You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Gunicorn无法维持持久TLS连接的问题求助

Gunicorn无法维持持久TLS连接的问题求助

我们需要编写一个能维持持久连接的Python服务器,这样新请求到来时可以复用旧连接,不用每次都创建新连接。目前我们选用了flask和gunicorn来实现这个需求。

Python代码

from flask import Flask, request, make_response, jsonify

app = Flask(__name__)

@app.route('/v1')
def get_availability():
   response = make_response("Custom Response", 204)
   return response

@app.route('/v2')
def get_ping():
   response = make_response("Custom Response", 200)
   return response

@app.errorhandler(404)
def not_found(error):
   return jsonify({'error': 'Custom message for unavailable path'}), 404

启动Gunicorn的命令

我们用以下命令启动Python服务器:

gunicorn --keyfile key.pem --certfile cert.pem --bind 127.0.0.1:8080 app:app

测试用的Curl命令

我写了一个简单的shell脚本,里面包含两条curl命令,用来测试持久连接的复用情况:

curl -H "Connection: keep-alive" -H "Keep-Alive: timeout=5, max=100" https://127.0.0.1:8080/v1 -v -k

curl -H "Connection: keep-alive" -H "Keep-Alive: timeout=5, max=100" https://127.0.0.1:8080/v2 -v -k

观察到的问题

运行脚本后能正常收到响应,但每次curl命令执行完后TLS连接都会被关闭,第二条curl并没有复用之前的连接,日志输出如下:

*   Trying 127.0.0.1:8080...
* Connected to 127.0.0.1 (127.0.0.1) port 8080
* ALPN: curl offers h2,http/1.1
* TLSv1.3 (OUT), TLS handshake, Client hello (1):
* TLSv1.3 (IN), TLS handshake, Server hello (2):
* TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):
* TLSv1.3 (IN), TLS handshake, Certificate (11):
* TLSv1.3 (IN), TLS handshake, CERT verify (15):
* TLSv1.3 (IN), TLS handshake, Finished (20):
* TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):
* TLSv1.3 (OUT), TLS handshake, Finished (20):
* SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519 / RSASSA-PSS
* ALPN: server did not agree on a protocol. Uses default.
* Server certificate:
*  subject: C=XX; L=Default City; O=Default Company Ltd
*  start date: Jan  8 22:43:00 2025 GMT
*  expire date: Jan  8 22:43:00 2026 GMT
*  issuer: C=XX; L=Default City; O=Default Company Ltd
*  SSL certificate verify result: self-signed certificate (18), continuing anyway.
*   Certificate level 0: Public key type RSA (4096/152 Bits/secBits), signed using sha256WithRSAEncryption
* using HTTP/1.x
> GET /v1 HTTP/1.1
> Host: 127.0.0.1:8080
> User-Agent: curl/8.5.0
> Accept: */*
> Connection: keep-alive
> Keep-Alive: timeout=5, max=100
> 
* TLSv1.3 (IN), TLS handshake, Newsession Ticket (4):
* TLSv1.3 (IN), TLS handshake, Newsession Ticket (4):
* old SSL session ID is stale, removing
< HTTP/1.1 200 OK
< Server: gunicorn
< Date: Thu, 09 Jan 2025 18:09:21 GMT
< Connection: close
< Content-Type: text/html; charset=utf-8
< Content-Length: 15
< 
* Closing connection
* TLSv1.3 (OUT), TLS alert, close notify (256):
Custom Response*   Trying 127.0.0.1:8080...
* Connected to 127.0.0.1 (127.0.0.1) port 8080
* ALPN: curl offers h2,http/1.1
* TLSv1.3 (OUT), TLS handshake, Client hello (1):
* TLSv1.3 (IN), TLS handshake, Server hello (2):
* TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):
* TLSv1.3 (IN), TLS handshake, Certificate (11):
* TLSv1.3 (IN), TLS handshake, CERT verify (15):
* TLSv1.3 (IN), TLS handshake, Finished (20):
* TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):
* TLSv1.3 (OUT), TLS handshake, Finished (20):
* SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / X25519 / RSASSA-PSS
* ALPN: server did not agree on a protocol. Uses default.
* Server certificate:
*  subject: C=XX; L=Default City; O=Default Company Ltd
*  start date: Jan  8 22:43:00 2025 GMT
*  expire date: Jan  8 22:43:00 2026 GMT
*  issuer: C=XX; L=Default City; O=Default Company Ltd
*  SSL certificate verify result: self-signed certificate (18), continuing anyway.
*   Certificate level 0: Public key type RSA (4096/152 Bits/secBits), signed using sha256WithRSAEncryption
* using HTTP/1.x
> GET /v1 HTTP/1.1
> Host: 127.0.0.1:8080
> User-Agent: curl/8.5.0
> Accept: */*
> Connection: keep-alive
> Keep-Alive: timeout=5, max=100
> 
* TLSv1.3 (IN), TLS handshake, Newsession Ticket (4):
* TLSv1.3 (IN), TLS handshake, Newsession Ticket (4):
* old SSL session ID is stale, removing
< HTTP/1.1 200 OK
< Server: gunicorn
< Date: Thu, 09 Jan 2025 18:09:21 GMT
< Connection: close
< Content-Type: text/html; charset=utf-8
< Content-Length: 15
< 
* Closing connection
* TLSv1.3 (OUT), TLS alert, close notify (256):

我原本以为gunicorn会自动维持持久连接,但现在它每次请求后都会返回Connection: close头并关闭连接。有没有办法配置它来维持持久的TLS连接呢?

备注:内容来源于stack exchange,提问作者kadina

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.15 03:40:26