发到对应应用的非常规端口上。下面给你详细拆解具体怎么做:
第一步:先搞定子域名解析
不管OVH能不能指定端口,先把所有需要的子域名(git.domain.com、sgbd.domain.com、cloud.domain.com、website.domain.com)都解析到你的公网IP上,和主域名domain.com的解析记录一致就行。后续的端口转发逻辑交给反向代理服务器处理。
第二步:在服务器上部署反向代理工具
推荐两个常用工具,选一个你顺手的就行:
选项1:Nginx(功能强大,生态成熟)
- 先在你的服务器上安装Nginx(根据操作系统用对应包管理器,比如Ubuntu用
apt install nginx,CentOS用yum install nginx)。 - 为每个子域名配置反向代理规则:
打开Nginx配置目录(通常是/etc/nginx/sites-available/),新建配置文件domain-proxy.conf,内容如下:# Git服务反向代理 server { listen 443 ssl; server_name git.domain.com; # SSL证书路径(后续会说明获取方式) ssl_certificate /etc/letsencrypt/live/domain.com/fullchain.pem; ssl_certificate_key /etc/letsencrypt/live/domain.com/privkey.pem; location / { proxy_pass http://localhost:50000; # 转发到Git服务端口 proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; } } # SGBD服务反向代理 server { listen 443 ssl; server_name sgbd.domain.com; ssl_certificate /etc/letsencrypt/live/domain.com/fullchain.pem; ssl_certificate_key /etc/letsencrypt/live/domain.com/privkey.pem; location / { proxy_pass http://localhost:55000; # 转发到SGBD服务端口 proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; } } # Cloud服务反向代理 server { listen 443 ssl; server_name cloud.domain.com; ssl_certificate /etc/letsencrypt/live/domain.com/fullchain.pem; ssl_certificate_key /etc/letsencrypt/live/domain.com/privkey.pem; location / { proxy_pass http://localhost:60000; # 转发到Cloud服务端口 proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; } } # 主网站服务反向代理 server { listen 443 ssl; server_name domain.com; ssl_certificate /etc/letsencrypt/live/domain.com/fullchain.pem; ssl_certificate_key /etc/letsencrypt/live/domain.com/privkey.pem; location / { proxy_pass http://localhost:65000; # 转发到主网站端口 proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; } } - 启用配置:创建软链接到
sites-enabled目录(ln -s /etc/nginx/sites-available/domain-proxy.conf /etc/nginx/sites-enabled/),测试配置合法性(nginx -t),没问题就重启Nginx(systemctl restart nginx)。
选项2:Caddy(自动管理SSL,配置极简)
如果你不想折腾证书和复杂配置,Caddy是绝佳选择,它会自动申请和续期Let's Encrypt证书:
- 安装Caddy(比如Ubuntu用
apt install caddy)。 - 编辑Caddyfile(通常在
/etc/caddy/Caddyfile),内容如下:git.domain.com { reverse_proxy localhost:50000 } sgbd.domain.com { reverse_proxy localhost:55000 } cloud.domain.com { reverse_proxy localhost:60000 } domain.com { reverse_proxy localhost:65000 } - 重启Caddy(
systemctl restart caddy),它会自动为所有子域名申请SSL证书,无需手动操作。
第三步:获取SSL证书(针对Nginx用户)
推荐用Let's Encrypt的免费通配符证书(覆盖所有子域名),用Certbot工具申请:
- 安装Certbot和Nginx插件:
apt install certbot python3-certbot-nginx(Ubuntu)。 - 申请通配符证书:
certbot certonly --manual --preferred-challenges=dns -d *.domain.com -d domain.com,按照提示在OVH域名解析中添加TXT记录完成验证,证书生成后路径默认是/etc/letsencrypt/live/domain.com/。 - 测试自动续期:
certbot renew --dry-run,Certbot默认会自动续期证书。
关键注意事项
- 确保服务器本地防火墙允许443端口(路由器已转发,但服务器内部也要开放)。
- 把所有应用的监听地址改成
localhost(而非0.0.0.0),让应用仅在服务器内部可见,避免直接暴露公网,提升安全性。 - 如果应用本身支持HTTPS,也可将
proxy_pass改为https://localhost:xxxx,但通常让反向代理统一处理HTTPS更省心。
配置完成后,你就能直接通过git.domain.com、sgbd.domain.com等子域名访问对应应用,不用再输入端口号,且所有流量走443端口,不会被大多数防火墙拦截。
内容的提问来源于stack exchange,提问作者M. Ozn
相关产品推荐
相关产品推荐

