如何配置WPEngine对接DigitalOcean与Nginx,实现通配符域名SSL部署
Got it, let's walk through this step by step—you've got WP Engine handling your main .com WordPress sites, and a DigitalOcean Droplet running a Dockerized app behind Nginx. You want wildcard subdomains like test.company.com pointing to that Droplet with proper SSL, right? Here's exactly how to make that happen:
First, you need to tell the internet that all *.company.com subdomains should point to your DigitalOcean Droplet. Just make sure you don't mess with your main company.com records (those stay pointed at WP Engine).
- Log into your domain registrar's DNS management dashboard.
- Add a wildcard A record: Set the host to
*.company.comand point it to your Droplet's public IPv4 address. - (Optional) If you use IPv6, add a corresponding AAAA record for
*.company.com. - Wait 5-15 minutes for DNS changes to propagate. You can verify with this command:
It should return your Droplet's IP.dig *.company.com +short
Your Nginx instance needs to handle incoming wildcard domain requests and forward them to your Dockerized app. Here's how to set that up:
First, SSH into your Droplet:
ssh root@your-droplet-public-ip
Create a new Nginx config file (we'll use wildcard-company.conf as an example):
nano /etc/nginx/sites-available/wildcard-company.conf
Paste this config (replace YOUR_DOCKER_APP_PORT with the port your app is listening on inside/outside Docker):
# Redirect all HTTP traffic to HTTPS server { listen 80; server_name *.company.com; return 301 https://$host$request_uri; } # Handle HTTPS traffic for wildcard subdomains server { listen 443 ssl http2; server_name *.company.com; # SSL cert paths (we'll generate these next) ssl_certificate /etc/letsencrypt/live/company.com/fullchain.pem; ssl_certificate_key /etc/letsencrypt/live/company.com/privkey.pem; # Hardened SSL settings ssl_protocols TLSv1.2 TLSv1.3; ssl_ciphers HIGH:!aNULL:!MD5; ssl_prefer_server_ciphers on; # Forward requests to your Docker app location / { proxy_pass http://localhost:YOUR_DOCKER_APP_PORT; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; } }
Save and exit the editor, then enable the config and restart Nginx:
ln -s /etc/nginx/sites-available/wildcard-company.conf /etc/nginx/sites-enabled/ nginx -t # Check for config errors systemctl restart nginx
Wildcard certificates require a DNS challenge (since HTTP challenges can't cover all subdomains). We'll use Certbot for this—here's how:
First, install Certbot and the appropriate DNS plugin (replace with your domain registrar's plugin if you don't use Cloudflare):
apt update && apt install certbot python3-certbot-dns-cloudflare
Create a secure credentials file for your DNS provider (example for Cloudflare):
mkdir -p /root/.secrets/certbot nano /root/.secrets/certbot/cloudflare.ini
Add your Cloudflare credentials:
dns_cloudflare_email = your-cloudflare-login-email@example.com dns_cloudflare_api_key = your-cloudflare-global-api-key
Lock down the file permissions to keep it secure:
chmod 600 /root/.secrets/certbot/cloudflare.ini
Now request the wildcard certificate:
certbot certonly --dns-cloudflare --dns-cloudflare-credentials /root/.secrets/certbot/cloudflare.ini -d *.company.com -d company.com
Certbot will automatically create DNS records to verify ownership, then generate your certificate. To make sure auto-renewal works, run a dry test:
certbot renew --dry-run
Double-check that your Docker app is reachable from Nginx:
curl http://localhost:YOUR_DOCKER_APP_PORT
If you get a response from your app, you're good to go. If not, confirm your Docker container is running and the port is mapped correctly (or if using a custom Docker network, update the proxy_pass in Nginx to point to the container's service name instead of localhost).
Once DNS propagation is done, fire up a browser and visit https://test.company.com. You should see your app load with a valid, trusted SSL certificate.
Quick Tips to Avoid Headaches
- WP Engine Isolation: Your main
company.comdomain should still point to WP Engine—we only modified the wildcard subdomains, so your WordPress sites won't be interrupted. - Droplet Firewall: Make sure your DigitalOcean Droplet's firewall allows incoming traffic on ports 80 (HTTP) and 443 (HTTPS).
- Docker Networks: If using Docker Compose, set up a custom network so Nginx can resolve your app container by name (e.g.,
http://my-app:3000) instead of relying on port mapping.
内容的提问来源于stack exchange,提问作者Richard Zheng

