网站绑定域名后直接通过域名访问使用的是 80 端口,因此 tomcat 须监听 80 端口,而为了安全起见 tomcat 一般不用 root 身份运行,综上,需要以普通用户来运行监听 80 端口的 tomcat。此时就会启动失败,报没有权限,因为只有 root 身份才能监听 1024 以下的熟知端口。



There are a few different solutions to work around this:

  1. Install and configure Apache or nginx as a reverse proxy server, which can be started as root to open the port, and then downgrade its privileges back to a normal user.
  2. Set up a firewall on the server using iptables or an alternative, so that the lower port number is forwarded internally to a higher port number listened by Confluence.
  3. Use jsvc, which is able to open ports as root, and then downgrade privileges.
  4. Use authbind to grant privileges for a non-root user to open a privileged port.

1、通过 iptables 进行端口转发

  1. tomcat 监听 8080(其他非熟知端口皆可)端口,直接执行 sudo iptables -t nat -A PREROUTING -p tcp –dport 80 -j REDIRECT –to-port 8080 将对 80 端口的请求转发到 8080 端口。
  2. iptables 规则设置后都是即时生效的,但在机器重启后 iptables 中的配置信息会被清空。因此可以将这些配置保存下来,让 iptables 在 interface 启动时自动被加载:

(1)保存防火墙规则:sudo iptables-save > /etc/zsmiptables.rules 

(2)编辑 /etc/network/interfaces,在末尾加一行:pre-up iptables-restore < /etc/zsmiptables.rules


(前者言将 iptables-restore < /etc/zsmiptables.rules 放到一脚本里置于 /etc/network/if-pre-up.d/ 下,但一直不成功;改用后者所言将 iptables-restore < /etc/zsmiptables.rules 加到 /etc/network/interfaces 末尾成功了)

2、通过 isvc

jsvc 能以 root 角色使用端口,因此借助之即可。另外,这种方式也把 tomcat 做成了服务,能够开机自己启动。

