nginx - 心识

概念

官方文档:nginx

nginx(Web 服务、reserver load反向代理)是一个HTTP网络服务器、反向代理、内容缓存、负载均衡器、TCP/UDP代理服务器和邮件代理服务器

基本HTTP网络服务器

status:

1XX:基本信息

2XX:成功返回 200

3XX:重定向 301,302,304

4XX:用户错误信息 404

5XX:服务器错误信息 503

nginx的特性

  • 高可靠性
  • 低****内存
  • 热部署****(不停止nginx,即可实现更新配置文件,升级Nginx)

nginx的架构

nginx是一个master进程负责生成多个worker进程(真正负责用户请求)

Nginx的发行版本

Nginx社区免费版 : https://nginx.org/

Nginx 商业版:https://www.nginx.com/

淘宝的tengine:http://tengine.taobao.org/

Nginx编译安装

源码:编译安装(公司基本使用这种)

因为公司对**nginx**是有定制要求的

制作好的程序包

nginx提供Stable和Mainline两个版本分支。Stable版本经过充分测试,适合生产环境的使用,推荐的nginx stable版本 --------> nginx 1.14.0

安装nginx的依赖包

[root@localhost nginx]# tar xf nginx-1.14.2.tar.gz
[root@localhost nginx]# cd nginx-1.14.2/
[root@localhost nginx-1.14.2]# yum -y install pcre-devel gcc-c++ zlib zlib-devel openssl openssl-devel

