Skip to main content

Localhost reverse proxy fails nginx AWS Ubuntu



I am attempting to to host a Flask app with Gunicoron on a server that hosts multiple web services on Nginx. I am using AWS ubuntu as a test bed for evetually hosting it on said Nginx mutilple web service (that's not AWS). I've been trying to make it production status by changing the IP from external AWS to localhost 127.0.0.1 with socket 8006 as well as others. I tried to do the reverse proxying with no luck. I get a 502 Bad Gateway error with the following error:




Site Error Log




2019/06/11 05:08:58 [error] 9310#9310: *9 connect() failed (111:
Connection refused) while connecting to upstream, client:
162.155.112.131, server: 127.0.0.1, request: "GET /favicon.ico HTTP/1.1", upstream: "http://127.0.0.1:8006/favicon.ico", host: AWS




Error Log:





2019/06/11 05:08:08 [emerg] 9311#9311: open() "/run/nginx.pid" failed
(13: Permission denied) 2019/06/11 05:08:25 [warn] 9313#9313: could
not build optimal proxy_headers_hash, you should increase either
proxy_headers_hash_max_size: 512 or proxy_headers_hash_bucket_size:
64; ignoring proxy_headers_hash_bucket_size




Here's the code reproduced. I tried showing what I did while making it reproducible





/etc/nginx/sites-available/Flask




upstream tester {
server 127.0.0.1:3306;
}
server {
listen 80;

server_name 127.0.0.1;
listen [::]:80;
listen 443 ssl;
location / {
include proxy_params;
# proxy_pass 34.215.33.211;
# proxy_pass http://unix:/tmp/Flask.sock;
proxy_pass http://127.0.0.1:8006;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;

proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
}
location ^~ /static/ {
rewrite ^/static$ / break;
rewrite ^/static/(.*) /$1 break;
include /etc/nginx/mime.types;
proxy_pass http://127.0.0.1:8009;
}

}



/etc/nginx/nginx.conf (Only the Virtual Host)




  ##
# Virtual Host Configs
##

include /etc/nginx/conf.d/*.conf;

include /etc/nginx/sites-enabled/*;



Please and thank you for helping me out on this issue.



Edit: The http://unix:/tmp/Flask.sock works for proxy pass on my AWS but not on the production server



Edit 2: Now I'm also triggering 500 errors with the following:




768 worker_connections are not enough while connecting to upstream, client: 127.0.0.1, server: [AWS] request: "GET /favicon.ico HTTP/1.0"


The code for /etc/nginx/sites-available/Flask is now the following:



upstream gnx{
server 127.0.0.1:8006;
}
server {
listen 80;

server_name [AWS URL];
listen [::]:80;
listen 8006;
listen [::]:8006;
listen [::1];
access_log /var/log/nginx/site_access.log;
error_log /var/log/nginx/site_error.log;

location / {
include proxy_params;

# proxy_pass http://unix:/tmp/Flask.sock;
proxy_pass http://gnx;
proxy_redirect off;
}
location ^~ /static/ {
#root /home/ubuntu/Flask/static/;
#proxy_pass http://gnx;

proxy_redirect http://127.0.0.1:8006/static/ http://$host/static/;
proxy_set_header SCRIPT_NAME /static;

}

location /docs {
alias /home/ubuntu/Flask/docs;
}
}

Answer



Okay, I found the issue so first let's address the /sites-available/Flask (or /default) file




upstream gnx{
server 127.0.0.1:8006;
}
server {
listen 80;
server_name [AWS URL];
listen [::]:80;
listen [::1];
access_log /var/log/nginx/site_access.log;
error_log /var/log/nginx/site_error.log;


location / {
include proxy_params;
# proxy_pass http://unix:/tmp/Flask.sock;
proxy_pass http://gnx;
proxy_set_header X-SCRIPT-NAME "/";
}
location ^~ /static/ {
#root /home/ubuntu/Flask/static/;
#proxy_pass http://gnx;


proxy_redirect http://127.0.0.1:8006/static/ http://$host/static/;
proxy_set_header SCRIPT_NAME /static;
}

location /docs {
alias /home/ubuntu/Flask/docs;
}
}



So we do not need to listen to the ports 8006 as we will be using them. The next part we added was the following:



proxy_set_header X-SCRIPT-NAME "/";


X-SCRIPT-NAME allows redirection of the Flask Reverse proxying to the Flask script. You can also put it in the proxy_params file (/etc/nginx/proxy_params), which I did, but I wanted to put it in the script so it was visible.



