Linux配置nginx
作者QQ:67065435 QQ群:669756510
本站内容全部为作者原创,转载请注明出处!
日志定制
- 日志定制
log_format my_style '[$time_local] $remote_addr $status $request'; access_log logs/access.log my_style;
资源预览
下载主题ngxtheme
cd /xxx wget --no-check-certificate -c ngx_theme.tar.gz tar -xf ngx_theme.tar.gz资源预览
server { listen 80; server_name xxx.com; root /xxx; charset utf-8; location / { autoindex on; autoindex_format html; fancyindex on; fancyindex_localtime on; fancyindex_exact_size off; fancyindex_name_length 300; fancyindex_default_sort name; fancyindex_time_format "%Y-%m-%d %H:%M:%S"; # 暗色主题 # fancyindex_header "/xxx/.ngx_theme/tem-drk/header.html"; # fancyindex_footer "/xxx/.ngx_theme/tem-drk/footer.html"; # 亮色主题 # fancyindex_header "/xxx/.ngx_theme/tem-lit/header.html"; # fancyindex_footer "/xxx/.ngx_theme/tem-lit/footer.html"; } }资源加密
# 生成加密文件 yum -y --nogpgcheck install httpd-tools htpasswd -cb /xxx/pswd 账号 密码 # 修改Nginx配置 server { auth_basic '请输入账号密码'; auth_basic_user_file /xxx/pswd; }
静态缓存
静态缓存+开启Range
server { listen 80; server_name xxx.com; root /xxx; location / { add_header Cache-Control max-age=86400000; } }
开启Range
开启Range
server { listen 80; server_name xxx.com; root /xxx; location / { slice 512k; } }
防盗链
防盗链
server { listen 80; server_name xxx.com; root /xxx; location / { valid_referers none blocked *.xxx.com xxx.com; if ($invalid_referer) { return 444; } } }
静态缓存+开启Range+防盗链
静态缓存+开启Range+防盗链
server { listen 80; server_name xxx.com; root /xxx; location / { # 开启Range slice 512k; # 缓存1000天 add_header Cache-Control max-age=86400000; # 防盗链 valid_referers none blocked *.xxx.com xxx.com; if ($invalid_referer) { return 444; } } }
HTTPS支持
HTTPS支持(同时支持HTTP、HTTPS、IPV4、IPV6、H2)
server { listen 80; listen [::]:80; listen 443 ssl http2; listen [::]:443 ssl http2; server_name xxx.com; root /xxx; location / { index index.html; } ssl_session_timeout 5m; ssl_prefer_server_ciphers on; ssl_certificate /xxx/fullchain.pem; ssl_certificate_key /xxx/privkey.pem; ssl_protocols TLSv1 TLSv1.1 TLSv1.2; ssl_ciphers ALL:!ADH:!EXPORT56:RC4+RSA:+HIGH:+MEDIUM:+LOW:+SSLv2:+EXP; }
多IF判断
- 多IF判断
set $flag "0"; if ($uri = '/') { set $flag "${flag}1"; } if ($scheme = 'http') { set $flag "${flag}2"; } # 两个条件都不成立 if ($flag = '0') { # Do something... } # 只有第一个条件成立 if ($flag = '01') { # Do something... } # 只有第二个条件成立 if ($flag = '02') { # Do something... } # 两个条件都能成立 if ($flag = '012') { # Do something... }
URL重写
URL重写
server { listen 80; server_name xxx.com; rewrite ^(.*) https://www.$host$1 permanent; }
PHP-FPM
PHP部署-PHP-FPM
server { listen 80; server_name xxx.com; root /xxx; location / { index index.php index.html index.htm; } location ~* \.php { include fastcgi_params; fastcgi_index index.php; fastcgi_pass 127.0.0.1:9000; fastcgi_split_path_info ^(.+\.php)(.*)$; fastcgi_param PATH_INFO $fastcgi_path_info; fastcgi_param SCRIPT_NAME $fastcgi_script_name; fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name; } }PHP部署-symfony3
server { listen 80; server_name xxx.com; root /xxx; location / { try_files $uri /app.php$is_args$args; } location ~ ^/(app_dev|config)\.php(/|$) { fastcgi_pass 127.0.0.1:9000; fastcgi_split_path_info ^(.+\.php)(/.*)$; include fastcgi_params; fastcgi_param SCRIPT_FILENAME $realpath_root$fastcgi_script_name; fastcgi_param DOCUMENT_ROOT $realpath_root; } location ~ ^/app\.php(/|$) { fastcgi_pass 127.0.0.1:9000; fastcgi_split_path_info ^(.+\.php)(/.*)$; include fastcgi_params; fastcgi_param SCRIPT_FILENAME $realpath_root$fastcgi_script_name; fastcgi_param DOCUMENT_ROOT $realpath_root; internal; } location ~ \.php$ { return 404; } }PHP部署-路由反代
