# 使用官方 Nginx 镜像 FROM nginx:09051708 # 维护者信息 LABEL maintainer="awei" LABEL description="HTTP server with SSL support" # 复制配置文件 # 先清理基础镜像中可能残留的旧配置,再写入新配置 # conf.d 只放不依赖证书的常驻配置(80 端口:ACME 验证 + HTTPS 跳转) COPY nginx.conf /etc/nginx/nginx.conf RUN rm -rf /etc/nginx/conf.d/* COPY conf.d /etc/nginx/conf.d COPY verification.html /usr/share/nginx/html/verification.html # 创建日志目录与 HTTPS 配置目录 # ssl.d 必须存在:nginx.conf 里的 wildcard include 在目录不存在时会报 emerg RUN mkdir -p /var/log/nginx /etc/nginx/ssl.d # 暴露端口 EXPOSE 80 EXPOSE 8443 # 健康检查:/healthz 固定返回 200,不跟随 301,冷启动阶段也不会误判 HEALTHCHECK --interval=30s --timeout=3s --start-period=5s --retries=3 \ CMD wget --quiet --tries=1 -O /dev/null http://127.0.0.1/healthz || exit 1 # 启动 Nginx CMD ["nginx", "-g", "daemon off;"]