Apache2+多Tomcat SSL配置求助:Linux服务器Kolab代理问题
Let's tackle this reverse proxy setup for your Apache + multiple Tomcat instances. The core issue here is that all three Tomcats are using the root context (ContextPath=""), so we need to add a layer of routing in Apache to direct requests to the right instance without conflicts. Here are two solid solutions, plus debugging tips to get you up and running:
Prerequisite: Enable Required Apache Modules
First, make sure you have all necessary modules enabled. Run these commands:
a2enmod proxy proxy_http proxy_ajp rewrite ssl systemctl restart apache2
Solution 1: Route by URL Path Prefixes
This approach maps different subpaths of example.com to each Tomcat instance. For example:
https://example.com/service/*→ tc1 (Web Service)https://example.com/bamboo/*→ tc2 (Bamboo)https://example.com/bitbucket/*→ tc3 (Bitbucket)
Add this configuration to your HTTPS VirtualHost (usually in /etc/apache2/sites-available/example.com-ssl.conf):
<VirtualHost *:443> ServerName example.com # Your existing SSL config (keep this as-is) SSLEngine on SSLCertificateFile /path/to/your/certificate.pem SSLCertificateKeyFile /path/to/your/private-key.pem # Route Web Service (tc1) ProxyPass /service http://localhost:8087/ ProxyPassReverse /service http://localhost:8087/ # Route Bamboo (tc2) ProxyPass /bamboo http://localhost:8085/ ProxyPassReverse /bamboo http://localhost:8085/ # Route Bitbucket (tc3) ProxyPass /bitbucket http://localhost:7990/ ProxyPassReverse /bitbucket http://localhost:7990/ # Optional: Use HTTPS to connect to Tomcat (instead of HTTP) # Uncomment the lines below if you want to encrypt traffic between Apache and Tomcat # ProxyPass /service https://localhost:8443/ # ProxyPassReverse /service https://localhost:8443/ # SSLProxyEngine On # # Disable certificate validation ONLY for testing (not recommended for production) # SSLProxyVerify none # SSLProxyCheckPeerCN off # SSLProxyCheckPeerName off # SSLProxyCheckPeerExpire off # Keep Kolab's existing routes working # Make sure Kolab's Alias/Proxy rules come BEFORE the Tomcat routes to avoid conflicts # Example: Alias /roundcube /usr/share/roundcube (adjust to your Kolab setup) # Proxy tuning (optional but helpful) ProxyTimeout 300 ProxyBufferSize 4096 </VirtualHost>
Solution 2: Route by Subdomains
If you prefer cleaner URLs (no path prefixes), use subdomains to map each Tomcat instance directly:
https://service.example.com/*→ tc1https://bamboo.example.com/*→ tc2https://bitbucket.example.com/*→ tc3
Create separate VirtualHosts for each subdomain:
# tc1 (Web Service) VirtualHost <VirtualHost *:443> ServerName service.example.com SSLEngine on SSLCertificateFile /path/to/your/certificate.pem SSLCertificateKeyFile /path/to/your/private-key.pem ProxyPass / http://localhost:8087/ ProxyPassReverse / http://localhost:8087/ </VirtualHost> # tc2 (Bamboo) VirtualHost <VirtualHost *:443> ServerName bamboo.example.com SSLEngine on SSLCertificateFile /path/to/your/certificate.pem SSLCertificateKeyFile /path/to/your/private-key.pem ProxyPass / http://localhost:8085/ ProxyPassReverse / http://localhost:8085/ </VirtualHost> # tc3 (Bitbucket) VirtualHost <VirtualHost *:443> ServerName bitbucket.example.com SSLEngine on SSLCertificateFile /path/to/your/certificate.pem SSLCertificateKeyFile /path/to/your/private-key.pem ProxyPass / http://localhost:7990/ ProxyPassReverse / http://localhost:7990/ </VirtualHost>
Note: Don't forget to update your DNS records to point each subdomain to your server's IP.
Optimize Tomcat Configuration
To ensure Tomcat generates correct URLs (avoiding broken links/redirects), update each Tomcat's server.xml Connector configuration:
<!-- For tc1, adjust port to match your setup --> <Connector port="8087" protocol="HTTP/1.1" connectionTimeout="20000" redirectPort="8443" address="127.0.0.1" <!-- Restrict to local access for security --> proxyName="example.com" <!-- Or your subdomain, e.g., service.example.com --> proxyPort="443" />
Bonus: Use AJP for Better Performance
For faster communication between Apache and Tomcat, use the AJP protocol instead of HTTP. Enable the AJP Connector in Tomcat's server.xml:
<Connector port="8009" protocol="AJP/1.3" redirectPort="8443" />
Then update your Apache ProxyPass lines to use ajp://localhost:8009/ instead of http://localhost:8087/.
Debugging Tips
If you're still having issues:
- Check Apache Error Logs:
Look for proxy-related errors (e.g., connection refused, invalid configuration).tail -f /var/log/apache2/error.log - Test with Curl:
Verify the response comes from the correct Tomcat instance.curl -v https://example.com/service - Firewall Check: Ensure your server's firewall allows Apache to access Tomcat's ports (8087, 8085, 7990). Since they're local, this is usually allowed by default, but double-check if you're using
ufworiptables.
内容的提问来源于stack exchange,提问作者Desperate

