Cấu hình Nginx reverse proxy + HTTPS với CertbotNginx reverse proxy + HTTPS setup with Certbot
Dựng Nginx làm reverse proxy cho app ở localhost:3000 và bật HTTPS bằng Certbot.Put Nginx in front of an app on localhost:3000 as a reverse proxy and turn on HTTPS with Certbot.
Một request HTTPS đi qua đâuWhere one HTTPS request goes
Cả đường đi: trình duyệt → Nginx (cổng 443, TLS) → app ở localhost:3000 → trả về. Bấm ▶ để xem từng bước.The whole trip: browser → Nginx (port 443, TLS) → the app on localhost:3000 → back. Press ▶ to step through.
Hướng dẫn dựng Nginx làm reverse proxy cho app chạy ở localhost:3000 và bật HTTPS bằng Certbot.
1. Cài đặt Nginx
sudo apt install nginx -yKiểm tra và khởi động:
sudo systemctl status nginx
sudo systemctl start nginx
sudo systemctl enable nginx2. Tạo file cấu hình site
cd /etc/nginx/sites-available
sudo nano app1.domain.comNội dung reverse proxy về cổng nội bộ 3000:
3. Kích hoạt site & bỏ default
sudo ln -s /etc/nginx/sites-available/cms-api-dev.vietinv.com /etc/nginx/sites-enabled/
sudo rm /etc/nginx/sites-enabled/default
sudo rm /etc/nginx/sites-available/defaultKiểm tra cấu hình và nạp lại:
sudo nginx -t
sudo systemctl restart nginx
sudo systemctl reload nginx4. Bật HTTPS bằng Certbot
sudo apt install certbot python3-certbot-nginx
sudo certbot --nginx -d cms-api-dev.vietinv.com5. Kiểm tra chứng chỉ & mapping
Kiểm tra SAN của cert:
openssl s_client -connect auth.yemi.app:443 -servername auth.yemi.app | openssl x509 -noout -text | grep -A1 "Subject Alternative Name"Kiểm tra mapping server_name:
sudo nginx -T | grep server_name6. Ví dụ cấu hình đầy đủ (redirect 80 → 443)
Guide to set up Nginx as a reverse proxy for an app running on localhost:3000 and enable HTTPS with Certbot.
1. Install Nginx
sudo apt install nginx -yCheck status and start:
sudo systemctl status nginx
sudo systemctl start nginx
sudo systemctl enable nginx2. Create the site config
cd /etc/nginx/sites-available
sudo nano app1.domain.comReverse proxy to the internal port 3000:
3. Enable the site & remove default
sudo ln -s /etc/nginx/sites-available/cms-api-dev.vietinv.com /etc/nginx/sites-enabled/
sudo rm /etc/nginx/sites-enabled/default
sudo rm /etc/nginx/sites-available/defaultValidate the config and reload:
sudo nginx -t
sudo systemctl restart nginx
sudo systemctl reload nginx4. Enable HTTPS with Certbot
sudo apt install certbot python3-certbot-nginx
sudo certbot --nginx -d cms-api-dev.vietinv.com5. Check certificate & mapping
Check the cert's SAN:
openssl s_client -connect auth.yemi.app:443 -servername auth.yemi.app | openssl x509 -noout -text | grep -A1 "Subject Alternative Name"Check the server_name mapping:
sudo nginx -T | grep server_name