# 了解编译的参数的一些信息

[root@localhost nginx-1.14.2]# ./configure --help | less--help                             print this message--prefix=PATH                      set installation prefix # 默认安装路径--sbin-path=PATH                   set nginx binary pathname # nginx主程序路径--modules-path=PATH                set modules path # modules路径--conf-path=PATH                   set nginx.conf pathname # 主配置文件的路径--error-log-path=PATH              set error log pathname # 错误日志的路径--pid-path=PATH                    set nginx.pid pathname # pid的路径--lock-path=PATH                   set nginx.lock pathname # 锁文件的路径--user=USER                        set non-privileged user for worker processes  # 使用哪个普通用户路径运行--group=GROUP                      set non-privileged group forworker processes--build=NAME                       set build name--builddir=DIR                     set build directory# 下面一些with开启某个功能的路径    ------ without表示的是禁用某个功能的路径--with-select_module               enable select module--without-select_module            disable select module--with-poll_module                 enable poll module--without-poll_module              disable poll module--with-threads                     enable thread pool support--with-file-aio                    enable file AIO support--with-http_ssl_module             enable ngx_http_ssl_module # HTTPS 支持--with-http_v2_module              enable ngx_http_v2_module # HTTP/2 加速--with-http_realip_module          enable ngx_http_realip_module # HTTP/3(QUIC)更快的 https--with-http_addition_module        enable ngx_http_addition_module # 响应内容追加(很少用)--with-http_xslt_module            enable ngx_http_xslt_module--with-http_xslt_module=dynamic    enable dynamic ngx_http_xslt_module--with-http_image_filter_module    enable ngx_http_image_filter_module--with-http_image_filter_module=dynamicenable dynamic ngx_http_image_filter_module--with-http_geoip_module           enable ngx_http_geoip_module--with-http_geoip_module=dynamic   enable dynamic ngx_http_geoip_module--with-http_sub_module             enable ngx_http_sub_module # 页面内容替换--with-http_dav_module             enable ngx_http_dav_module # 文件管理网盘/WebDAV--with-http_flv_module             enable ngx_http_flv_module # FLV 视频伪流媒体--with-http_mp4_module             enable ngx_http_mp4_module # MP4 视频拖动播放--with-http_gunzip_module          enable ngx_http_gunzip_module # 自动解压 gzip--with-http_gzip_static_module     enable ngx_http_gzip_static_module # 静态文件预压缩--with-http_auth_request_module    enable ngx_http_auth_request_module # 鉴权、验证权限--with-http_random_index_module    enable ngx_http_random_index_module--with-http_secure_link_module     enable ngx_http_secure_link_module # 防盗链、私密下载--with-http_degradation_module     enable ngx_http_degradation_module # 服务器高并发时自动降级--with-http_slice_module           enable ngx_http_slice_module--with-http_stub_status_module     enable ngx_http_stub_status_module--without-http_charset_module      disable ngx_http_charset_module--without-http_gzip_module         disable ngx_http_gzip_module--without-http_ssi_module          disable ngx_http_ssi_module # 默认启动ssi--without-http_userid_module       disable ngx_http_userid_module--without-http_access_module       disable ngx_http_access_module--without-http_auth_basic_module   disable ngx_http_auth_basic_module--without-http_mirror_module       disable ngx_http_mirror_module--without-http_autoindex_module    disable ngx_http_autoindex_module--without-http_geo_module          disable ngx_http_geo_module--without-http_map_module          disable ngx_http_map_module--without-http_split_clients_module disable ngx_http_split_clients_module--without-http_referer_module      disable ngx_http_referer_module--without-http_rewrite_module      disable ngx_http_rewrite_module--without-http_proxy_module        disable ngx_http_proxy_module--without-http_fastcgi_module      disable ngx_http_fastcgi_module--without-http_uwsgi_module        disable ngx_http_uwsgi_module--without-http_scgi_module         disable ngx_http_scgi_module--without-http_grpc_module         disable ngx_http_grpc_module--without-http_memcached_module    disable ngx_http_memcached_module--without-http_limit_conn_module   disable ngx_http_limit_conn_module--without-http_limit_req_module    disable ngx_http_limit_req_module--without-http_empty_gif_module    disable ngx_http_empty_gif_module--without-http_browser_module      disable ngx_http_browser_module--without-http_upstream_hash_moduledisable ngx_http_upstream_hash_module--without-http_upstream_ip_hash_moduledisable ngx_http_upstream_ip_hash_module--without-http_upstream_least_conn_moduledisable ngx_http_upstream_least_conn_module--without-http_upstream_keepalive_moduledisable ngx_http_upstream_keepalive_module--without-http_upstream_zone_moduledisable ngx_http_upstream_zone_module--with-http_perl_module            enable ngx_http_perl_module--with-http_perl_module=dynamic    enable dynamic ngx_http_perl_module--with-perl_modules_path=PATH      set Perl modules path--with-perl=PATH                   set perl binary pathname--http-log-path=PATH               set http access log pathname--http-client-body-temp-path=PATH  set path to storehttp client request body temporary files # 把客户端上传的路径传到临时目录--http-proxy-temp-path=PATH        set path to storehttp proxy temporary files--http-fastcgi-temp-path=PATH      set path to storehttp fastcgi temporary files--http-uwsgi-temp-path=PATH        set path to storehttp uwsgi temporary files--http-scgi-temp-path=PATH         set path to storehttp scgi temporary files--without-http                     disable HTTP server--without-http-cache               disable HTTP cache--with-mail                        enable POP3/IMAP4/SMTP proxy module--with-mail=dynamic                enable dynamic POP3/IMAP4/SMTP proxy module--with-mail_ssl_module             enable ngx_mail_ssl_module--without-mail_pop3_module         disable ngx_mail_pop3_module--without-mail_imap_module         disable ngx_mail_imap_module--without-mail_smtp_module         disable ngx_mail_smtp_module--with-stream                      enable TCP/UDP proxy module # 开启四层代理--with-stream=dynamic              enable dynamic TCP/UDP proxy module --with-stream_ssl_module           enable ngx_stream_ssl_module # TCP 代理也支持 TLS--with-stream_realip_module        enable ngx_stream_realip_module # 获取真实客户端 IP--with-stream_geoip_module         enable ngx_stream_geoip_module--with-stream_geoip_module=dynamic enable dynamic ngx_stream_geoip_module--with-stream_ssl_preread_module   enable ngx_stream_ssl_preread_module # --without-stream_limit_conn_module disable ngx_stream_limit_conn_module--without-stream_access_module     disable ngx_stream_access_module--without-stream_geo_module        disable ngx_stream_geo_module--without-stream_map_module        disable ngx_stream_map_module--without-stream_split_clients_moduledisable ngx_stream_split_clients_module--without-stream_return_module     disable ngx_stream_return_module--without-stream_upstream_hash_moduledisable ngx_stream_upstream_hash_module--without-stream_upstream_least_conn_moduledisable ngx_stream_upstream_least_conn_module--without-stream_upstream_zone_moduledisable ngx_stream_upstream_zone_module--with-google_perftools_module     enable ngx_google_perftools_module--with-cpp_test_module             enable ngx_cpp_test_module--add-module=PATH                  enable external module--add-dynamic-module=PATH          enable dynamic external module--with-compat                      dynamic modules compatibility--with-cc=PATH                     set C compiler pathname--with-cpp=PATH                    set C preprocessor pathname--with-cc-opt=OPTIONS              set additional C compiler options--with-ld-opt=OPTIONS              set additional linker options--with-cpu-opt=CPU                 build for the specified CPU, valid values:pentium, pentiumpro, pentium3, pentium4,athlon, opteron, sparc32, sparc64, ppc64--with-compat                      dynamic modules compatibility--with-cc=PATH                     set C compiler pathname--with-cpp=PATH                    set C preprocessor pathname--with-cc-opt=OPTIONS              set additional C compiler options--with-ld-opt=OPTIONS              set additional linker options--with-cpu-opt=CPU                 build for the specified CPU, valid values:pentium, pentiumpro, pentium3, pentium4,athlon, opteron, sparc32, sparc64, ppc64--without-pcre                     disable PCRE library usage--with-pcre                        force PCRE library usage--with-pcre=DIR                    set path to PCRE library sources--with-pcre-opt=OPTIONS            set additional build options for PCRE--with-pcre-jit                    build PCRE with JIT compilation support--with-zlib=DIR                    set path to zlib library sources--with-zlib-opt=OPTIONS            set additional build options for zlib--with-zlib-asm=CPU                use zlib assembler sources optimizedfor the specified CPU, valid values:pentium, pentiumpro--with-libatomic                   force libatomic_ops library usage--with-libatomic=DIR               set path to libatomic_ops library sources--with-openssl=DIR                 set path to OpenSSL library sources--with-openssl-opt=OPTIONS         set additional build options for OpenSSL--with-debug                       enable debug logging # 开启debug调试功能

