ARTICLE · INTELLIGENCE

战地情报 · 详情页

来自尧图项目组的一线实战观察与深度解析

一文带你搞懂Nginx,老王出品,必属精品

一文带你搞懂Nginx,老王出品,必属精品 前言Nginx (engine x) 是一个高性能的HTTP和反向代理web服务器同时也提供了IMAP/POP3/SMTP服务一、nginx 基础常用命令1. ./nginx -t #检查配置文件的语法的正确性并尝试打开配置文件中所引用到的文件。 2. ./nginx -c /home/xx/nginx.conf #指定一个配置文件来代替缺省的。 3. ./nginx -v #nginx 的版本。 4. ./nginx -s reload #reload 会重新加载配置文件Nginx服务不会中断。而且reload时会测试conf语法等。 5. ./nginx #启动nginx。 6. ./nginx -s stop #stop 会立即停止服务这种方法比较强硬无论进程是否在工作都直接停止进程。 7. ./nginx -s quit #quit 较stop相比就比较温和一些了需要进程完成当前工作后再停止。nginx的Nginx 处理请求的路由机制# 块 A你的真实业务 server { listen 8080 ssl; server_name www.baidu.com; # ... 业务配置 } # 块 B兜底配置 server { listen 8080 ssl default_server; server_name _; return 403; } listen 8080 ssl default_server; 配置讲解Nginx 对 default_server 的校验非常严格对于任何一个特定的监听地址例如 0.0.0.0:15080只能有一个 server 块被标记为 default_server。 server_name _; 配置讲解在 Nginx 中下划线 _ 没有任何特殊的技术含义。它的作用纯粹是 “语义化” 和 “约定俗成”二、nginx 配置反向代理转发rewrite、proxy_pass# rewrite 关键字使用场景 rewrite regex replacement [flag]; regex 表示正则匹配规则。 replacement 表示跳转后的内容。 flag 表示 rewrite 支持的 flag 标记。 flag标记说明 last 本条规则匹配完成后不终止重写后的url匹配一般用在 server 和 if 中。 break 本条规则匹配完成即终止终止重写后的url匹配一般使用在 location 中。 redirect 返回302临时重定向浏览器地址会显示跳转后的URL地址。 permanent 返回301永久重定向浏览器地址栏会显示跳转后的URL地址。 # rewrite permanent (301永久重定向浏览器地址栏会显示跳转后的URL地址) 用法 # 请求url http://127.0.0.1:8080/abc/index.html location /abc { rewrite (.) http://www.yy.com/bbs$1 permanent; } # 通过rewrite permanent用户的浏览器地址栏会发生变化(301永久重定向) # 直接跳转到http://www.yy.com/bbs/abc/index.html # rewrite permanent (执行顺序 rewrite 永远先于 proxy_pass 执行) 用法 # 请求url http://127.0.0.1:8080/abc/index.html location /abc { # 浏览器会直接跳转到 yy.com请求到此为止 rewrite ^/abc/(.*)$ http://www.yy.com/bbs/$1 permanent; # 这行代码永远不会被执行 proxy_pass http://127.0.0.1:8080; } # 通过rewrite permanent重定向url地址为http://www.yy.com/bbs/index.html # rewrite break (本条规则匹配完成即终止终止重写后的url匹配) 用法 # 请求url http://127.0.0.1:8080/app_service/applog/index.html location ~ ^/app_service/(applog|watch) { rewrite ^/app_service/(.*)$ /chinaunicom/$1 break; proxy_pass http://127.0.0.1:19080; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; } # 通过 rewrite breakURI 被内部修改为 /chinaunicom/applog/index.html # proxy_pass 代理地址http://127.0.0.1:8080/chinaunicom/applog/index.html # rewrite last (本条规则匹配完成后不终止重写后的url匹配) 用法 # 请求url http://127.0.0.1:8080/abc/test location /abc { # 把 /abc/test 重写为 /bbs/test然后拿着 /bbs/test 重新去匹配 location rewrite ^/abc/(.*)$ /bbs/$1 last; # 这行代码会被跳过因为 Nginx 跑去重新匹配 location 了 proxy_pass http://127.0.0.1:8080; } # 如果请求变成了 /bbs/test就会匹配到这里 location /bbs { proxy_pass http://127.0.0.1:9090; # 最终执行的是这个代理 } # 通过rewrite last代理转发的url地址为http://127.0.0.1:9090/bbs/test #location 带/结尾 # 请求url http://127.0.0.1:8080/proxy/index.html location /proxy { rewrite ^/proxy/(.