nginx.conf nginx反向代理配置文件

nginx反向代理配置文件

  • nginx.conf
  • proxy_default.conf
  • vhost/*.conf
  • upstream/*.conf
  • cache/*.conf

nginx.conf 配置

user  www;
worker_processes  2;
pid /var/run/nginx.pid;
worker_cpu_affinity auto;
worker_rlimit_nofile 65535;

events {
    use epoll;
    worker_connections  65535;
}

http {
include /usr/local/nginx/conf/autoconfig/proxy_default.conf;
include /usr/local/nginx/conf/autoconfig/vhost/*.conf;
include /usr/local/nginx/conf/autoconfig/upstream/*.conf;
include /usr/local/nginx/conf/autoconfig/cache/*.conf;
include /usr/local/nginx/conf/include/*.conf;

map $host $node_ip {
    default "192.168.1.87";
}

    server {
        listen 80 default_server;
        server_name  _;
        root html;
        client_body_buffer_size 2m;
        client_header_buffer_size 2m;

        location / {
        return       403;
        }

        location = /_.gif {
            empty_gif;
        }
    }

    server {
        listen 443 ssl default_server;
        server_name _;
        ssl_certificate /usr/local/nginx/nginx.crt;
        ssl_certificate_key /usr/local/nginx/nginx.key;
        return       403;
    }

}

proxy_default.conf 默认reverse proxy配置

include mime.types;
default_type "text/html";
charset utf-8;
log_format main ‘$time_local{G;}$remote_addr{G;}$http_host{G;}$request_uri{G;}$upstream_cache_status{G;}$status{G;}$upstream_addr{G;}$upstream_status{G;}$upstream_response_time{G;}$request_time{G;}$body_bytes_sent{G;}$request_length{G;}$content_length{G;}$sent_http_cache_control{G;}$sent_http_content_type{G;}$http_referer{G;}$http_x_forwarded_for{G;}$http_user_agent{G;}$node_ip{G;}$geoip2_data_country_code{G;}$geoip2_data_city_name{G;}$geoip2_data_province_isocode{G;}$server_port{G;}$server_protocol{G;}$request_method{G;}$scheme{G;}$ssl_protocol{G;}$remote_port{G;}$mobile_request{G;}$http_cookie{G;}$args‘;

log_format json ‘{"@timestamp":"$time_local",‘
                ‘"remote_addr":"$remote_addr",‘
                ‘"http_host":"$http_host",‘
                ‘"request_uri":"$request_uri",‘
                ‘"upstream_cache_status":"$upstream_cache_status",‘
                ‘"status":"$status",‘
                ‘"upstream_addr":"$upstream_addr",‘
                ‘"upstream_status":"$upstream_status",‘
                ‘"upstream_response_time":"$upstream_response_time",‘
                ‘"request_time":"$request_time",‘
                ‘"body_bytes_sent":"$body_bytes_sent",‘
                ‘"request_length":"$request_length",‘
                ‘"content_length":"$content_length",‘
                ‘"sent_http_cache_control":"$sent_http_cache_control",‘
                ‘"sent_http_content_type":"$sent_http_content_type",‘
                ‘"http_referer":"$http_referer",‘
                ‘"http_x_forwarded_for":"$http_x_forwarded_for",‘
                ‘"http_user_agent":"$http_user_agent",‘
                ‘"node_ip":"$node_ip",‘
                ‘"geoip2_data_country_code":"$geoip2_data_country_code",‘
                ‘"geoip2_data_city_name":"geoip2_data_city_name",‘
                ‘"geoip2_data_province_isocode":"$geoip2_data_province_isocode",‘
                ‘"server_port":"$server_port",‘
                ‘"server_protocol":"$server_protocol",‘
                ‘"request_method":"$request_method",‘
                ‘"scheme":"$scheme",‘
                ‘"ssl_protocol":"$ssl_protocol",‘
                ‘"remote_port":"$remote_port",‘
                ‘"mobile_request":"$mobile_request",‘
                ‘"http_cookie":"$http_cookie",‘
                ‘"args":"$args"}‘;

access_log logs/access.json.log json;
access_log logs/access.log main buffer=4k flush=10s;
open_log_file_cache max=1024 inactive=10s valid=10s min_uses=1;

server_tokens  off;
ssl_session_cache shared:SSL:50m;

resolver 8.8.8.8 8.8.4.4 1.1.1.1 valid=600s ipv6=off;
resolver_timeout 30s;

