在 macOS 上搭建自动化 SSL 反向代理环境需:①用真实域名并解析至本机公网 IP;②用 Certbot standalone 模式申请证书;③Nginx 配置多 server 块绑定证书并 proxy_pass;④通过 launchd 设置 weekly renew + nginx reload。
在 macos 上搭建支持自动化 ssl 证书申请与续期的本地反向代理环境,核心是组合使用 certbot(或 acme.sh) + nginx + 域名解析基础。不需要复杂编译或自建 ca,重点在于让验证流程能走通、证书能自动更新、nginx 能热加载新证书。
准备域名与网络基础
SSL 自动化依赖真实可解析的域名(不能只用 localhost)。你需要:
- 一个已注册的域名(如
example.com),并能登录其 DNS 管理后台 - 将该域名(及需要覆盖的子域名,如
www.example.com、api.example.com)全部解析到你 macOS 的公网 IP(若在内网,需配置路由器端口映射:80/443 → 本机) - 确保 macOS 防火墙允许入站 80 和 443 端口(系统设置 → 网络 → 防火墙选项 → 允许传入连接)
安装 Certbot 并申请首张证书
推荐用 Homebrew 安装 Certbot(稳定、易更新):
brew install certbot
运行 standalone 模式一次性申请多域名证书(Certbot 会临时起一个 HTTP 服务监听 80 端口完成验证):
sudo certbot certonly --standalone -d example.com -d www.example.com -d api.example.com
成功后证书存于:/etc/letsencrypt/live/example.com/fullchain.pem(证书链)/etc/letsencrypt/live/example.com/privkey.pem(私钥)
配置 Nginx 反向代理并绑定证书
为每个要代理的服务(比如本地运行在 3000 端口的前端、8010 端口的 Buildbot)单独写一个 server 块,监听 443,严格匹配 server_name:
macOS 微信消息自动化工具。通过 GUI 自动化实现:发送消息给指定联系人、读取聊天内容、监控新消息。适用于需要自动化微信操作的场景,如定时发送、批量回复、消息备份等。依赖 peekaboo 进行屏幕截图和 UI 交互。仅支持 macOS。开源地址:https://github.com/chairmanmia...
server {
listen 443 ssl http2;
server_name example.com www.example.com;
ssl_certificate /etc/letsencrypt/live/example.com/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/example.com/privkey.pem;
location / {
proxy_pass http://127.0.0.1:3000;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
}
}
server {
listen 443 ssl http2;
server_name api.example.com;
ssl_certificate /etc/letsencrypt/live/example.com/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/example.com/privkey.pem;
location / {
proxy_pass http://127.0.0.1:8010;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
}
}
保存后测试配置并重载:
sudo nginx -t && sudo nginx -s reload
启用自动续期并验证流程
Certbot 自带续期机制,但 macOS 默认不启用定时任务。手动添加 launchd 任务:
- 创建 plist 文件:
~/Library/LaunchAgents/homebrew.mxcl.certbot.plist - 内容填入每周二凌晨 2:15 执行 renew(Certbot 会跳过未到期证书):
<dict>
<key>Label</key>
<string>homebrew.mxcl.certbot</string>
<key>ProgramArguments</key>
<array>
<string>certbot</string>
<string>renew</string>
<string>--quiet</string>
<string>--post-hook</string>
<string>nginx -s reload</string>
</array>
<key>StartCalendarInterval</key>
<dict>
<key>Hour</key>
<integer>2</integer>
<key>Minute</key>
<integer>15</integer>
<key>Weekday</key>
<integer>2</integer>
</dict>
</dict>
加载并启动:
launchctl load ~/Library/LaunchAgents/homebrew.mxcl.certbot.plist launchctl start homebrew.mxcl.certbot
✅ 续期成功时,--post-hook 会自动重载 Nginx,无需人工干预。

