创建nginx用户

[root@localhost nginx-1.14.2]# groupadd -r nginx
[root@localhost nginx-1.14.2]# useradd -g nginx -r nginx
[root@localhost nginx-1.14.2]# id nginx
uid=997(nginx) gid=995(nginx) 组=995(nginx)# 生产环境配置
[root@localhost nginx-1.14.2]# ./configure \
--prefix=/usr/local/nginx \
--conf-path=/etc/nginx/nginx.conf \
--user=nginx \
--group=nginx \
--error-log-path=/var/log/nginx/error.log \
--http-log-path=/var/log/nginx/access.log \
--pid-path=/var/run/nginx/nginx.pid \
--lock-path=/var/lock/nginx.lock \
--http-client-body-temp-path=/var/tmp/nginx/client \
--http-proxy-temp-path=/var/tmp/nginx/proxy \
--http-fastcgi-temp-path=/var/tmp/nginx/fastcgi \
--http-uwsgi-temp-path=/var/tmp/nginx/uwsgi \
--http-scgi-temp-path=/var/tmp/nginx/scgi \
--with-http_ssl_module \
--with-http_v2_module \
--with-http_v3_module \
--with-http_realip_module \
--with-http_addition_module \
--with-http_sub_module \
--with-http_dav_module \
--with-http_flv_module \
--with-http_mp4_module \
--with-http_gunzip_module \
--with-http_gzip_static_module \
--with-http_auth_request_module \
--with-http_random_index_module \
--with-http_secure_link_module \
--with-http_degradation_module \
--with-http_slice_module \
--with-http_stub_status_module \
--with-mail \
--with-mail_ssl_module \
--with-stream \
--with-stream_ssl_module \
--with-stream_realip_module \
--with-stream_ssl_preread_module \
--with-file-aio \
--with-threads# 测试配置
[root@localhost nginx-1.14.2]# ./configure \
--prefix=/usr/local/nginx \
--conf-path=/etc/nginx/nginx.conf \
--user=nginx \
--group=nginx \
--error-log-path=/var/log/nginx/nginx.log \
--http-log-path=/var/log/nginx/access.log \
--pid-path=/var/run/nginx/nginx.pid \
--lock-path=/var/lock/nginx.lock \
--with-http_ssl_module \
--with-http_stub_status_module \
--with-http_gzip_static_module \
--with-http_flv_module \
--with-http_mp4_module \
--http-client-body-temp-path=/var/tmp/nginx/client \
--http-proxy-temp-path=/var/tmp/nginx/proxy \
--http-fastcgi-temp-path=/var/tmp/nginx/fastcgi \
--http-uwsgi-temp-path=/var/tmp/nginx/uwsgi
参数 作用
--with-http_ssl_module 启用 HTTPS/SSL 支持(必须依赖 OpenSSL)
--with-http_stub_status_module 启用状态监控页面(查看连接数、请求数等)
--with-http_gzip_static_module 启用静态资源预压缩(直接读取 .gz 文件,提升性能)
--with-http_flv_module / --with-http_mp4_module 启用 FLV/MP4 视频伪流支持(适合视频点播场景)
[root@localhost nginx-1.14.2]# make && make install
[root@localhost nginx-1.14.2]# mkdir -pv /var/tmp/nginx/{proxy,fastcgi,uwsgi,client}# 开启nginx
[root@localhost nginx-1.14.2]# /usr/local/nginx/sbin/nginx
[root@localhost nginx-1.14.2]# ss -alntp
State      Recv-Q Send-Q             Local Address:Port                            Peer Address:Port
LISTEN     0      128                            *:80                                         *:*                   users:(("nginx",pid=59691,fd=6),("nginx",pid=59690,fd=6))
[root@localhost nginx-1.14.2]# ps -aux | grep nginx
root      59690  0.0  0.0  45984  1132 ?        Ss   06:34   0:00 nginx: master process /usr/local/nginx/sbin/nginx
nginx     59691  0.0  0.1  46432  1880 ?        S    06:34   0:00 nginx: worker process
root      60648  0.0  0.0 112824   984 pts/0    S+   06:37   0:00 grep --color=auto nginx