etag on;
sendfile on;
send_timeout 3600s;
tcp_nopush on;
keepalive_timeout 3600;
keepalive_requests 360000;
server_names_hash_bucket_size 4096;
server_names_hash_max_size 4096;
client_header_buffer_size 128k;
large_client_header_buffers 32 128k;
client_max_body_size 300M;
client_header_timeout 36000;
connection_pool_size 4096;
proxy_connect_timeout 360000;
proxy_send_timeout 360000;
proxy_read_timeout 360000;
proxy_headers_hash_max_size 51200;
proxy_headers_hash_bucket_size 6400;
underscores_in_headers on;

ssl_protocols               TLSv1 TLSv1.1 TLSv1.2 TLSv1.3;
ssl_ciphers                 ‘ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:DHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-CHACHA20-POLY1305:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA384:DHE-RSA-AES256-SHA256:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256:DHE-RSA-AES128-SHA256:ECDHE-ECDSA-AES256-SHA:ECDHE-RSA-AES256-SHA:DHE-RSA-AES256-SHA:ECDHE-ECDSA-AES128-SHA:ECDHE-RSA-AES128-SHA:DHE-RSA-AES128-SHA:RSA-PSK-AES256-GCM-SHA384:DHE-PSK-AES256-GCM-SHA384:RSA-PSK-CHACHA20-POLY1305:DHE-PSK-CHACHA20-POLY1305:ECDHE-PSK-CHACHA20-POLY1305:AES256-GCM-SHA384:PSK-AES256-GCM-SHA384:PSK-CHACHA20-POLY1305:RSA-PSK-AES128-GCM-SHA256:DHE-PSK-AES128-GCM-SHA256:AES128-GCM-SHA256:PSK-AES128-GCM-SHA256:AES256-SHA256:AES128-SHA256:ECDHE-PSK-AES256-CBC-SHA384:ECDHE-PSK-AES256-CBC-SHA:SRP-RSA-AES-256-CBC-SHA:SRP-AES-256-CBC-SHA:RSA-PSK-AES256-CBC-SHA384:DHE-PSK-AES256-CBC-SHA384:RSA-PSK-AES256-CBC-SHA:DHE-PSK-AES256-CBC-SHA:AES256-SHA:PSK-AES256-CBC-SHA384:PSK-AES256-CBC-SHA:ECDHE-PSK-AES128-CBC-SHA256:ECDHE-PSK-AES128-CBC-SHA:SRP-RSA-AES-128-CBC-SHA:SRP-AES-128-CBC-SHA:RSA-PSK-AES128-CBC-SHA256:DHE-PSK-AES128-CBC-SHA256:RSA-PSK-AES128-CBC-SHA:DHE-PSK-AES128-CBC-SHA:AES128-SHA:PSK-AES128-CBC-SHA256:PSK-AES128-CBC-SHA‘;
ssl_prefer_server_ciphers   on;
ssl_session_timeout 1d;
ssl_session_cache shared:SSL:50m;
ssl_session_tickets on;

fastcgi_connect_timeout 360000;
fastcgi_send_timeout 360000;
fastcgi_read_timeout 360000;
fastcgi_buffer_size 128k;
fastcgi_buffers 4 128k;
fastcgi_busy_buffers_size 256k;
fastcgi_temp_file_write_size 256k;

gzip on;
gzip_min_length 1024;
gzip_buffers 16 8k;
gzip_comp_level 5;
gzip_types text/xml text/plain application/xml application/xhtml+xml image/svg+xml text/javascript application/x-javascript application/javascript application/json text/css application/font-woff;
gzip_vary on;

fastcgi_param COUNTRY_CODE $geoip2_data_country_code;
fastcgi_param COUNTRY_NAME $geoip2_data_country_name;
fastcgi_param CITY_NAME    $geoip2_data_city_name;

geoip2 /usr/local/nginx/geoip/maxmind-city.mmdb {
    $geoip2_data_country_code default=US source=$remote_addr country iso_code;
    $geoip2_data_country_name country names en;
    $geoip2_data_city_name default=London city names en;
    $geoip2_data_province_name subdivisions 0 names en;
    $geoip2_data_province_isocode subdivisions 0 iso_code;
}

client_body_buffer_size 512k;
tcp_nodelay on;
proxy_cache_use_stale error timeout http_500 http_502 http_503 http_504 http_404;
proxy_next_upstream error timeout http_500 http_502 http_503 http_504;
proxy_ignore_headers X-Accel-Expires Expires Set-Cookie;
proxy_buffering on;
proxy_cache_lock on;
proxy_cache_revalidate on;
proxy_buffer_size 64k;
proxy_buffers 64 128k;
proxy_busy_buffers_size 128k;
proxy_temp_file_write_size 128k;
chunked_transfer_encoding on;

