You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

在Ubuntu 16.04服务器上为Docker容器应用配置HTTPS

Hey there! Let's get your app running over HTTPS smoothly, so you can access it via https://www.myserver.com without any port numbers. Since you already have a valid SSL certificate, here are two reliable approaches to choose from:

方案1:直接在Docker容器内配置HTTPS

This works if you want your application container to handle SSL directly.

  • First, move your SSL certificate files (e.g., myserver.com.crt for the full chain and myserver.com.key for the private key) into a folder in your current working directory—let's call it ssl/ for organization.
  • Adjust your Docker run command to mount this ssl folder into the container, and map the host's 443 port to the container's HTTPS port (we'll use 443 inside the container here):
    docker run --rm -it -v $(pwd):/data -v $(pwd)/ssl:/etc/ssl/myserver -p 443:443 app/name
    
  • Next, update your application's configuration inside the container to enable HTTPS:
    For example, if your app uses Nginx, modify the server block in your Nginx config:
    server {
        listen 443 ssl;
        server_name www.myserver.com;
    
        ssl_certificate /etc/ssl/myserver/myserver.com.crt;
        ssl_certificate_key /etc/ssl/myserver/myserver.com.key;
    
        # Keep your existing app configuration (like root directory, routes, etc.)
        root /data;
    }
    
    If your app is something else (like Flask, Node.js), adjust its settings to use the mounted certificate files and listen on port 443.

Once you restart the container, https://www.myserver.com will work directly—since HTTPS uses port 443 by default, you don't need to append it to the URL.

方案2:用反向代理(Nginx)处理SSL(推荐)

This is a more flexible approach, especially if you plan to run multiple containers later. We'll let a standalone Nginx (on your host or in another container) handle SSL termination, then proxy requests to your app container running HTTP.

Step 1: Adjust your Docker container

First, run your app container without exposing port 443 to the public—instead, bind it to your host's localhost only for security:

docker run --rm -d -v $(pwd):/data -p 127.0.0.1:8080:80 app/name

We're using -d to run it in the background, and mapping port 8080 on your host to port 80 in the container.

Step 2: Install and configure Nginx on your host

  1. Install Nginx if you haven't already:
    sudo apt-get update && sudo apt-get install nginx
    
  2. Create a new Nginx config file at /etc/nginx/sites-available/myserver.conf:
    server {
        listen 443 ssl;
        server_name www.myserver.com;
    
        # Point to your SSL certificate files
        ssl_certificate /path/to/your/myserver.com.crt;
        ssl_certificate_key /path/to/your/myserver.com.key;
    
        # Optional: Add SSL hardening settings
        ssl_protocols TLSv1.2 TLSv1.3;
        ssl_ciphers HIGH:!aNULL:!MD5;
        ssl_prefer_server_ciphers on;
    
        # Proxy requests to your Docker container
        location / {
            proxy_pass http://localhost:8080;
            proxy_set_header Host $host;
            proxy_set_header X-Real-IP $remote_addr;
            proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
            proxy_set_header X-Forwarded-Proto $scheme;
        }
    }
    
    # Optional: Redirect all HTTP traffic to HTTPS
    server {
        listen 80;
        server_name www.myserver.com;
        return 301 https://$server_name$request_uri;
    }
    
  3. Enable the config and disable the default Nginx site:
    sudo ln -s /etc/nginx/sites-available/myserver.conf /etc/nginx/sites-enabled/
    sudo rm /etc/nginx/sites-enabled/default
    
  4. Test the Nginx config and restart the service:
    sudo nginx -t
    sudo systemctl restart nginx
    

That's it!

Now https://www.myserver.com will route through Nginx, which handles the SSL handshake, then passes the request to your Docker container. The optional HTTP redirect ensures anyone trying to access the HTTP version gets sent to HTTPS automatically.


内容的提问来源于stack exchange,提问作者Sven Nijs

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.27 10:06:57