现在是一个主进程,一个是worker进程

测试访问一下:

性能调优

[root@www ~]# vi /etc/nginx/nginx.conf
user  nginx;
worker_processes  2; # 工作进程数,一般设置成CPU一样或者比CPU少1 调节https://nginx.org/en/docs/ngx_core_module.html#worker_processes
pid        logs/nginx.pid;
worker_cpu_affinity 0101 1010;
worker_rlimit_nofile 65535; # 最大可以打开的文件数,需要修改一下操作系统events { # 主要配置性能的worker_connections  20480; # use epoll; # Linux 使用 epoll 事件模型multi_accept on; # 一次性接受所有新连接,避免逐个接受
}

# 如果报错,请查看日志 /var/log 看防火墙

[root@localhost ~]# tail -f /var/log/firewalld 
2026-05-14 06:44:04 ERROR: Backup of file '/etc/firewalld/zones/public.xml' failed: [Errno 13] 权限不够: '/etc/firewalld/zones/public.xml.old'
2026-05-14 06:46:57 WARNING: ALREADY_ENABLED: nginx
2026-05-14 06:48:01 ERROR: Backup of file '/etc/firewalld/zones/public.xml' failed: [Errno 13] 权限不够: '/etc/firewalld/zones/public.xml.old'
2026-05-14 06:49:27 ERROR: Backup of file '/etc/firewalld/zones/public.xml' failed: [Errno 13] 权限不够: '/etc/firewalld/zones/public.xml.old'
2026-05-14 06:49:37 WARNING: ALREADY_ENABLED: nginx
2026-05-14 06:53:44 WARNING: ALREADY_ENABLED: nginx
2026-05-14 06:56:01 WARNING: NOT_ENABLED: nginx
2026-05-14 06:56:01 ERROR: Backup of file '/etc/firewalld/zones/public.xml' failed: [Errno 13] 权限不够: '/etc/firewalld/zones/public.xml.old'
2026-05-14 07:01:03 ERROR: Backup of file '/etc/firewalld/zones/public.xml' failed: [Errno 13] 权限不够: '/etc/firewalld/zones/public.xml.old'
2026-05-14 07:01:48 ERROR: Backup of file '/etc/firewalld/zones/public.xml' failed: [Errno 13] 权限不够: '/etc/firewalld/zones/public.xml.old'
发现是selinux导致的,所以修改一些getenforce 0

nginx web服务配置详细

来源 官方文档:https://nginx.org/en/docs/http/ngx_http_core_module.html#server

server {}

定义一个虚拟主机; 可以定义多个虚拟主机

server{listen 8080;server_name www.yangkun.com; #基于域名的虚拟主机:端口可相同,server_name为不同域名 公有云用的最多root "/vhosts/web1";
}# another virtual host using mix of IP-, name-, and port-based configuration##server {
#    listen       8000;
[root@localhost ~]# mkdir /vhosts/web1 -pv
mkdir: 已创建目录 "/vhosts"
mkdir: 已创建目录 "/vhosts/web1"
[root@localhost ~]# vi /vhosts/web1/index.html
<h1>this is web1<h1/>
访问一下

打开hosts文件

访问:

listen

指定监听端口

server_name

后可跟多个主机;名称还可以使用正则表达式(~)或者通配符

(1) 先做精确匹配检查;

(2) 左侧通配符匹配检查:*.yang.com

(3) 右侧通配符匹配检查:如mail.*

(4) 正则表达式匹配检查:如 ~^.*\.yang\.|

server {server_name www.yang.com;
}server {server_name *.yang.com;
}server {server_name mail.*
}

root

Syntax: 语法: root path;
Default: 默认值: root html;
Context: 上下文: http, server, location, if in location

