You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何配置WPEngine对接DigitalOcean与Nginx,实现通配符域名SSL部署

Got it, let's walk through this step by step—you've got WP Engine handling your main .com WordPress sites, and a DigitalOcean Droplet running a Dockerized app behind Nginx. You want wildcard subdomains like test.company.com pointing to that Droplet with proper SSL, right? Here's exactly how to make that happen:

1. Update Your Domain's DNS Records

First, you need to tell the internet that all *.company.com subdomains should point to your DigitalOcean Droplet. Just make sure you don't mess with your main company.com records (those stay pointed at WP Engine).

  • Log into your domain registrar's DNS management dashboard.
  • Add a wildcard A record: Set the host to *.company.com and point it to your Droplet's public IPv4 address.
  • (Optional) If you use IPv6, add a corresponding AAAA record for *.company.com.
  • Wait 5-15 minutes for DNS changes to propagate. You can verify with this command:
    dig *.company.com +short
    
    It should return your Droplet's IP.
2. Configure Nginx as a Reverse Proxy

Your Nginx instance needs to handle incoming wildcard domain requests and forward them to your Dockerized app. Here's how to set that up:

First, SSH into your Droplet:

ssh root@your-droplet-public-ip

Create a new Nginx config file (we'll use wildcard-company.conf as an example):

nano /etc/nginx/sites-available/wildcard-company.conf

Paste this config (replace YOUR_DOCKER_APP_PORT with the port your app is listening on inside/outside Docker):

# Redirect all HTTP traffic to HTTPS
server {
    listen 80;
    server_name *.company.com;
    return 301 https://$host$request_uri;
}

# Handle HTTPS traffic for wildcard subdomains
server {
    listen 443 ssl http2;
    server_name *.company.com;

    # SSL cert paths (we'll generate these next)
    ssl_certificate /etc/letsencrypt/live/company.com/fullchain.pem;
    ssl_certificate_key /etc/letsencrypt/live/company.com/privkey.pem;

    # Hardened SSL settings
    ssl_protocols TLSv1.2 TLSv1.3;
    ssl_ciphers HIGH:!aNULL:!MD5;
    ssl_prefer_server_ciphers on;

    # Forward requests to your Docker app
    location / {
        proxy_pass http://localhost:YOUR_DOCKER_APP_PORT;
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;
    }
}

Save and exit the editor, then enable the config and restart Nginx:

ln -s /etc/nginx/sites-available/wildcard-company.conf /etc/nginx/sites-enabled/
nginx -t # Check for config errors
systemctl restart nginx
3. Generate a Wildcard SSL Certificate with Let's Encrypt

Wildcard certificates require a DNS challenge (since HTTP challenges can't cover all subdomains). We'll use Certbot for this—here's how:

First, install Certbot and the appropriate DNS plugin (replace with your domain registrar's plugin if you don't use Cloudflare):

apt update && apt install certbot python3-certbot-dns-cloudflare

Create a secure credentials file for your DNS provider (example for Cloudflare):

mkdir -p /root/.secrets/certbot
nano /root/.secrets/certbot/cloudflare.ini

Add your Cloudflare credentials:

dns_cloudflare_email = your-cloudflare-login-email@example.com
dns_cloudflare_api_key = your-cloudflare-global-api-key

Lock down the file permissions to keep it secure:

chmod 600 /root/.secrets/certbot/cloudflare.ini

Now request the wildcard certificate:

certbot certonly --dns-cloudflare --dns-cloudflare-credentials /root/.secrets/certbot/cloudflare.ini -d *.company.com -d company.com

Certbot will automatically create DNS records to verify ownership, then generate your certificate. To make sure auto-renewal works, run a dry test:

certbot renew --dry-run
4. Verify Docker App Connectivity

Double-check that your Docker app is reachable from Nginx:

curl http://localhost:YOUR_DOCKER_APP_PORT

If you get a response from your app, you're good to go. If not, confirm your Docker container is running and the port is mapped correctly (or if using a custom Docker network, update the proxy_pass in Nginx to point to the container's service name instead of localhost).

5. Test Your Wildcard Domain

Once DNS propagation is done, fire up a browser and visit https://test.company.com. You should see your app load with a valid, trusted SSL certificate.

Quick Tips to Avoid Headaches

  • WP Engine Isolation: Your main company.com domain should still point to WP Engine—we only modified the wildcard subdomains, so your WordPress sites won't be interrupted.
  • Droplet Firewall: Make sure your DigitalOcean Droplet's firewall allows incoming traffic on ports 80 (HTTP) and 443 (HTTPS).
  • Docker Networks: If using Docker Compose, set up a custom network so Nginx can resolve your app container by name (e.g., http://my-app:3000) instead of relying on port mapping.

内容的提问来源于stack exchange,提问作者Richard Zheng

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 08:44:55