*)$ /$1 break; proxy_pass http://127.0.0.1:8080; } # 通过rewrite break代理转发的url地址为http://127.0.0.1:8080/index.html location /proxy/ { proxy_pass http://127.0.0.1:8080/; } # 代理地址以 / 结尾代理转发的url地址为http://127.0.0.1:8080/index.html location /proxy/ { proxy_pass http://127.0.0.1:8080; } # 代理地址不以 / 结尾代理转发的url地址为http://127.0.0.1:8080/proxy/index.html location /proxy/ { proxy_pass http://127.0.0.1:8080/tomcat/; } # 代理地址以 tomcat/ 结尾代理转发的url地址为http://127.0.0.1:8080/tomat/index.html location /proxy/ { proxy_pass http://127.0.0.1:8080/tomcat; } # 代理地址以 tomcat 代理转发的url地址为http://127.0.0.1:8080/proxytomcat/index.html #location 不带/结尾 location /proxy { proxy_pass http://127.0.0.1:8080/tomcat; } # 代理地址以 tomcat 代理转发的url地址为http://127.0.0.1:8080/tomcat/index.html location /proxy { proxy_pass http://127.0.0.1:8080/; } # 代理地址以 / 代理转发的url地址为http://127.0.0.1:8080//index.html location /proxy { proxy_pass http://127.0.0.1:8080; } # 代理地址不以 / 代理转发的url地址为http://127.0.0.1:8080/proxy/index.html #alias与root location / { alias /www/abc/; } # 当匹配路径为 / 时alias引用的路径结尾 “需要加 /” location /test/ { alias /www/abc/; } # 使用alias当访问/test/时会到/www/abc/目录下找文件 location / { root /www/abc; } # 当匹配路径为 / 时root引用的路径结尾 “不需要加 /” location /test/ { root /www/abc; } # 使用root当访问/test/时会到/www/abc/test/目录下找文件如果没有test目录会报403 #多层nginx代理Websocket服务 location /secure/socket { add_header backendIP $upstream_addr; add_header backendCode $upstream_status; proxy_redirect off; proxy_connect_timeout 6000; proxy_read_timeout 6000; proxy_send_timeout 6000; proxy_set_header Host 192.168.9.101:8087; proxy_pass http://localhost:8080/websocket/web; proxy_http_version 1.1; proxy_set_header Upgrade $http_upgrade; proxy_set_header Connection upgrade; proxy_set_header token $arg_username; } #多层nginx代理Java服务 #主机127.0.0.1下的nginx配置port8081 location /local/app/ { proxy_pass http://10.9.103.36:8081/; } #主机10.9.103.36下的nginx配置port8081 location /chat/ { proxy_pass http://10.186.253.117:8081/; } #多层nginx代理HTML资源 #主机10.9.103.35下的nginx配置port8083 location ^~ /html/chat/ { #符号^~一旦匹配到就不继续匹配(静态资源匹配) proxy_pass http://10.9.103.36:8081/; } #主机10.9.103.36下的nginx配置port8081(下图为html资源目录结构) location /mystatic { root html; index index.html index.htm; }//真实提供服务的为10.186.253.117:8081这个服务多层nginx代理Java服务Stringurlhttp://127.0.0.1:8081/local/app/chat/LargeModelLayout/session/sso;HashMapString,ObjectrequestBodynewHashMap(1);requestBody.put(app,kuandai);MapString,ObjectobjectMapHttpUtils.doJsonGet(url,newHashMap(0),requestBody);//Java多层代理分析//http://127.0.0.1:8081/local/app 匹配到第一层nginx代理转发到http://10.9.103.36:8081/;//http://10.9.103.36:8081/chat 匹配到第二层nginx代理转发到http://10.186.253.117:8081/;//最终格式url为http://10.186.253.117:8081/LargeModelLayout/session/sso//由http://10.186.253.117:8081/LargeModelLayout/session/sso提供服务//真实HTML资源由10.9.103.36:8083提供服务多层nginx代理HTML资源Stringurlhttp://10.9.103.35:8083/html/chat/mystatic/;//HTML多层代理分析//http://10.9.103.35:8083/html/chat/ 匹配到第一层nginx代理转发到http://10.9.103.36:8081///http://10.9.103.36:8081/mystatic/ 匹配到第二次nginx静态资源目录(html/mystatic)//最终格式url为http://10.9.103.36:8081/mystatic/index.html//请注意上文静态资源配置的注意事项三、nginx 配置负载均衡策略默认为轮询策略支持 轮循 Round Robin、加权轮循 Weighted Round Robin、最少连接数 Least Connection、源 IP 哈希 Source IP Hash等多种策略upstream webservers{ server 127.0.0.1:8080; server 127.0.0.1:8081; server 127.0.0.1:8082; } location / { #转发到负载服务上 proxy_pass http://webservers; }四、openssl生成证书1. openssl生成ssl证书1.1. 下载opens ssl并安装http://slproweb.com/products/Win32OpenSSL.html 官网地址1.2. 安装openssl且配置环境变量新增系统变量变量名 OPENSSL_HOME 变量值 D:\Program Files\OpenSSL-Win64\bin(以自己实际安装路径为准)1.3. 