map $http_upgrade $connection_upgrade
{
    default upgrade;
    ‘‘ close;
}

vhost 实例 配置

server
{
        listen 80;
#        if ( $scheme = ‘http‘ ){rewrite ^(.*)$  https://$host$1 permanent;}
        listen 443 ssl http2;
        ssl_certificate /usr/local/nginx/conf/autoconfig/ssl/img.baidu.com.crt;
        ssl_certificate_key /usr/local/nginx/conf/autoconfig/ssl/img.baidu.com.key;
        ssl_stapling on;
        ssl_stapling_verify on;
        ssl_trusted_certificate /usr/local/nginx/conf/autoconfig/ssl/img.baidu.com.crt;
        server_name img.baidu.com;

        access_log logs/img-access.json.log json;
        access_log logs/img-access.log main;

    client_body_temp_path /usr/local/nginx/temp/client_body_temp/img 1 2 3;
        set $mobile_request ‘0‘;
        if ($http_user_agent ~* ‘(Android|webOS|iPhone|iPod|BlackBerry)‘) { set $mobile_request ‘1‘;}

    location /
    {
            include /usr/local/nginx/conf/autoconfig/proxy_default.conf;
            proxy_set_header Upgrade $http_upgrade;
            proxy_set_header Connection $connection_upgrade;
            proxy_ignore_headers Cache-Control;proxy_no_cache 1;expires -1;
            proxy_pass http://img;
            break;
    }

       location ^~ /.well-known/acme-challenge/ {
            alias /usr/local/nginx/challenges/;
       }

    location ~*  ^.*\.(ggg)$
       {
            include /usr/local/nginx/conf/autoconfig/proxy_default.conf;
            proxy_set_header Connection ‘‘;
            proxy_hide_header Set-Cookie;
            add_header X-Proxy-Cache ‘HIT‘;
            root /usr/local/nginx/temp/proxy_store/img;
            proxy_store on;
            proxy_store_access user:rw group:rw all:rw;
            proxy_temp_path /usr/local/nginx/temp/proxy_store/img;
            if ( !-e $request_filename) {
                proxy_pass http://img;
            }
        }  

        location ~*  ^.*\.(gif|jpg|jpeg|png|bmp|swf|woff2|css|js|rar|zip|docx|tiff|csv|pptx|svg|midi|ppt|mid|fnt|svgz|ps|doc|eps|eot|tif|xlsx|woff|ejs|pdf|ico|class|webp|jar|pls|otf|xls|pict|ttf|opus|webm|mp3|ogg|zip|mp4|ipa|apk|wav|m4a)$
       {
                include /usr/local/nginx/conf/autoconfig/proxy_default.conf;
                proxy_set_header Connection ‘‘;
                proxy_hide_header Set-Cookie;
                add_header X-Proxy-Cache ‘HIT‘;
                proxy_cache img;
                proxy_cache_key $uri$is_args$args;
                proxy_cache_valid 404 10s;
                proxy_ignore_headers Cache-Control; proxy_cache_valid 200 206 301 304 14d;
                proxy_cache_valid 405 2m;
                expires 14d;
                if ( !-e $request_filename) {
                    proxy_pass http://img;
                }
        }

       location = /_.gif {
            empty_gif;
       }
}

upsteam 实例配置

upstream img
{
check interval=20000 fall=5 rise=2 timeout=3000 default_down=false type=tcp;
dynamic_resolve fallback=stale fail_timeout=30s;
server origin.abc.com:80 max_fails=3 fail_timeout=0s;
server 192.168.1.30:80 max_fails=3 fail_timeout=0s backup;
server 192.168.1.31:80 max_fails=3 fail_timeout=0s backup;
server 192.168.1.30:80 max_fails=3 fail_timeout=0s backup;
server 192.168.1.31:80 max_fails=3 fail_timeout=0s backup;
server 192.168.1.30:80 max_fails=3 fail_timeout=0s backup;
server 192.168.1.31:80 max_fails=3 fail_timeout=0s backup;

keepalive 360000;
}

cache path 相关配置

proxy_cache_path /usr/local/nginx/temp/proxy_cache/img levels=1:2 keys_zone=img:15m inactive=7d max_size=1024M use_temp_path=off;

