Bỏ qua tới nội dung chính
Portfolio
Deployment

Cấu hình Nginx reverse proxy + HTTPS với CertbotNginx reverse proxy + HTTPS setup with Certbot

Dựng Nginx làm reverse proxy cho app ở localhost:3000 và bật HTTPS bằng Certbot.Put Nginx in front of an app on localhost:3000 as a reverse proxy and turn on HTTPS with Certbot.

Một request HTTPS đi qua đâuWhere one HTTPS request goes

Browserapp1.domain.comNginx:443 · TLSApplocalhost:3000Certbot

Cả đường đi: trình duyệt → Nginx (cổng 443, TLS) → app ở localhost:3000 → trả về. Bấm ▶ để xem từng bước.The whole trip: browser → Nginx (port 443, TLS) → the app on localhost:3000 → back. Press ▶ to step through.

Hướng dẫn dựng Nginx làm reverse proxy cho app chạy ở localhost:3000 và bật HTTPS bằng Certbot.

1. Cài đặt Nginx

bash
sudo apt install nginx -y

Kiểm tra và khởi động:

bash
sudo systemctl status nginx
sudo systemctl start nginx
sudo systemctl enable nginx

2. Tạo file cấu hình site

bash
cd /etc/nginx/sites-available
sudo nano app1.domain.com

Nội dung reverse proxy về cổng nội bộ 3000:

nginx
Loading...

3. Kích hoạt site & bỏ default

bash
sudo ln -s /etc/nginx/sites-available/cms-api-dev.vietinv.com /etc/nginx/sites-enabled/
sudo rm /etc/nginx/sites-enabled/default
sudo rm /etc/nginx/sites-available/default

Kiểm tra cấu hình và nạp lại:

bash
sudo nginx -t
sudo systemctl restart nginx
sudo systemctl reload nginx

4. Bật HTTPS bằng Certbot

bash
sudo apt install certbot python3-certbot-nginx
sudo certbot --nginx -d cms-api-dev.vietinv.com

5. Kiểm tra chứng chỉ & mapping

Kiểm tra SAN của cert:

bash
openssl s_client -connect auth.yemi.app:443 -servername auth.yemi.app | openssl x509 -noout -text | grep -A1 "Subject Alternative Name"

Kiểm tra mapping server_name:

bash
sudo nginx -T | grep server_name

6. Ví dụ cấu hình đầy đủ (redirect 80 → 443)

nginx
Loading...

Guide to set up Nginx as a reverse proxy for an app running on localhost:3000 and enable HTTPS with Certbot.

1. Install Nginx

bash
sudo apt install nginx -y

Check status and start:

bash
sudo systemctl status nginx
sudo systemctl start nginx
sudo systemctl enable nginx

2. Create the site config

bash
cd /etc/nginx/sites-available
sudo nano app1.domain.com

Reverse proxy to the internal port 3000:

nginx
Loading...

3. Enable the site & remove default

bash
sudo ln -s /etc/nginx/sites-available/cms-api-dev.vietinv.com /etc/nginx/sites-enabled/
sudo rm /etc/nginx/sites-enabled/default
sudo rm /etc/nginx/sites-available/default

Validate the config and reload:

bash
sudo nginx -t
sudo systemctl restart nginx
sudo systemctl reload nginx

4. Enable HTTPS with Certbot

bash
sudo apt install certbot python3-certbot-nginx
sudo certbot --nginx -d cms-api-dev.vietinv.com

5. Check certificate & mapping

Check the cert's SAN:

bash
openssl s_client -connect auth.yemi.app:443 -servername auth.yemi.app | openssl x509 -noout -text | grep -A1 "Subject Alternative Name"

Check the server_name mapping:

bash
sudo nginx -T | grep server_name

6. Full config example (redirect 80 → 443)

nginx
Loading...