Gunicorn无法维持持久TLS连接的问题求助
Gunicorn无法维持持久TLS连接的问题求助
我们需要编写一个能维持持久连接的Python服务器,这样新请求到来时可以复用旧连接,不用每次都创建新连接。目前我们选用了flask和gunicorn来实现这个需求。
Python代码
from flask import Flask, request, make_response, jsonify app = Flask(__name__) @app.route('/v1') def get_availability(): response = make_response("Custom Response", 204) return response @app.route('/v2') def get_ping(): response = make_response("Custom Response", 200) return response @app.errorhandler(404) def not_found(error): return jsonify({'error': 'Custom message for unavailable path'}), 404
启动Gunicorn的命令
我们用以下命令启动Python服务器:
gunicorn --keyfile key.pem --certfile cert.pem --bind 127.0.0.1:8080 app:app
测试用的Curl命令
我写了一个简单的shell脚本,里面包含两条curl命令,用来测试持久连接的复用情况:
curl -H "Connection: keep-alive" -H "Keep-Alive: timeout=5, max=100" https://127.0.0.1:8080/v1 -v -k curl -H "Connection: keep-alive" -H "Keep-Alive: timeout=5, max=100" https://127.0.0.1:8080/v2 -v -k
观察到的问题
运行脚本后能正常收到响应,但每次curl命令执行完后TLS连接都会被关闭,第二条curl并没有复用之前的连接,日志输出如下:
* Trying 127.0.0.1:8080... * Connected to 127.0.0.1 (127.0.0.1) port 8080 * ALPN: curl offers h2,http/1.1 * TLSv1.3 (OUT), TLS handshake, Client hello (1): * TLSv1.3 (IN), TLS handshake, Server hello (2): * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): * TLSv1.3 (IN), TLS handshake, Certificate (11): * TLSv1.3 (IN), TLS handshake, CERT verify (15): * TLSv1.3 (IN), TLS handshake, Finished (20): * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): * TLSv1.3 (OUT), TLS handshake, Finished (20): * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519 / RSASSA-PSS * ALPN: server did not agree on a protocol. Uses default. * Server certificate: * subject: C=XX; L=Default City; O=Default Company Ltd * start date: Jan 8 22:43:00 2025 GMT * expire date: Jan 8 22:43:00 2026 GMT * issuer: C=XX; L=Default City; O=Default Company Ltd * SSL certificate verify result: self-signed certificate (18), continuing anyway. * Certificate level 0: Public key type RSA (4096/152 Bits/secBits), signed using sha256WithRSAEncryption * using HTTP/1.x > GET /v1 HTTP/1.1 > Host: 127.0.0.1:8080 > User-Agent: curl/8.5.0 > Accept: */* > Connection: keep-alive > Keep-Alive: timeout=5, max=100 > * TLSv1.3 (IN), TLS handshake, Newsession Ticket (4): * TLSv1.3 (IN), TLS handshake, Newsession Ticket (4): * old SSL session ID is stale, removing < HTTP/1.1 200 OK < Server: gunicorn < Date: Thu, 09 Jan 2025 18:09:21 GMT < Connection: close < Content-Type: text/html; charset=utf-8 < Content-Length: 15 < * Closing connection * TLSv1.3 (OUT), TLS alert, close notify (256): Custom Response* Trying 127.0.0.1:8080... * Connected to 127.0.0.1 (127.0.0.1) port 8080 * ALPN: curl offers h2,http/1.1 * TLSv1.3 (OUT), TLS handshake, Client hello (1): * TLSv1.3 (IN), TLS handshake, Server hello (2): * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): * TLSv1.3 (IN), TLS handshake, Certificate (11): * TLSv1.3 (IN), TLS handshake, CERT verify (15): * TLSv1.3 (IN), TLS handshake, Finished (20): * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1): * TLSv1.3 (OUT), TLS handshake, Finished (20): * SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519 / RSASSA-PSS * ALPN: server did not agree on a protocol. Uses default. * Server certificate: * subject: C=XX; L=Default City; O=Default Company Ltd * start date: Jan 8 22:43:00 2025 GMT * expire date: Jan 8 22:43:00 2026 GMT * issuer: C=XX; L=Default City; O=Default Company Ltd * SSL certificate verify result: self-signed certificate (18), continuing anyway. * Certificate level 0: Public key type RSA (4096/152 Bits/secBits), signed using sha256WithRSAEncryption * using HTTP/1.x > GET /v1 HTTP/1.1 > Host: 127.0.0.1:8080 > User-Agent: curl/8.5.0 > Accept: */* > Connection: keep-alive > Keep-Alive: timeout=5, max=100 > * TLSv1.3 (IN), TLS handshake, Newsession Ticket (4): * TLSv1.3 (IN), TLS handshake, Newsession Ticket (4): * old SSL session ID is stale, removing < HTTP/1.1 200 OK < Server: gunicorn < Date: Thu, 09 Jan 2025 18:09:21 GMT < Connection: close < Content-Type: text/html; charset=utf-8 < Content-Length: 15 < * Closing connection * TLSv1.3 (OUT), TLS alert, close notify (256):
我原本以为gunicorn会自动维持持久连接,但现在它每次请求后都会返回Connection: close头并关闭连接。有没有办法配置它来维持持久的TLS连接呢?
备注:内容来源于stack exchange,提问作者kadina
相关产品推荐
相关产品推荐

