Skip to content

28、Nginx配置域名SSL证书

https://console.cloud.tencent.com/ssl

1、下载证书

image-20250730154115198

2、将证书放入Nginx目录

image-20250730155433462

image-20250730155500315

dockerfile
# 基础镜像
FROM registry.cn-hangzhou.aliyuncs.com/xx_blog/nginx:1.27.2

# author
MAINTAINER maintainer="xx@qq.com"

# 复制nginx.conf
COPY ./conf/nginx.conf /etc/nginx/nginx.conf

COPY ./conf/cert/xx.xiaoxueblog.com.key /etc/nginx/xx.xiaoxueblog.com.key
COPY ./conf/cert/xx.xiaoxueblog.com_bundle.pem /etc/nginx/xx.xiaoxueblog.com_bundle.pem


# 复制html文件到路径
COPY dist/ /usr/share/nginx/html

EXPOSE 80
EXPOSE 443

3、开放443端口

sh
docker run -d --name=${SERVER_NAME} -p 80:80 -p 443:443 ${SERVER_NAME}:v${BUILD_NUMBER}

image-20250730155545539

防火墙也记得开放443端口

4、修改Nginx配置文件

nginx

user  nginx;
worker_processes  auto;

error_log  /var/log/nginx/error.log notice;
pid        /var/run/nginx.pid;


events {
    worker_connections  1024;
}


http {
    include       /etc/nginx/mime.types;
    default_type  application/octet-stream;

    log_format  main  '$remote_addr - $remote_user [$time_local] "$request" '
                      '$status $body_bytes_sent "$http_referer" '
                      '"$http_user_agent" "$http_x_forwarded_for"';

    access_log  /var/log/nginx/access.log  main;

    sendfile        on;
    #tcp_nopush     on;

    keepalive_timeout  65;

    #gzip  on;

   server {
    listen       80;
    server_name  localhost;

    location /manager/ {
        proxy_pass http://112.74.160.27:8001/manager/;
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
    }

    location / {
       root   /usr/share/nginx/html;
        index  index.html index.htm;
        try_files $uri $uri/ /index.html;
    }
    error_page   500 502 503 504  /50x.html;
    location = /50x.html {
        root   html;
    }
 }


     server {
             #SSL 访问端口号为 443
             listen 443 ssl;
             #填写绑定证书的域名
             server_name xx.xiaoxueblog.com;
             #证书文件名称
             ssl_certificate xx.xiaoxueblog.com_bundle.pem;
             #私钥文件名称
             ssl_certificate_key xx.xiaoxueblog.com.key;
             ssl_session_timeout 5m;
             #请按照以下协议配置
             ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
             #请按照以下套件配置,配置加密套件,写法遵循 openssl 标准。
             ssl_ciphers ECDHE-RSA-AES128-GCM-SHA256:HIGH:!aNULL:!MD5:!RC4:!DHE;
             ssl_prefer_server_ciphers on;

            location /manager/ {
                proxy_pass http://112.74.160.27:8001/manager/;
                proxy_set_header Host $host;
                proxy_set_header X-Real-IP $remote_addr;
                proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
            }

             location ^~ / {
                     root /usr/share/nginx/html/;
                     index  index.html index.htm;
                     }
         }



    include /etc/nginx/conf.d/*.conf;
}

5、访问

http
https://xx.xiaoxueblog.com

image-20250730155357391

http
https://xx.xiaoxueblog.com/manager/test

image-20250730155416427