Kind of a newbie question, hopefully I'm on the right tracks :)
I have a FastAPI web server hosting some endpoint APIs for some IOS app I'm working on.
My webserver is running on an AWS EC2 machine using GUNICORN & Docker.
At first, I've hosted my webserver running simple HTTP, with the following Dockerfile:
WORKDIR /app
COPY . /app
# add files to Docker environment
...
# run app
RUN pip install -r requirements.txt
EXPOSE 80
CMD ["gunicorn", "-b", "0.0.0.0:80", "-k", "uvicorn.workers.UvicornWorker", "main:app"]
This worked perfectly, and I was able to access my APIs using http://<ec2-machine-public-ip>/...
However, I want to make sure all communications between a client (app-user) and my server are secure using HTTPS.
Since I only want to use my webserver for hosting APIs (and don't actually want anyone accessing the routes via browser), I figured a self-signed certificate would suffice (despite browser warnings).
To do that, I've generated self-signed certificates with OpenSSL using the following command:
openssl req -x509 -newkey rsa:4096 -keyout key.pem -out cert.pem -days 365
This created cert.pem and key.pem files.
Then, I attempted running with HTTPS with the following Dockerfile:
FROM tiangolo/uvicorn-gunicorn-fastapi:python3.7
WORKDIR /app
COPY . /app
# add files to Docker environment
...
# run app
RUN pip install -r requirements.txt
EXPOSE 433
CMD ["gunicorn", "-b", "0.0.0.0:433", "--keyfile", "key.pem", "--certfile", "cert.pem", "-k", "uvicorn.workers.UvicornWorker", "main:app"]
Unfortunately, when I try to access my APIs using https://<ec2-machine-public-ip>/... - I get an error: "This site can't be reached".
I should mention that everything looks normal in my container's logs:
[2020-11-13 17:02:56 +0000] [1] [INFO] Starting gunicorn 20.0.4
[2020-11-13 17:02:56 +0000] [1] [INFO] Listening at: https://0.0.0.0:433 (1)
[2020-11-13 17:02:56 +0000] [1] [INFO] Using worker: uvicorn.workers.UvicornWorker
[2020-11-13 17:02:56 +0000] [8] [INFO] Booting worker with pid: 8
[2020-11-13 17:02:56 +0000] [8] [INFO] Started server process [8]
2020-11-13 17:02:56,490 Started server process [8]
[2020-11-13 17:02:56 +0000] [8] [INFO] Waiting for application startup.
2020-11-13 17:02:56,491 Waiting for application startup.
[2020-11-13 17:02:56 +0000] [8] [INFO] Application startup complete.
2020-11-13 17:02:56,491 Application startup complete.
BTW, my EC2 machine has port 443 open for HTTPS from all IP addresses (Here's a screenshot from my machine's security group inbound-rules).
What am I doing wrong?
Any help is appreciated!