Files
deploy-ops/03-HTTPS配置.md

66 lines
1.3 KiB
Markdown
Raw Permalink Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# HTTPS + Nginx 配置
## 架构
```
浏览器 (https://suyushi.top:443)
→ Nginx (端口 80/443)
→ LobeHub 容器 (内部 127.0.0.1:3210)
```
## Nginx 安装
```bash
yum install -y nginx
```
## Nginx 配置
文件路径:`/etc/nginx/conf.d/lobehub.conf`
```nginx
server {
listen 80;
server_name suyushi.top www.suyushi.top;
location / {
proxy_pass http://127.0.0.1:3210;
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection 'upgrade';
proxy_set_header Host $host;
proxy_cache_bypass $http_upgrade;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
}
}
```
## Let's Encrypt SSL 证书
### 安装 Certbot
```bash
yum install -y certbot python3-certbot-nginx
```
### 签发证书
```bash
certbot --nginx -d suyushi.top -d www.suyushi.top --non-interactive --agree-tos --email panghusys2025@gmail.com --redirect
```
> 证书自动续期已配置,90天有效,到期前自动更新
## 启动 Nginx 自启
```bash
systemctl enable nginx
```
## 端口冲突处理
如果 nginx 起不来报 `Address already in use:80`
```bash
fuser -k 80/tcp # 杀掉占用端口的进程
systemctl start nginx
```