Hashicorp Vault UI - 无法在 'integrity' 属性中找到有效的摘要...资源已被阻止
Hashicorp Vault UI - Failed to find a valid digest in the 'integrity' attribute ... The resource has been blocked
我在私有子网中托管 Vault 和 Consul 服务器,在这个私有子网中我有专用实例作为反向代理服务器,假设该实例称为 (private_subnet_proxy)。
为了能够使用 public 中的 Consul 和 Vault 的 UI,我专门使用了一个 public 实例作为 public 中的反向代理网络进入 private_subnet_proxy.
Consul 的 UI 与我使用的方法配合得很好(在 private-subnet-proxy.conf 和 [= 的配置中有详细说明30=]public-子网-proxy.conf
).但是,当我尝试调用 Vault 的 UI 时,出现了一个奇怪的错误。
Failed to find a valid digest in the 'integrity' attribute for resource 'https://example.com/vault/ui/assets/vendor-170f8056c4a9bc57b01e6b288c9056e5.js' with computed SHA-256 integrity 'Vl+es41l9uLYuOXW/5b17aSw8jo6h94D00opmpuhryY='. The resource has been blocked.
有没有其他人遇到过这个问题并可以帮助我解决这个问题?如果有任何想法或建议,我将不胜感激。
私有子网-proxy.conf
server {
listen 80;
listen [::]:80;
upstream vault {
server vault_instance:8200;
}
location /vault/ui/ {
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header Host $http_host;
proxy_set_header X-NginX-Proxy true;
resolver 127.0.0.1;
allow "127.0.0.1";
allow "10.10.1.12";
deny all;
proxy_pass http://vault/ui/;
proxy_set_header Accept-Encoding "";
sub_filter_types text/css text/http;
sub_filter_once off;
sub_filter /v1/ /vault_v1/;
sub_filter /ui/ /vault/ui/;
sub_filter "rel=\"stylesheet\"" "";
}
location /vault_v1/ {
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header Host $http_host;
proxy_set_header X-NginX-Proxy true;
proxy_pass http://vault/v1/;
sub_filter_types text/css text/http;
sub_filter_once off;
sub_filter /v1/ /vault_v1/;
sub_filter /ui/ /vault/ui/;
sub_filter "rel=\"stylesheet\"" "";
}
}
public-子网-proxy.conf
server {
error_page 497 https://$host:$server_port$request_uri;
auth_basic "Administrator's Area";
auth_basic_user_file /etc/apache2/.htpasswd;
listen 443 default_server ssl;
server_name example.com www.example.com;
location /vault/ {
proxy_pass http://private_subnet_proxy/vault/ui/;
}
location /vault_v1/ {
proxy_pass http://private_subnet_proxy/vault_v1/;
}
}
此 github 存储库中包含的步骤帮助我在 nginx 反向代理后面设置了 Vault UI
我在私有子网中托管 Vault 和 Consul 服务器,在这个私有子网中我有专用实例作为反向代理服务器,假设该实例称为 (private_subnet_proxy)。
为了能够使用 public 中的 Consul 和 Vault 的 UI,我专门使用了一个 public 实例作为 public 中的反向代理网络进入 private_subnet_proxy.
Consul 的 UI 与我使用的方法配合得很好(在 private-subnet-proxy.conf 和 [= 的配置中有详细说明30=]public-子网-proxy.conf ).但是,当我尝试调用 Vault 的 UI 时,出现了一个奇怪的错误。
Failed to find a valid digest in the 'integrity' attribute for resource 'https://example.com/vault/ui/assets/vendor-170f8056c4a9bc57b01e6b288c9056e5.js' with computed SHA-256 integrity 'Vl+es41l9uLYuOXW/5b17aSw8jo6h94D00opmpuhryY='. The resource has been blocked.
有没有其他人遇到过这个问题并可以帮助我解决这个问题?如果有任何想法或建议,我将不胜感激。
私有子网-proxy.conf
server {
listen 80;
listen [::]:80;
upstream vault {
server vault_instance:8200;
}
location /vault/ui/ {
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header Host $http_host;
proxy_set_header X-NginX-Proxy true;
resolver 127.0.0.1;
allow "127.0.0.1";
allow "10.10.1.12";
deny all;
proxy_pass http://vault/ui/;
proxy_set_header Accept-Encoding "";
sub_filter_types text/css text/http;
sub_filter_once off;
sub_filter /v1/ /vault_v1/;
sub_filter /ui/ /vault/ui/;
sub_filter "rel=\"stylesheet\"" "";
}
location /vault_v1/ {
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header Host $http_host;
proxy_set_header X-NginX-Proxy true;
proxy_pass http://vault/v1/;
sub_filter_types text/css text/http;
sub_filter_once off;
sub_filter /v1/ /vault_v1/;
sub_filter /ui/ /vault/ui/;
sub_filter "rel=\"stylesheet\"" "";
}
}
public-子网-proxy.conf
server {
error_page 497 https://$host:$server_port$request_uri;
auth_basic "Administrator's Area";
auth_basic_user_file /etc/apache2/.htpasswd;
listen 443 default_server ssl;
server_name example.com www.example.com;
location /vault/ {
proxy_pass http://private_subnet_proxy/vault/ui/;
}
location /vault_v1/ {
proxy_pass http://private_subnet_proxy/vault_v1/;
}
}
此 github 存储库中包含的步骤帮助我在 nginx 反向代理后面设置了 Vault UI