Node.js+Nginx+Cloudflare配置失效及正确部署方案咨询
Let’s walk through fixing your setup step by step—your current issues are pretty common, and we can sort them out quickly. First, let’s break down what’s going wrong:
- Error 1000 on Cloudflare: This means Cloudflare can’t establish a connection to your origin server. Usually, this stems from misconfigured ports, firewall blocks, or incorrect SSL settings.
- Working without Cloudflare but no HTTPS/IP hiding: That makes sense—you’re connecting directly to your server’s IP on port 3000, which skips Cloudflare’s proxy layer entirely, so no SSL encryption or IP masking.
Step 1: Update Your Nginx Configuration
Your current Nginx config is too basic and isn’t listening on ports Cloudflare supports. Let’s adjust it to handle proper proxying and SSL.
Option 1: Standard HTTPS (Recommended)
For full HTTPS and IP hiding, use this config. First, grab a free SSL certificate for your domain (Let’s Encrypt’s Certbot is the easiest way):
# Redirect all HTTP traffic to HTTPS server { listen 80; server_name your-domain.com; return 301 https://$host$request_uri; } # HTTPS server that proxies to Node.js on 3000 server { listen 443 ssl; server_name your-domain.com; # Update these paths to your actual SSL certificate files ssl_certificate /etc/letsencrypt/live/your-domain.com/fullchain.pem; ssl_certificate_key /etc/letsencrypt/live/your-domain.com/privkey.pem; location / { proxy_pass http://localhost:3000; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; } }
Option 2: Using Cloudflare’s Non-Standard Ports (e.g., 8080)
If you want to use ports like 8080 or 2052 (Cloudflare’s allowed HTTP ports), add this server block:
server { listen 8080; server_name your-domain.com; location / { proxy_pass http://localhost:3000; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; } }
Pro Tip: Replace
your-domain.comwith your actual domain, and always test your Nginx config withsudo nginx -tbefore reloading it (sudo systemctl reload nginx).
Step 2: Configure Cloudflare Properly
a. DNS Records
- Head to your Cloudflare Dashboard → DNS
- Ensure your A/AAAA record points to your origin server’s public IP, and the cloud icon next to it is orange (this enables Cloudflare’s proxy, which hides your IP).
- No need to add the port to the DNS record—Cloudflare handles that via its SSL/TLS settings.
b. SSL/TLS Mode
- Go to Cloudflare Dashboard → SSL/TLS → Overview
- Choose the right mode for your setup:
- Flexible: Use this if you don’t have an SSL certificate on your origin (Cloudflare uses HTTPS with users, but connects to your server via HTTP). Easiest to set up but less secure.
- Full: Use this if you have a valid SSL certificate on your origin (even self-signed, but Let’s Encrypt is better). Cloudflare uses HTTPS to connect to your server.
- Full (Strict): Most secure option—requires your origin to have a trusted SSL certificate from a recognized CA (like Let’s Encrypt).
c. Set Origin Port (For Non-Standard Ports)
If you’re using 8080, 2052, etc.:
- Go to Cloudflare Dashboard → SSL/TLS → Origin Server
- Under Origin Port, set the port Cloudflare should use to connect to your Nginx server (e.g., 8080 for HTTP).
Step 3: Open Ports Exclusively for Cloudflare
To hide your origin IP, you must only allow traffic from Cloudflare’s IP ranges on the ports you’re using (80, 443, 8080, etc.). Never open these ports to the entire internet!
For example, if you’re using UFW (Ubuntu’s firewall):
# Allow Cloudflare IP ranges on ports 80, 443, 8080 ufw allow from 103.21.244.0/22 to any port 80,443,8080 ufw allow from 103.22.200.0/22 to any port 80,443,8080 ufw allow from 103.31.4.0/22 to any port 80,443,8080 # Add all Cloudflare IP ranges (you can get the full list from Cloudflare's official docs) ufw reload
Step 4: Verify Your Node.js App
Make sure your Node.js app is listening on localhost:3000 (or 0.0.0.0:3000, but localhost is safer for proxying). Test it locally with:
curl http://localhost:3000
Troubleshooting Error 1000
If you still see Error 1000 after these steps:
- Test Cloudflare Connectivity: Use Cloudflare’s Diagnostics tool in the dashboard to check if Cloudflare can reach your origin server.
- Check Nginx Listening Ports: Run
netstat -tulpn | grep nginxto confirm Nginx is listening on the ports you configured. - Double-Check DNS: Ensure your Cloudflare DNS record points to the correct public IP of your origin server.
内容的提问来源于stack exchange,提问作者user5384437

