在Ubuntu 16.04服务器上为Docker容器应用配置HTTPS
Hey there! Let's get your app running over HTTPS smoothly, so you can access it via https://www.myserver.com without any port numbers. Since you already have a valid SSL certificate, here are two reliable approaches to choose from:
This works if you want your application container to handle SSL directly.
- First, move your SSL certificate files (e.g.,
myserver.com.crtfor the full chain andmyserver.com.keyfor the private key) into a folder in your current working directory—let's call itssl/for organization. - Adjust your Docker run command to mount this
sslfolder into the container, and map the host's 443 port to the container's HTTPS port (we'll use 443 inside the container here):docker run --rm -it -v $(pwd):/data -v $(pwd)/ssl:/etc/ssl/myserver -p 443:443 app/name - Next, update your application's configuration inside the container to enable HTTPS:
For example, if your app uses Nginx, modify the server block in your Nginx config:
If your app is something else (like Flask, Node.js), adjust its settings to use the mounted certificate files and listen on port 443.server { listen 443 ssl; server_name www.myserver.com; ssl_certificate /etc/ssl/myserver/myserver.com.crt; ssl_certificate_key /etc/ssl/myserver/myserver.com.key; # Keep your existing app configuration (like root directory, routes, etc.) root /data; }
Once you restart the container, https://www.myserver.com will work directly—since HTTPS uses port 443 by default, you don't need to append it to the URL.
This is a more flexible approach, especially if you plan to run multiple containers later. We'll let a standalone Nginx (on your host or in another container) handle SSL termination, then proxy requests to your app container running HTTP.
Step 1: Adjust your Docker container
First, run your app container without exposing port 443 to the public—instead, bind it to your host's localhost only for security:
docker run --rm -d -v $(pwd):/data -p 127.0.0.1:8080:80 app/name
We're using -d to run it in the background, and mapping port 8080 on your host to port 80 in the container.
Step 2: Install and configure Nginx on your host
- Install Nginx if you haven't already:
sudo apt-get update && sudo apt-get install nginx - Create a new Nginx config file at
/etc/nginx/sites-available/myserver.conf:server { listen 443 ssl; server_name www.myserver.com; # Point to your SSL certificate files ssl_certificate /path/to/your/myserver.com.crt; ssl_certificate_key /path/to/your/myserver.com.key; # Optional: Add SSL hardening settings ssl_protocols TLSv1.2 TLSv1.3; ssl_ciphers HIGH:!aNULL:!MD5; ssl_prefer_server_ciphers on; # Proxy requests to your Docker container location / { proxy_pass http://localhost:8080; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; } } # Optional: Redirect all HTTP traffic to HTTPS server { listen 80; server_name www.myserver.com; return 301 https://$server_name$request_uri; } - Enable the config and disable the default Nginx site:
sudo ln -s /etc/nginx/sites-available/myserver.conf /etc/nginx/sites-enabled/ sudo rm /etc/nginx/sites-enabled/default - Test the Nginx config and restart the service:
sudo nginx -t sudo systemctl restart nginx
That's it!
Now https://www.myserver.com will route through Nginx, which handles the SSL handshake, then passes the request to your Docker container. The optional HTTP redirect ensures anyone trying to access the HTTP version gets sent to HTTPS automatically.
内容的提问来源于stack exchange,提问作者Sven Nijs

