Cookiecutter-Django生产环境Docker-Compose启动停滞及连接拒绝问题
Let’s walk through diagnosing why your deployment is stuck and throwing connection errors. Here’s a step-by-step breakdown tailored to your setup:
1. Diagnose the Hanging docker-compose up Command
When docker-compose -f production.yml up doesn’t return to the terminal, it’s almost always because one or more services failed to start properly or are waiting on an unready dependency.
Open a new terminal on your EC2 instance and run this to check container statuses:
docker-compose -f production.yml psLook for services marked
restartingorexited—these are likely the root cause.Pull logs for misbehaving services (focus on
webandnginxfirst):docker-compose -f production.yml logs web docker-compose -f production.yml logs nginxCommon issues here include database connection failures, missing environment variables, or invalid Nginx configuration.
2. Fix Nginx Configuration for ELB SSL Termination
Since you swapped Caddy for Nginx, you need to ensure Nginx is configured to work with AWS ELB’s SSL termination:
- Verify your Nginx config (usually in
compose/production/nginx/nginx.conf) includes these settings to trust ELB’s forwarded headers:server { listen 80; # Trust headers from ELB to handle SSL termination correctly proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; proxy_set_header Host $host; # Your existing proxy pass settings for Django... } - Check that
production.ymlmaps Nginx’s container port to EC2’s port 80:nginx: build: context: . dockerfile: ./compose/production/nginx/Dockerfile ports: - "80:80" # ELB forwards traffic to this port depends_on: - web
3. Validate Critical Environment Variables in .env
Cookiecutter-Django relies heavily on env vars—double-check these key settings:
DJANGO_ALLOWED_HOSTS: Must include your domain name and EC2 public IP (e.g.,yourdomain.com,1.2.3.4)DJANGO_SECURE_SSL_REDIRECT: Set toTrue(since ELB handles SSL termination)- Ensure these Django settings are enabled (in
settings/production.pyor via env vars):
These tell Django to trust the SSL status passed from ELB’sUSE_X_FORWARDED_HOST = True USE_X_FORWARDED_PORT = True SECURE_PROXY_SSL_HEADER = ('HTTP_X_FORWARDED_PROTO', 'https')X-Forwarded-Protoheader.
4. Audit AWS Security Groups & ELB Settings
Connection refusals often stem from network access issues:
EC2 Instance Security Group
- Allow inbound traffic on port 80 from:
- Your ELB’s security group (so ELB can forward traffic to EC2)
- Your personal IP (if you want to test direct access to EC2’s IP)
- Don’t open port 443 directly on EC2—ELB handles SSL termination, so it forwards unencrypted traffic to EC2’s port 80.
ELB & Target Group
- Confirm your ELB listener is set to forward HTTPS (443) traffic to your target group on port 80.
- Check target group health checks: Are they pointing to a valid endpoint (e.g.,
/health/)? If health checks fail, ELB won’t send traffic to your EC2 instance. - Ensure your EC2 instance is registered in the target group and marked as "healthy".
5. Test Direct Local Access on EC2
If accessing the EC2 IP gives ERR_CONNECTION_REFUSED, test if Nginx is listening on port 80:
curl localhost:80
If this returns a connection error, Nginx isn’t running properly—go back to checking Nginx logs and container status.
内容的提问来源于stack exchange,提问作者Brad Rhoads

