Certbot 启用根域,而不是仅启用子域

Certbot 启用根域,而不是仅启用子域

我拥有一个域名,比如说 example.com。

我希望根域 example.com 为 404 或返回空白页(如果不可能出现 404)。

sub1.example.com-应该将流量重定向到localhost:3000处正在运行的docker容器。

server {
    server_name example.com www.example.com;
    listen 80;
    return 404;
}

server {
    server_name sub1.example.com;

    location / {
        proxy_pass http://localhost:8000;
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;
    }
}

一切正常,直到我生成sudo certbot证书(使用 letsencrypt)并安装它们 + 将 http 重定向到 https。

在激活过程中我只做了sub.example.com

server {
    server_name example.com www.example.com;
    listen 80;
    return 404;
}

server {
    server_name sub1.example.com;

    location / {
        proxy_pass http://localhost:8000;
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;
    }


    listen 443 ssl; # managed by Certbot
    ssl_certificate /etc/letsencrypt/live/sub1.example.com-0002/fullchain.pem; # managed by Certbot
    ssl_certificate_key /etc/letsencrypt/live/sub1.example.com-0002/privkey.pem; # managed by Certbot
    include /etc/letsencrypt/options-ssl-nginx.conf; # managed by Certbot
    ssl_dhparam /etc/letsencrypt/ssl-dhparams.pem; # managed by Certbot

}


server {
    if ($host = sub1.example.com) {
        return 301 https://$host$request_uri;
    } # managed by Certbot


    server_name sub1.example.com;
    listen 80;
    return 404; # managed by Certbot


}

现在sub1.example.com工作正常,但它以某种方式将根域重定向example.com到运行的同一个 docker 容器localhost:8000

我错过了什么 ?

sub1.example.com -> 应该可以工作 example.com -> 不应该可以工作

相关内容