You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Docker环境下Spring Boot应用通过HTTPS部署于Nginx后方的配置问询

Convert Nginx Reverse Proxy to HTTPS for Your Spring Boot Docker App

Got it, let's walk through converting your existing HTTP reverse proxy setup to HTTPS. Here's a step-by-step guide covering both production-ready and testing certificate options:

1. Get an SSL Certificate

First, you need a valid SSL certificate. Pick the option that fits your use case:

Option A: Production-Grade with Let's Encrypt (Free)

Use Certbot to generate trusted certificates. If you prefer containerized tools, run this command (replace <your-domain> with your actual domain name):

docker run -it --rm -v /etc/letsencrypt:/etc/letsencrypt -v /var/lib/letsencrypt:/var/lib/letsencrypt certbot/certbot certonly --standalone -d <your-domain>

This saves your certificates in /etc/letsencrypt/live/<your-domain>/ (you'll need fullchain.pem and privkey.pem later).

Option B: Self-Signed Certificate (Testing Only)

For local testing, generate a self-signed cert with OpenSSL:

openssl req -x509 -newkey rsa:4096 -keyout key.pem -out cert.pem -days 365 -nodes

This creates key.pem (private key) and cert.pem (certificate) in your current directory. Note: Browsers will flag this as untrusted—only use it for testing!

2. Update Your Nginx Configuration

Replace your existing Nginx config with this HTTPS-enabled version. Adjust paths and server names to match your setup:

# HTTPS Server Block
server {
    server_name <your-domain-or-ip>;
    listen 443 ssl;

    # Paths to your SSL certs (adjust based on which option you chose)
    ssl_certificate /etc/letsencrypt/live/<your-domain>/fullchain.pem;  # Let's Encrypt path
    ssl_certificate_key /etc/letsencrypt/live/<your-domain>/privkey.pem;  # Let's Encrypt path
    # For self-signed:
    # ssl_certificate /etc/nginx/certs/cert.pem;
    # ssl_certificate_key /etc/nginx/certs/key.pem;

    # Pass HTTPS context to Spring Boot (recommended)
    location / {
        proxy_pass http://172.17.0.2:8080/;
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;  # Tells Spring Boot it's behind HTTPS
    }
}

# Redirect HTTP to HTTPS (user-friendly optional step)
server {
    listen 80;
    server_name <your-domain-or-ip>;
    return 301 https://$host$request_uri;
}

3. Update Your Nginx Docker Setup

You need to expose port 443 and mount your certificate files into the Nginx container so it can access them.

Using docker run

# For Let's Encrypt:
docker run -d -p 80:80 -p 443:443 -v /path/to/your/nginx.conf:/etc/nginx/conf.d/default.conf -v /etc/letsencrypt:/etc/letsencrypt nginx

# For self-signed certs:
docker run -d -p 80:80 -p 443:443 -v /path/to/your/nginx.conf:/etc/nginx/conf.d/default.conf -v /path/to/your/certs:/etc/nginx/certs nginx

Using docker-compose (Cleaner for Persistent Setups)

Create a docker-compose.yml file:

version: '3.8'
services:
  nginx:
    image: nginx:latest
    ports:
      - "80:80"
      - "443:443"
    volumes:
      - ./nginx.conf:/etc/nginx/conf.d/default.conf
      # For Let's Encrypt:
      - /etc/letsencrypt:/etc/letsencrypt
      # For self-signed:
      # - ./certs:/etc/nginx/certs
    restart: unless-stopped

Run it with docker-compose up -d.

4. Verify Everything Works

  • Open your browser and go to https://<your-domain-or-ip>—you should see your Spring Boot app loaded over a secure connection.
  • Test the HTTP redirect by going to http://<your-domain-or-ip>—it should automatically send you to the HTTPS version.
  • If using Let's Encrypt, confirm the certificate is trusted (no browser warnings).

Quick Tips

  • Ensure your firewall allows incoming traffic on port 443.
  • For Let's Encrypt, set up auto-renewal (add a cron job or use Certbot's Docker renew command to avoid expired certs).
  • The X-Forwarded-Proto header is critical if your Spring Boot app generates URLs (it ensures links use HTTPS instead of HTTP).

内容的提问来源于stack exchange,提问作者dane131

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.25 07:41:48