So now, the trick is to implement the reverse proxying. This is the Python code and function you would want to put in:




from werkzeug.serving import WSGIRequestHandler
class ScriptNameHandler(WSGIRequestHandler):
def make_environ(self):
environ = super().make_environ()
script_name = environ.get('HTTP_X_SCRIPT_NAME', '')
if script_name:
environ['SCRIPT_NAME'] = script_name
path_info = environ['PATH_INFO']
if path_info.startswith(script_name):
environ['PATH_INFO'] = path_info[len(script_name):]

scheme = environ.get('HTTP_X_SCHEME', '')
if scheme:
environ['wsgi.url_scheme'] = scheme
return environ


Then finally for your app.run file, you want to switch it to the following:



app.run(request_handler=ScriptNameHandler)



Which now runs the reverse proxy for you and have the setup. This method was 99.9% derived from David which also has the Apache version. I hope it helps anyone in this issue.


Comments

Popular posts from this blog

linux - iDRAC6 Virtual Media native library cannot be loaded

When attempting to mount Virtual Media on a iDRAC6 IP KVM session I get the following error: I'm using Ubuntu 9.04 and: $ javaws -version Java(TM) Web Start 1.6.0_16 $ uname -a Linux aud22419-linux 2.6.28-15-generic #51-Ubuntu SMP Mon Aug 31 13:39:06 UTC 2009 x86_64 GNU/Linux $ firefox -version Mozilla Firefox 3.0.14, Copyright (c) 1998 - 2009 mozilla.org On Windows + IE it (unsurprisingly) works. I've just gotten off the phone with the Dell tech support and I was told it is known to work on Linux + Firefox, albeit Ubuntu is not supported (by Dell, that is). Has anyone out there managed to mount virtual media in the same scenario?

hp proliant - Smart Array P822 with HBA Mode?

We get an HP DL360 G8 with an Smart Array P822 controller. On that controller will come a HP StorageWorks D2700 . Does anybody know, that it is possible to run the Smart Array P822 in HBA mode? I found only information about the P410i, who can run HBA. If this is not supported, what you think about the LSI 9207-8e controller? Will this fit good in that setup? The Hardware we get is used but all original from HP. The StorageWorks has 25 x 900 GB SAS 10K disks. Because the disks are not new I would like to use only 22 for raid6, and the rest for spare (I need to see if the disk count is optimal or not for zfs). It would be nice if I'm not stick to SAS in future. As OS I would like to install debian stretch with zfs 0.71 as file system and software raid. I have see that hp has an page for debian to. I would like to use hba mode because it is recommend, that zfs know at most as possible about the disk, and I'm independent from the raid controller. For us zfs have many benefits,

apache 2.2 - Server Potentially Compromised -- c99madshell

So, low and behold, a legacy site we've been hosting for a client had a version of FCKEditor that allowed someone to upload the dreaded c99madshell exploit onto our web host. I'm not a big security buff -- frankly I'm just a dev currently responsible for S/A duties due to a loss of personnel. Accordingly, I'd love any help you server-faulters could provide in assessing the damage from the exploit. To give you a bit of information: The file was uploaded into a directory within the webroot, "/_img/fck_uploads/File/". The Apache user and group are restricted such that they can't log in and don't have permissions outside of the directory from which we serve sites. All the files had 770 permissions (user rwx, group rwx, other none) -- something I wanted to fix but was told to hold off on as it wasn't "high priority" (hopefully this changes that). So it seems the hackers could've easily executed the script. Now I wasn't able