原文地址:https://www.cnblogs.com/faberbeta/p/nginx-install004.html

时间: 2024-08-30 03:30:24

nginx.conf nginx反向代理配置文件的相关文章

Nginx之搭建反向代理实现tomcat分布式集群

参考博文: Nginx反向代理实现Tomcat分布式集群 1. jdk 安装 jdk 下载网址: http://www.oracle.com/technetwork/java/javase/downloads/jdk8-downloads-2133151.html 执行如下: # cd /usr # mkdir java # cp /xx/jdk-8u171-linux-x64.tar.gz /usr/java/ # cd /usr/java # tar -zxvf jdk-8u171-linu

Nginx安装和反向代理配置

Nginx安装和反向代理配置 Nginx安装需要一些准备工作. 安装gcc等 yum -y install make zlib zlib-devel gcc-c++ libtool  openssl openssl-devel 还需要安装pcre,PCRE(Perl Compatible Regular Expressions)是一个Perl库,包括 Perl兼容的正则表达式库. yum -y install pcre 下载Nginx源码包,这里选择是1.7.8版本.并且解压缩,并且编译 wge

Nginx高可用反向代理搭建

Nginx高可用反向代理搭建 Nginx简介 Nginx ("engine x") 是一个高性能的 HTTP 和 反向代理 服务器,也是一个 IMAP/POP3/SMTP 代理服务器. Nginx 是由 Igor Sysoev 为俄罗斯访问量第二的 Rambler.ru 站点开发的,第一个公开版本0.1.0发布于2004年10月4日.其将源代码以类BSD许可证的形式发布,因它的稳定性.丰富的功能集.示例配置文件和低系统资源的消耗而闻名. Nginx 可以在大多数 Unix like O

Nginx之(正)反向代理

在配置nginx反向代理之间我们得先准备两台测试服务器,Web1与Web2. 1.安装httpd 1 2 [[email protected] ~]# yum install -y httpd [[email protected] ~]# yum install -y httpd 2.提供测试页面 1 2 [[email protected] ~]# echo "<h1>web1.test.com</h1>" > /var/www/html/index.h

Nginx 如何设置反向代理

网络结构如上图.可能你只有一个公网的Ip地址. 但是您的内网有个网站需要映射至外网.而又不想添加其它的非80端口.则你可以直接使用nginx来做反向代理即可.首先,配置nginx.conf文件. http { include mime.types; default_type application/octet-stream; client_max_body_size 8m; #############################################################

Nginx+Tomcat实现反向代理及动静分离

通常tomcat部署结构 通常tomcat前端是nginx或apache,后端都为tomcat,也就意味着无论前端是什么角色都是以代理的方式进行工作的 但是要注意的是如果基于nginx做反向代理,转发请求到tomcat的时候是基于http协议进行转发的 但注意的是tomcat的连接器有httpajp jk2 jserv 而如果基于nginx做转发的话只支持http做转发 而如果apache做代理转发的话,几乎常用协议都支持 但常用的连接类型都是ajp协议,因为ajp协议可以工作在二进制模式下,而

五、Nginx多Server反向代理配置

Nginx强大的正则表达式支持,可以使server_name的配置变得很灵活,如果你要做多用户博客,那么每个用户拥有自己的二级域名也就很容易实现了. server_name的匹配顺序 Nginx中的server_name指令主要用于配置基于名称虚拟主机,server_name指令在接到请求后的匹配顺序分别为: 1.准确的server_name匹配,例如: 1 server { 2 listen 80; 3 server_name www.ooxx.com; 4 ... 5 } 2.以*通配符开始

tomcat配置及基于nginx、apache反向代理tomcat

如今,基于Web的应用越来越多,传统的Html已经满足不了如今的需求.我们需要一个交互式的Web,于是便诞生了各种Web语言.如Asp,Jsp,Php等.当然,这些语言与传统的语言有着密切的联系,如Php基于C和C 语言,Jsp基于Java语言.Tomcat即是一个Jsp和Servlet的运行平台. Tomcat是一个免费的开源的Serlvet容器,它是Apache基金会的Jakarta项目中的一个核心项目,由Apache,Sun和其它一些公司及个人共同开发而成.由于有了Sun的参与和支持,最新

Nginx多Server反向代理配置

Nginx强大的正则表达式支持,可以使server_name的配置变得很灵活,如果你要做多用户博客,那么每个用户拥有自己的二级域名也就很容易实现了. 下面我就来说说server_name的使用吧: server_name的匹配顺序 Nginx中的server_name指令主要用于配置基于名称虚拟主机,server_name指令在接到请求后的匹配顺序分别为: 1.准确的server_name匹配,例如: server { listen 80; server_name ssdr.info www.s