在path变量内新增内容 %OPENSSL_HOME%1.4. 在 ssl 文件夹下执行命令行操作1.4.1.创建私钥: openssl genrsa -des3 -out nj.key 10241.4.2.创建csr证书openssl req -new -key nj.key -out nj.csr1.4.3.复制文件 copy nj.key nj.key.copy1.4.4.去除密码 openssl rsa -in nj.key.copy -out nj.key1.4.4.生成 crt 证书 openssl x509 -req -days 365 -in nj.csr -signkey nj.key -out nj.crt五、nginx 配置ssl、 实现http转https1.1.nginx.conf配置文件#user nobody; worker_processes 1; #error_log logs/error.log; #error_log logs/error.log notice; #error_log logs/error.log info; #pid logs/nginx.pid; events { worker_connections 1024; } http { include mime.types; default_type application/octet-stream; #log_format main $remote_addr - $remote_user [$time_local] $request # $status $body_bytes_sent $http_referer # $http_user_agent $http_x_forwarded_for; #access_log logs/access.log main; sendfile on; #tcp_nopush on; #keepalive_timeout 0; keepalive_timeout 65; #gzip on; server { listen 443 ssl; server_name mt.hello.com; #ssl on; ssl_certificate ../ssl/nj.crt; ssl_certificate_key ../ssl/nj.key; ssl_session_cache shared:SSL:1m; ssl_session_timeout 5m; ssl_ciphers HIGH:!aNULL:!MD5; ssl_prefer_server_ciphers on; location /chat/ { proxy_pass http://jd.hello.com:8089; } } server { listen 80; #填写绑定证书的域名 server_name mt.hello.com; #强制将http的URL重写成https rewrite ^(.*) https://$server_name$1 permanent; } server { listen 8081; server_name mt.hello.com; location /chat/ { proxy_pass http://jd.hello.com:8089; } location /proxy/nginx/ { if ($host mt.hello.com) { rewrite ^(.*)$ http://jd.hello.com/$1 permanent; } proxy_pass http://jd.hello.com:8089/; } location /proxy/ { if ($host mt.hello.com) { rewrite ^(.*)$ http://www.baidu.com permanent; } proxy_pass http://jd.hello.com:8089/; } location /error/ { if ($host jd.hello.com) { return 404; } proxy_pass http://jd.hello.com:8089/; } error_page 404 /404.html; error_page 500 502 503 504 /50x.html; location /50x.html{ root html; } location /404.html{ root html; } location /mystatic { root html; index index.html index.htm; } } }1.2.配置ssl证书443为https的默认端口、实现http协议转https协议六、nginx 配置rewrite实现新旧域名平滑更换、配置错误代码转发七、静态资源映射location/error/{if($hostjd.hello.com){return404;}proxy_pass http://jd.hello.com:8089/;}error_page404/404.html;error_page500502503504/50x.html;location/50x.html{root html;}location/404.html{root html;}#https://mt.hello.com/mystatic/index.html location/mystatic{root html;index index.html index.htm;}#https://mt.hello.com/request/request.html location/request{root html;index index.html index.htm;}#https://mt.hello.com/slider/src/images/Pic0.jpg location/slider{root html;index index.html index.htm;}七、nginx快速安装教程(nginx-1.22.1-版本)rpm-qa|grep gcc yum-y install gcc zlib-devel openssl-devel pcre-devel groupadd nginx useradd-r-g nginx-s/sbin/nologin nginx cd nginx-1.22.1/./configure--usernginx--groupnginx--prefix/usr/local/nginx--with-http_ssl_module makemake install lscpu|grep ^CPU(s)|awk {print $2} cd/usr/local/nginxvim conf/nginx.conf server_tokens off;ln-s/usr/local/nginx/sbin/nginx/usr/sbin/nginx-Vnginx-s reload curl-I127.0.0.1
RELATED READING

延伸阅读

更多一线实战笔记与深度复盘,助您持续精进