Noking 毕升的nginx默认没有监听443,你需要在service/nginx/config/conf.d/bisheng.conf添加以下内容,并把证书放到正确位置才能开启https(实际上就是照着80端口的设置再抄一遍)。
server {
listen 443 ssl default_server;
server_name _;
ssl_certificate /keys/cert.crt; # 指定证书的位置,绝对路径
ssl_certificate_key /keys/cert.key; # 绝对路径,同上
ssl_protocols TLSv1 TLSv1.1 TLSv1.2; #按照这个协议配置
ssl_ciphers ECDHE-RSA-AES128-GCM-SHA256:HIGH:!aNULL:!MD5:!RC4:!DHE;
location / {
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header Host $http_host;
proxy_set_header X-NginX-Proxy true;
client_max_body_size 500m;
proxy_redirect off;
proxy_set_header x-scheme $scheme;
proxy_pass http://editor_app:5500;
}
location /apps{
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header Host $http_host;
proxy_set_header X-NginX-Proxy true;
client_max_body_size 500m;
proxy_redirect off;
proxy_set_header x-scheme $scheme;
location /apps/editor {
proxy_pass http://editor_app:5500/apps/editor;
}
location /apps/console {
proxy_pass http://editor_app:5500/apps/console;
}
}
location /officesite/static{
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header Host $http_host;
proxy_set_header X-NginX-Proxy true;
client_max_body_size 500m;
proxy_redirect off;
proxy_set_header x-scheme $scheme;
location /officesite/static/console {
proxy_pass http://editor_app:5500/officesite/static/console;
}
location /officesite/static/office {
proxy_pass http://editor_app:5500/officesite/static/office;
}
location /officesite/static/editor {
proxy_pass http://editor_app:5500/officesite/static/editor;
}
}
location /officesite/resource/custom/favicon.ico{
proxy_pass http://editor_app:5500/officesite/resource/custom/favicon.ico;
}
location /ws{
proxy_buffering on;
proxy_buffer_size 4k;
proxy_buffers 8 1m;
proxy_busy_buffers_size 2m;
proxy_max_temp_file_size 1024m;
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection $connection_upgrade;
location /ws/editor {
proxy_pass http://editor_app:5500/ws/editor;
}
}
location /s3/{
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-NginX-Proxy true;
proxy_redirect off;
proxy_set_header x-scheme $scheme;
proxy_pass http://minio:9000/;
}
}