# 细节1:proxy有无'/' # ①proxy无'/' http://127.0.0.1 listen 80; server_name xxx.com; location /api/ { proxy_pass http://127.0.0.1; } # ②proxy有'/' http://127.0.0.1/ listen 80; server_name xxx.com; location /api/ { proxy_pass http://127.0.0.1/; } # 同样请求 http://xxx.com/api/user_info # ①传到proxy请求为 http://127.0.0.1/api/user_info # ②传到proxy请求为 http://127.0.0.1/user_info # 细节2:location有无'/' proxy有无'/' # ①location无'/' location /api proxy无'/' http://127.0.0.1 listen 80; server_name xxx.com; location /api { proxy_pass http://127.0.0.1; } # ②location无'/' location /api proxy有'/' http://127.0.0.1/ listen 80; server_name xxx.com; location /api { proxy_pass http://127.0.0.1/; } # ③location有'/' location /api/ proxy无'/' http://127.0.0.1 listen 80; server_name xxx.com; location /api/ { proxy_pass http://127.0.0.1; } # ④location有'/' location /api/ proxy有'/' http://127.0.0.1/ listen 80; server_name xxx.com; location /api/ { proxy_pass http://127.0.0.1/; } # 同样请求 http://xxx.com/api/user_info # ①传到proxy请求为 http://127.0.0.1/api/user_info # ②传到proxy请求为 http://127.0.0.1//user_info # ③传到proxy请求为 http://127.0.0.1/api/user_info # ④传到proxy请求为 http://127.0.0.1/user_info
反向代理
反向代理
# 反向代理 # http://127.0.0.1:8080 # 用户访问 # http://www.xxx.com server { listen 80; server_name xxx.com; location / { proxy_pass http://127.0.0.1:8080; } } # 反向代理 # http://127.0.0.1:8080 # http://127.0.0.1:8888 # 用户访问 # http://www.xxx.com server { listen 80; server_name xxx.com; location /route1 { proxy_pass http://127.0.0.1:8080; } location /route2 { proxy_pass http://127.0.0.1:8888; } }反向代理https
location /route1 { proxy_pass https://m.xxx.com:xxx; proxy_ssl_server_name on; proxy_ssl_session_reuse off; }
负载均衡
IP列表
192.168.0.1 (负载均衡服务器) 192.168.0.2 (WEB 服务器1) 192.168.0.3 (WEB 服务器2)相关配置
#均询式负载均衡 upstream load_blc { server 192.168.0.2:80; server 192.168.0.3:80; } #权重式负载均衡 #upstream load_blc { # server 192.168.0.2:80 weight=10; # server 192.168.0.3:80 weight=10; #} #容错式负载均衡 #upstream load_blc { # server 192.168.0.2:80 max_fails=10; # server 192.168.0.3:80 max_fails=10; #} #ip_hash负载均衡(session兼容好) #upstream load_blc { # ip_hash; # server 192.168.0.2:80; # server 192.168.0.3:80; #} #fair负载均衡(响应最快服务器优先分配给用户) #upstream load_blc { # fair; # server 192.168.0.2:80; # server 192.168.0.3:80; #} #url_hash负载均衡(后端服务器为缓存时效果较好) #upstream load_blc { # server 192.168.0.2:80; # server 192.168.0.3:80; # hash $request_uri; # hash_method crc32; #} #upstream中server格式: #server ip:port [down|weight=?|max_fails|fail_timeout|backup]; #down: 表示单前的server暂时不参与负载 #weight: 默认为1.weight越大,负载的权重就越大。 #max_fails: 允许请求失败的次数默认为1.当超过最大次数时,返回proxy_next_upstream模块定义的错误 #fail_timeout: max_fails次失败后,暂停的时间。 #backup: 其它所有的非backup机器down或者忙的时候,请求backup机器。所以这台机器压力会较小。 server { listen 80; server_name www.xxx.com; location / { proxy_redirect default; proxy_set_header Host $host; proxy_pass http://load_blc; } }注意事项
nginx支持同时设置多组的负载均衡,用来给不同的负载均衡server来使用。 client_body_in_file_only: 设置为On 可以讲client post过来的数据记录到文件中用来做debug client_body_temp_path: 设置记录文件的目录 可以设置最多3层目录 location: 对URL进行匹配.可以进行重定向或者进行新的代理 负载均衡
响应异常
响应数据部分丢失报错如下。
# nginx响应数据不完整、丢失、缺失、缺少一部分 # net::ERR_INCOMPLETE_CHUNKED_ENCODING异常原因1(nginx php)
fastcgi_send_timeout 10s; fastcgi_read_timeout 10s; fastcgi_buffers 4 2048k; fastcgi_buffer_size 2048k; fastcgi_busy_buffers_size 6144k;异常原因2(nginx proxy)
proxy_send_timeout 10s; proxy_read_timeout 10s; proxy_buffers 4 2048k; proxy_buffer_size 2048k; proxy_busy_buffers_size 6144k;异常原因3(缓存目录权限问题)
# 获取运行nginx子进程的用户 ps aux|grep nginx|grep 'S '|awk '{print $1}'|uniq # 修改nginx相关文件用户归属 chown -R [用户组:用户名] /xxx/nginx/client_body_temp chown -R [用户组:用户名] /xxx/nginx/fastcgi_temp chown -R [用户组:用户名] /xxx/nginx/proxy_temp chown -R [用户组:用户名] /xxx/nginx/scgi_temp chown -R [用户组:用户名] /xxx/nginx/uwsgi_temp