You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

部署到Azure Service Fabric后无法访问Spring Boot端口

Troubleshooting Service Fabric FQDN Access Issues for Spring Boot Apps

Let me walk through targeted fixes and checks based on your scenario—since you can reach the app via the LB public IP but not the SF cluster FQDN, the problem is likely tied to DNS resolution, certificate configuration, or reverse proxy setup.

1. Verify DNS Resolution for Your SF FQDN

First, confirm that your Service Fabric cluster's FQDN is actually resolving to the correct load balancer public IP. If the DNS record is outdated or misconfigured, accessing via FQDN will fail even if the LB IP works.

Run these commands from your local machine to check:

# Using nslookup
nslookup your-sf-cluster-fqdn.example.com

# Using dig (Linux/macOS)
dig your-sf-cluster-fqdn.example.com

Compare the resolved IP to the public IP of your load balancer. If they don't match, update your DNS record (usually in Azure DNS or your domain registrar) to point to the correct LB IP.

2. Check if Your Cluster Certificate Includes the FQDN as a SAN

Since you're using a secure certificate-authenticated cluster, accessing via the FQDN requires the certificate to have the FQDN listed in its Subject Alternative Name (SAN). If this is missing, clients will reject the SSL/TLS handshake even if the app is healthy.

To inspect your cluster certificate's SAN:

# If you have the certificate file locally (e.g., .pem or .pfx)
openssl x509 -in your-cluster-cert.pem -text -noout | grep -A 5 "Subject Alternative Name"

Look for a line like DNS:your-sf-cluster-fqdn.example.com. If it's not present, regenerate your cluster certificate with the FQDN added as a SAN, then update the cluster to use this new certificate.

3. Validate Service Fabric Reverse Proxy Configuration

By default, the Service Fabric cluster FQDN points to the cluster's management endpoints (like port 19080), not your application's 8080 port. If you want to access your app directly via the SF FQDN, you need to enable and configure the Service Fabric Reverse Proxy:

  • Confirm reverse proxy is enabled in the Azure Portal under your cluster's "Settings" > "Reverse Proxy".
  • Ensure the reverse proxy listens on a port open in your NSG and LB rules (you can map it to 8080 if needed).
  • Verify the reverse proxy's certificate includes the SF FQDN as a SAN (same requirement as the cluster certificate).
  • Update your service manifest to include reverse proxy routing rules, so requests to https://your-sf-fqdn:8080 forward to your Spring Boot service.

4. Double-Check NSG and LB Rule Scope

While you configured LB rules for 8080, confirm your Network Security Groups (NSGs) associated with node types or the load balancer allow inbound traffic on 8080 from all necessary sources. Even if the LB IP works, a restrictive source IP filter in the NSG could block traffic routed via the FQDN.

5. Inspect Application and Cluster Port Bindings

Double-check your ServiceManifest.xml to ensure the endpoint is correctly defined:

<Endpoint Name="SpringBootEndpoint" Protocol="http" Port="8080" />

In your ApplicationManifest.xml, confirm the service is bound to this endpoint without conflicting mappings. Also, verify your node type's configuration allows inbound traffic on port 8080 (check in the Azure Portal under "Node Types" > "Ports").


内容的提问来源于stack exchange,提问作者Dan F

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.27 09:18:07