Nginx部署Django站点启用SSL后URL及静态资源无法访问
Hey there, let's work through this frustrating issue you're having—switching your Django site to HTTPS with Let's Encrypt/Certbot should be smooth, but those 503s and broken static assets are definitely a pain. Here's a step-by-step breakdown of what to check and fix:
1. Audit Your Nginx Configuration First
Certbot automatically modifies Nginx configs, and sometimes it can overwrite or break your existing Django proxy settings. Let's start here:
- Open your site's Nginx config file (usually in
/etc/nginx/sites-available/your-site.conf) and verify two critical sections:- Reverse Proxy to Django: Make sure the HTTPS
serverblock includes a validproxy_passdirective pointing to your backend (Gunicorn/UWSGI, typicallyhttp://127.0.0.1:8000). Also confirm you have these header settings—they help Django process requests correctly:location / { proxy_pass http://127.0.0.1:8000; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; } - Static Assets Handling: Ensure the HTTPS block has a
location /static/rule that matches your DjangoSTATIC_ROOTpath, and that Nginx has access to those files:location /static/ { root /path/to/your/django/project; expires 30d; add_header Cache-Control "public, max-age=2592000"; }
- Reverse Proxy to Django: Make sure the HTTPS
- Test your Nginx config for syntax errors with
sudo nginx -t. If it passes, restart Nginx:sudo systemctl restart nginx
2. Verify Your Backend Service (Gunicorn/UWSGI) is Running
503 errors almost always mean Nginx can't reach your Django backend. Let's confirm it's up and healthy:
- Check the service status:
sudo systemctl status gunicorn(replace with your service name if using UWSGI). If it's notactive (running), start it withsudo systemctl start gunicornand enable auto-start on boot:sudo systemctl enable gunicorn - Dig into backend logs (usually in
/var/log/gunicorn/or a path you configured) to look for errors—common issues include port conflicts, missing dependencies, or permission problems preventing Django from loading. - Test the backend directly: Run
curl http://127.0.0.1:8000on your server. If this returns an error, the problem is with Django itself, not Nginx/HTTPS—fix that first before moving on.
3. Check Certbot's Redirect Rules
Certbot adds HTTP-to-HTTPS redirects by default, and sometimes these can cause unexpected issues:
- Look for a
return 301 https://$host$request_uri;line in your HTTPserverblock. Make sure it's not creating a redirect loop (check browser dev tools > Network tab to see request status codes). - For testing, temporarily comment out the redirect rule and access the HTTPS URL directly to rule out redirect-related problems.
4. Fix Static Asset Loading Issues
If static files still won't load after fixing the 503s, focus on these checks:
- Re-run
python manage.py collectstatic—this ensures all static files are copied to yourSTATIC_ROOTdirectory, which Nginx serves directly. - Verify file permissions: The Nginx user (usually
www-data) needs read access to your static files. Runsudo chown -R www-data:www-data /path/to/your/static/rootto fix permissions. - Check browser dev tools for specific errors: A 404 means your Nginx
location /static/path is wrong; a 403 points to permission issues.
5. Rule Out Caching Problems
The "sometimes works after refresh" behavior hints at caching:
- Clear your browser cache or use incognito mode to eliminate client-side caching issues.
- Check if Nginx has any error-page caching configured—temporarily comment out cache directives to test if that resolves the intermittent 503s.
内容的提问来源于stack exchange,提问作者Nikhil Khandelwal

