Hashicorp Vault UI - 无法在 'integrity' 属性中找到有效的摘要...资源已被阻止

Hashicorp Vault UI - Failed to find a valid digest in the 'integrity' attribute ... The resource has been blocked

我在私有子网中托管 Vault 和 Consul 服务器,在这个私有子网中我有专用实例作为反向代理服务器,假设该实例称为 (private_subnet_proxy)。

为了能够使用 public 中的 Consul 和 Vault 的 UI,我专门使用了一个 public 实例作为 public 中的反向代理网络进入 private_subnet_proxy.

Consul 的 UI 与我使用的方法配合得很好(在 private-subnet-proxy.conf 和 [= 的配置中有详细说明30=]public-子网-proxy.conf ).但是,当我尝试调用 Vault 的 UI 时,出现了一个奇怪的错误。

Failed to find a valid digest in the 'integrity' attribute for resource 'https://example.com/vault/ui/assets/vendor-170f8056c4a9bc57b01e6b288c9056e5.js' with computed SHA-256 integrity 'Vl+es41l9uLYuOXW/5b17aSw8jo6h94D00opmpuhryY='. The resource has been blocked.

有没有其他人遇到过这个问题并可以帮助我解决这个问题?如果有任何想法或建议,我将不胜感激。

私有子网-proxy.conf

server {

    listen 80;
    listen [::]:80;
  
    

upstream vault {
    server vault_instance:8200;
}

    location  /vault/ui/ {


        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header Host $http_host;
        proxy_set_header X-NginX-Proxy true;
      

        resolver 127.0.0.1;
        allow "127.0.0.1";
        allow "10.10.1.12";
        deny   all;

        proxy_pass http://vault/ui/;
        
        proxy_set_header Accept-Encoding "";
        sub_filter_types text/css text/http;

        sub_filter_once off;
        sub_filter /v1/ /vault_v1/;
        sub_filter /ui/ /vault/ui/;
        sub_filter "rel=\"stylesheet\"" "";




    }

    location /vault_v1/ {

        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header Host $http_host;
        proxy_set_header X-NginX-Proxy true;
        

        proxy_pass http://vault/v1/;

        sub_filter_types text/css text/http;
        sub_filter_once off;
        sub_filter /v1/ /vault_v1/;
        sub_filter /ui/ /vault/ui/;
        sub_filter "rel=\"stylesheet\"" "";



    }

}

public-子网-proxy.conf

    server {

        error_page 497 https://$host:$server_port$request_uri;

        auth_basic           "Administrator's Area";
        auth_basic_user_file /etc/apache2/.htpasswd;
        listen 443 default_server ssl;
        server_name example.com www.example.com;


           location /vault/ {


            proxy_pass http://private_subnet_proxy/vault/ui/;



        }

        location /vault_v1/ {



            proxy_pass http://private_subnet_proxy/vault_v1/;
            

        }


}

此 github 存储库中包含的步骤帮助我在 nginx 反向代理后面设置了 Vault UI

https://github.com/Folcky/hashicorp-vault-and-nginx