Nginx OSM tiles caching proxy with https upstream

Viewed 762

I have the old nginx-based OSM tile caching proxy configured by https://coderwall.com/p/--wgba/nginx-reverse-proxy-cache-for-openstreetmap, but as source tile server migrated to HTTPS this solution is not working anymore: 421-Misdirected Request.

The fix I based on the article https://kimsereyblog.blogspot.com/2018/07/nginx-502-bad-gateway-after-ssl-setup.html. Unfortunately after days of experiments - I'm still getting 502 error.

My theory is that the root cause is the upstream servers SSL certificate which uses wildcard: *.tile.openstreetmap.org but all attempts to use $http_host, $host, proxy_ssl_name, proxy_ssl_session_reuse in different combinations did't help: 421 or 502 every time.

My current nginx config is:

worker_processes auto;

events {
  worker_connections 768;
}

http {

  access_log /etc/nginx/logs/access_log.log;
  error_log /etc/nginx/logs/error_log.log;

  client_max_body_size 20m;

  proxy_cache_path  /etc/nginx/cache levels=1:2 keys_zone=openstreetmap-backend-cache:8m     max_size=500000m inactive=1000d;
  proxy_temp_path   /etc/nginx/cache/tmp;

  proxy_ssl_trusted_certificate /etc/nginx/ca.crt;
  proxy_ssl_verify on;
  proxy_ssl_verify_depth 2;
  proxy_ssl_session_reuse on;
  proxy_ssl_name *.tile.openstreetmap.org;

  sendfile on;

  upstream openstreetmap_backend {
    server  a.tile.openstreetmap.org:443;
    server  b.tile.openstreetmap.org:443;
    server  c.tile.openstreetmap.org:443;
  }

  server {
    listen               80;
    listen                   [::]:80;
    server_name          example.com www.example.com;

    include /etc/nginx/mime.types;

    root /dist/browser/;

    location ~ ^/osm-tiles/(.+) {

        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X_FORWARDED_PROTO http;
        proxy_set_header Host $http_host;
        proxy_cache openstreetmap-backend-cache;
        proxy_cache_valid  200 302  365d;
        proxy_cache_valid  404      1m;
        proxy_redirect off;
        if (!-f $request_filename) {
            proxy_pass https://openstreetmap_backend/$1;
            break;
        }
    }
  }
}

But it still produces error when accessing https://example.com/osm-tiles/12/2392/1188.png:

2021/02/28 15:05:47 [error] 23#23: *1 upstream SSL certificate does not match "*.tile.openstreetmap.org" while SSL handshaking to upstream, client: 172.28.0.1, server: example.com, request: "GET /osm-tiles/12/2392/1188.png HTTP/1.0", upstream: "https://151.101.2.217:443/12/2392/1188.png", host: "localhost:3003"

Host OS Ubuntu 20.04 (here https is handled), nginx is runnig on docker from nginx:latest image, ca.crt is the default ubuntu's crt.

Please help.

0 Answers
Related