You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何将AWS EC2实例从HTTP重定向至HTTPS?Jenkins证书配置故障

Fixing Jenkins HTTPS & Redirect Issues on AWS EC2

Let’s tackle your problems one by one—first fixing that annoying "not secure" certificate warning, then setting up reliable HTTP-to-HTTPS redirects for your Jenkins instance.

1. Resolve the "Not Secure" Certificate Warning

The error you’re seeing is almost certainly because the self-signed certificate from the tutorial isn’t trusted by browsers by default. Here are two solutions:

This is the best approach for public-facing instances:

  • Step 1: Install Certbot
    On Ubuntu/Debian:
    sudo apt update && sudo apt install certbot -y
    
    On Amazon Linux 2/RHEL/CentOS:
    sudo amazon-linux-extras install epel -y && sudo yum install certbot -y
    
  • Step 2: Validate Your Domain
    First, confirm your domain myinstance.com points to your EC2 instance’s public (or elastic) IP. Temporarily stop Jenkins to free up port 80:
    sudo systemctl stop jenkins
    
    Run Certbot to generate the trusted certificate:
    sudo certbot certonly --standalone -d myinstance.com
    
    Follow the prompts to verify domain ownership.
  • Step 3: Configure Jenkins to Use the Cert
    Open your Jenkins config file (location varies by OS):
    • Ubuntu/Debian: /etc/default/jenkins
    • Amazon Linux/RHEL: /etc/sysconfig/jenkins
      Modify these parameters:
    # Disable default HTTP port (or keep it for redirects later)
    HTTP_PORT="-1"
    # Set HTTPS to standard port 443
    HTTPS_PORT="443"
    # Add SSL cert paths to Jenkins startup args
    JENKINS_ARGS="--httpsPort=$HTTPS_PORT --httpsCertificate=/etc/letsencrypt/live/myinstance.com/fullchain.pem --httpsPrivateKey=/etc/letsencrypt/live/myinstance.com/privkey.pem"
    
  • Step 4: Restart Jenkins
    sudo systemctl restart jenkins
    
    Visiting https://myinstance.com should now show a trusted connection.

Option B: Fix Self-Signed Cert (For Testing Only)

If you’re just testing, you can fix the trust issue:

  • Regenerate the cert with your actual domain as the Common Name (CN) (this is critical):
    keytool -genkey -keyalg RSA -alias jenkins -keystore /var/lib/jenkins/jenkins.jks -validity 3650 -keysize 2048
    
    When prompted, enter myinstance.com as the Common Name.
  • Update Jenkins to use this new keystore in your config file, then export the cert to import into your browser:
    keytool -export -alias jenkins -keystore /var/lib/jenkins/jenkins.jks -file jenkins.crt
    
  • Import jenkins.crt into your browser’s trusted root certificates store. This stops the warning but isn’t suitable for production.

2. Set Up HTTP-to-HTTPS Redirects

You have two solid options—using Jenkins directly or a reverse proxy like Nginx (more flexible for production).

Option A: Jenkins Built-In Redirect

If you want to avoid extra software:

  • Open your Jenkins config file again, set HTTP_PORT="80" (instead of -1).
  • Add this to JENKINS_ARGS:
    --redirectHttpToHttps
    
  • Restart Jenkins. Note: Jenkins needs root privileges to bind to port 80 (a privileged port <1024). If you get permission errors, use authbind to grant access, or use the Nginx method below.

This is more stable and scalable:

  • Step 1: Install Nginx
    # Ubuntu/Debian
    sudo apt install nginx -y
    # Amazon Linux/RHEL
    sudo yum install nginx -y
    
  • Step 2: Configure Nginx
    Create a config file:
    • Ubuntu/Debian: /etc/nginx/sites-available/jenkins
    • Amazon Linux/RHEL: /etc/nginx/conf.d/jenkins.conf
      Paste this content (adjust paths if needed):
    # Redirect all HTTP traffic to HTTPS
    server {
        listen 80;
        server_name myinstance.com;
        return 301 https://$host$request_uri;
    }
    
    # Serve Jenkins over HTTPS
    server {
        listen 443 ssl;
        server_name myinstance.com;
    
        # Use Let's Encrypt certs
        ssl_certificate /etc/letsencrypt/live/myinstance.com/fullchain.pem;
        ssl_certificate_key /etc/letsencrypt/live/myinstance.com/privkey.pem;
    
        location / {
            proxy_pass http://127.0.0.1:8080; # Default Jenkins port
            proxy_set_header Host $host;
            proxy_set_header X-Real-IP $remote_addr;
            proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
            proxy_set_header X-Forwarded-Proto $scheme;
        }
    }
    
  • Step 3: Enable & Test the Config
    For Ubuntu/Debian:
    sudo ln -s /etc/nginx/sites-available/jenkins /etc/nginx/sites-enabled/
    
    Test for config errors:
    sudo nginx -t
    
    If all is good, restart Nginx:
    sudo systemctl restart nginx
    
  • Step 4: Update Jenkins
    In your Jenkins config file, set HTTP_PORT="8080" (default) and disable HTTPS mode (HTTPS_PORT="-1"). Then go to Jenkins UI → Manage Jenkins → Configure System → Jenkins Location and set the Jenkins URL to https://myinstance.com. Also enable proxy compatibility in Manage Jenkins → Configure Global Security → check Enable proxy compatibility.

Final Checks

  • Ensure your EC2 security group allows inbound traffic on ports 80 (HTTP) and 443 (HTTPS) from your desired IP ranges.
  • If using an elastic IP for your EC2 instance, confirm your domain’s DNS record points to this static IP to avoid downtime if the instance restarts.

内容的提问来源于stack exchange,提问作者fuzzi

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.27 04:27:23