AWS EC2 Flask应用配置Let's Encrypt SSL遇阻求助
Hey there! Let's work through why you're hitting snags setting up SSL with Let's Encrypt for your <blabla>.ga domain. First off, the letsencrypt-auto tool you're using is deprecated—that's probably part of the problem. Let's switch to Certbot, the official supported tool, and walk through the correct setup for your Flask server on EC2.
Step 1: Replace letsencrypt-auto with Certbot
First, clean up the old tool and install Certbot (commands tailored to Amazon Linux 2; adjust for Ubuntu/Debian if needed):
# Remove the outdated letsencrypt directory sudo rm -rf /opt/letsencrypt # Install Certbot and the Apache plugin (we'll use this for reverse proxy + SSL setup) sudo yum install certbot python3-certbot-apache -y # For Ubuntu/Debian, use these commands instead: # sudo apt update && sudo apt install certbot python3-certbot-apache -y
Step 2: Ensure Your Domain is Reachable Over HTTP
Let's Encrypt uses HTTP-01 validation, which requires your domain to respond on port 80. Since you're running Flask (usually on port 5000 by default), you need a reverse proxy (like Apache) to forward port 80 traffic to Flask.
Configure Apache Reverse Proxy
Create a virtual host config for your domain:
sudo nano /etc/httpd/conf.d/<blabla>.ga.conf
Paste this config (update the Flask port if you're using something other than 5000):
<VirtualHost *:80> ServerName <blabla>.ga # Forward traffic to your Flask server ProxyPass / http://127.0.0.1:5000/ ProxyPassReverse / http://127.0.0.1:5000/ </VirtualHost>
Save the file, then restart Apache:
sudo systemctl restart httpd
Verify EC2 Security Groups
Double-check your EC2 security group allows inbound traffic on:
- Port 80 (HTTP) for Let's Encrypt validation
- Port 443 (HTTPS) for the secured site
- Port 5000 (or your Flask port) if you need direct access (not strictly required for SSL setup)
Step 3: Obtain Your SSL Certificate
Run Certbot to automatically get and install the certificate:
sudo certbot --apache -d <blabla>.ga
Follow the prompts:
- Enter your email address for renewal reminders
- Agree to the terms of service
- Choose whether to share your email with the Electronic Frontier Foundation
- Certbot will automatically configure Apache to use SSL and set up auto-renewal
Step 4: Verify Everything Works
- Visit
https://<blabla>.gain your browser—you should see the secure lock icon - Test auto-renewal (this is a dry run, no changes will be made):
sudo certbot renew --dry-run
Troubleshooting Common Issues
If you still hit validation errors:
- Check DNS Propagation: Run
nslookup <blabla>.gato confirm the domain is pointing to your EC2's public IP, and that the Route53 nameservers are active (it can take up to 24 hours for DNS changes to propagate, though usually much faster) - Firewall Checks: Ensure EC2's internal firewall (like
iptables) isn't blocking ports 80 or 443 - Flask Server Status: Make sure your Flask app is running and responding to requests on
http://127.0.0.1:5000
内容的提问来源于stack exchange,提问作者Anum Sheraz

