惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

S
Secure Thoughts
P
Privacy International News Feed
T
Tenable Blog
L
Lohrmann on Cybersecurity
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
T
Threat Research - Cisco Blogs
S
Securelist
C
CXSECURITY Database RSS Feed - CXSecurity.com
Cisco Talos Blog
Cisco Talos Blog
T
The Exploit Database - CXSecurity.com
S
Schneier on Security
P
Privacy & Cybersecurity Law Blog
Vercel News
Vercel News
Cyberwarzone
Cyberwarzone
月光博客
月光博客
T
The Blog of Author Tim Ferriss
Scott Helme
Scott Helme
爱范儿
爱范儿
Stack Overflow Blog
Stack Overflow Blog
C
Cisco Blogs
aimingoo的专栏
aimingoo的专栏
博客园 - 司徒正美
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
P
Proofpoint News Feed
A
Arctic Wolf
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
L
LangChain Blog
C
Cyber Attacks, Cyber Crime and Cyber Security
阮一峰的网络日志
阮一峰的网络日志
Simon Willison's Weblog
Simon Willison's Weblog
T
Tor Project blog
Security Latest
Security Latest
Blog — PlanetScale
Blog — PlanetScale
G
GRAHAM CLULEY
V
Vulnerabilities – Threatpost
博客园 - 三生石上(FineUI控件)
I
InfoQ
Spread Privacy
Spread Privacy
B
Blog RSS Feed
Microsoft Azure Blog
Microsoft Azure Blog
S
SegmentFault 最新的问题
云风的 BLOG
云风的 BLOG
Last Week in AI
Last Week in AI
MongoDB | Blog
MongoDB | Blog
C
CERT Recently Published Vulnerability Notes
A
About on SuperTechFans
博客园_首页
Engineering at Meta
Engineering at Meta
Project Zero
Project Zero
Latest news
Latest news

NGINX

有用 Nginx UI 的朋友吗?这玩意是不是时不时将磁盘 IO 打满? fail2ban 保护 nginx 方案 - V2EX 麦当劳服务模式是 nginx,肯德基服务模式是 apache,这样理解对不对? - V2EX oracleusa.ml 的实现原理 - V2EX 尝试自己配置转发后端请求的时候有个疑问 - V2EX 请教 Nginx 时完整的 SSL 刷新教程或者脚本 - V2EX 问问大家 nginx 日志流量分析用什么方案? - V2EX nginx 二级目录反向代理是不是有先天缺陷? - V2EX nginx rewrite 指令的问题 - V2EX 问个 nginx 配置问题 - V2EX 请问下为啥微信客户端访问到 nginx 没有参数了? - V2EX 有兄弟们用 nginx proxy manager(或者其他图形化工具)来管理 nginx 反向代理的吗? - V2EX 请问 Nginx 怎么添加 CORS 白名单? - V2EX 使用 nginx 监听已被监听的端口, reload 不会失败, 但会导致其他配置不生效. - V2EX nginx 如何获取/打印完整代理路径? - V2EX Nginx 四层反代 QUIC 如何传递客户端 IP - V2EX 关于 windows 下面重启之后 nginx 的问题 - V2EX 我是不是可以反向代理个 V2EX 网站? - V2EX 用 nginx 做的 xai 的转发好像一直有问题 - V2EX 请教一个 Nginx 配置和浏览器强制 http 转 https 问题 - V2EX nginx proxy manager ipv6 反代指向内网 ipv4 局域网地址,还可以这样操作🤔? - V2EX 关于 Nginx 反向代理性能调优的问题,求指导🙏 - V2EX nginx 配置根据请求头分发问题 - V2EX 用过 nginx-proxy-manager 请进, 咨询个问题. - V2EX 我有一个端口转发问题,求大佬们协助 - V2EX 使用 Nginx 代理 Emby 服务器,浏览器可以访问但是客户端连不上 - V2EX 小白在使用 Nginx proxy manager 遇到问题,请大佬们指教。 - V2EX 请教下 nginx 反代配置 - V2EX nginx 配置问题求解答 - V2EX Nginx 流量异常,请大佬支招~ - V2EX nginx 读取 ssl 证书的权限问题请教 - V2EX 请问一个二级域名如何配置可以访问多个 http 服务? - V2EX 配置证书相关的问题 - V2EX 关于 nginx 的一些提问 - V2EX nginx 限流失败的奇怪问题 - V2EX 反向代理提示该网站已被拦截,请教 - V2EX 为什么我的 docker nginx 的不能反向代理 favicon 啊 - V2EX Nginx 能不能实现按域名限制网速? - V2EX 虚心请教一个有关于 nginx 配置的问题 - V2EX 求解 nginx 反代某堡垒机 443 页面出现问题 - V2EX nginx if 语句 return 403,没办法跳转自定义 403 页面 - V2EX 请教 nginx deny 优先级的问题。 - V2EX 求教关于反代的问题 - V2EX nginx 增加 http 块 就报证书错误,请问是什么原因,第一次见 - V2EX 有台生产服务器, Nginx 每天都会因为不同原因 exit 一次,虽然配了自动重启,有没办法排查是什么原因?平均一天 1820 万请求 - V2EX openresty 怎么修改代理站的文件返回给客户端 有啥平替 resend、ZeptoMail 的国内解决方案嘛? 求救:屏蔽爬虫试了 2 天,没成功 - V2EX
请教一下各位关于 nginx 版本更新区别导致反向代理无法访问的问题 - V2EX
KadeDivent · 2024-11-01 · via NGINX

迁移了一个 headscale 服务端,反向代理配置了 headscale-ui 的静态页面

我将 centos 7 中的 nginx v1.20.1 配置迁移到了 rocky linux 9 中的 nginx v1.26.2 中,

使用的均为 rpm 包

nginx v1.20.1 是官方源中下载

nginx v1.26.2 是从 nginx 源中下载


迁移之后 headscale 被反向代理后的 8082 端口就无法访问了,但是原生的 8080 端口可以访问,

两个站点配置完全一样,是直接复制过去的

新版本的 nginx 日志中没有相关访问日志

并且 nginx 的主要更新日志,并没有什么头绪,所以发帖请教一下各位


以下是日志与配置

站点主要配置如下

server {
    listen              8082 ssl ;
    listen              [::]:8082 ssl ;
    server_name         xxxx;
    root                /opt/headscale/headscale-ui/web;

    # SSL
    ssl_certificate     /etc/nginx/cert/xxxx.crt;
    ssl_certificate_key /etc/nginx/cert/xxxx.key;
    ssl_protocols TLSv1.2 TLSv1.3;

    # logging
    # 这里其实有日志配置,但是不知道放进来就不能发帖

    location /web {
        alias /opt/headscale/headscale-ui/web;
        index index.html;
    }

    # reverse proxy
    location / {
        proxy_pass            http://127.0.0.1:8080;
        proxy_http_version 1.1;
        proxy_set_header Upgrade $http_upgrade;
        proxy_set_header Connection $connection_upgrade;
        proxy_set_header Host $server_name;
        proxy_redirect http:// https://;
        proxy_buffering off;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $http_x_forwarded_proto;
        add_header Strict-Transport-Security "max-age=15552000; includeSubDomains" always;
    }

}

headscale 的部分日志如下

Nov 01 17:13:17 xxxxxx tailscaled[2145341]: control: LoginInteractive -> regen=true
Nov 01 17:13:17 xxxxxx tailscaled[2145341]: control: doLogin(regen=true, hasUrl=false)
Nov 01 17:13:17 xxxxxx tailscaled[2145341]: Received error: fetch control key: Get "https://xxxxxx:8082/key?v=106": read tcp 192.168.2.199:36346->xx.xx.xx.xx:8082: read: connection reset by peer
Nov 01 17:13:17 xxxxxx tailscaled[2145341]: health(warnable=login-state): error: You are logged out. The last login error was: fetch control key: Get "https://xxxxxx:8082/key?v=106": read tcp 192.168.2.199:36346->xx.xx.xx.xx:8082: read: connection reset by peer

nginx 的版本信息如下

旧服务器

nginx version: nginx/1.20.1
built by gcc 4.8.5 20150623 (Red Hat 4.8.5-44) (GCC) 
built with OpenSSL 1.1.1k  FIPS 25 Mar 2021
TLS SNI support enabled

新服务器

nginx version: nginx/1.26.2
built by gcc 11.4.1 20231218 (Red Hat 11.4.1-3) (GCC) 
built with OpenSSL 3.0.7 1 Nov 2022
TLS SNI support enabled

详细的编译参数放不进去,如果有需要的话,后续考虑截图放在后面