设置资源路径映射,用于指定文件系统的起始路径

localtion

功能:允许根据用户请求的 URI 来匹配定义的各 location;匹配到时,此请求将被相应的 location 配置块中的配置所处理,例如做访问控制等功能;

=:精确匹配检查;

~:正则表达式模式匹配检查,区分字符大小写;

~*:正则表达式模块匹配检查,不区分字符大小写;

^~:URI 的前半部分匹配,不支持正则表达式;

server {listen 80;server_name www.yang.com;location / {root "/vhosts/web1";}location /images/ {root "/vhosts/images";}location ~* \.php$ {fcgipass}
}

error_page

错误页面,默认没有定义是404

比如我在下面进行定义

[root@localhost ~]# vi /etc/nginx/nginx.confserver {listen 8080;server_name www.yangkun.com;location / {root "/vhosts/web1"; # 默认/为/vhosts/web1error_page 404 /404_customed.html;}location /images {root "/vhosts/images";}}
保存退出
# 检查语法错误
[root@localhost ~]# /usr/local/nginx/sbin/nginx -t
[root@localhost ~]# /usr/local/nginx/sbin/nginx -s reload# 书写error_page页面
[root@localhost ~]# vi /vhosts/web1/404_customed.html
<h1>O_O wrong</h1>

基于IP地址的访问控制allow/deny

相当于网络中的ACL

比如说:现在我需要去拒绝192.168.100.0/24的网段,不允许进入

[root@localhost ~]# vi /etc/nginx/nginx.conflocation / {root "/vhosts/web1";error_page 404 /404_customed.html;deny 192.168.100.0/24;}
[root@localhost ~]# /usr/local/nginx/sbin/nginx -t
[root@localhost ~]# /usr/local/nginx/sbin/nginx -s reload

再次访问

公司中一般是这样做

location / {root "/vhosts/web1";error_page 404 /404_customed.html;allow 192.168.100.0/24;deny all;}
[root@localhost ~]# /usr/local/nginx/sbin/nginx -t
[root@localhost ~]# /usr/local/nginx/sbin/nginx -s reload

基于用户的访问控制

auth_basic :显示信息

auth_basic_user_file 密码文件

satisfy all 满足所有条件

[root@localhost ~]# vi /etc/nginx/nginx.conflocation / {root "/vhosts/web1";error_page 404 /404_customed.html;allow 192.168.100.0/24;deny all;satisfy all;auth_basic "Only for VIP";auth_basic_user_file /etc/nginx/user/.htpasswd;}# 创建user
[root@localhost ~]# mkdir /etc/nginx/user# 使用htpasswd创建密码文件,需要使用到httpd,我默认是安装了httpd
[root@localhost ~]# rpm -q httpd
httpd-2.4.6-99.el7.centos.1.x86_64
[root@localhost ~]# htpasswd -c -m /etc/nginx/user/.htpasswd yang
New password:
Re-type new password:
Adding password for user yang[root@localhost ~]# /usr/local/nginx/sbin/nginx -t
[root@localhost ~]# /usr/local/nginx/sbin/nginx -s reload

访问测试一下

fastcgi的相关配置

php启动fpm模型

location ~ \.php$ {root           html; # 哪个目录fastcgi_pass   127.0.0.1:9000; # 反向代理fastcgi_index  index.php; # fastcgi的主页fastcgi_param  SCRIPT_FILENAME  /scripts$fastcgi_script_name;include        fastcgi_params;}

rewrite重写规则(重点)

官方文档: https://nginx.org/en/docs/http/ngx_http_rewrite_module.html#rewrite

rewrite 在我们的工作中非常常见,比如:我以前有个域名是www.test.com/gz --> 表示广州,但是突然有一天,我需要把****www.test.com/gz 改--> www.test.com/g****uangzhou

基本语法

localtion 匹配规则{rewrite 匹配内容 替换后的内容 flag;
}

flag 标记说明:

表格

标记 作用
last 本条规则匹配完成后,继续向下匹配新的 location URI 规则
break 本条规则匹配完成即终止,不再匹配后面的任何规则
redirect 返回 302 临时重定向,浏览器地址会显示跳转后的 URL 地址
permanent 返回 301 永久重定向,浏览器地址栏会显示跳转后的 URL 地址

资源重定向

[root@localhost ~]# vi /etc/nginx/nginx.confserver {listen 8080;server_name www.yangkun.com;location / {root "/vhosts/web1";error_page 404 /404_customed.html;allow 192.168.100.0/24;deny all;satisfy all;rewrite /index.html /test.html last;}# 创建test.html文件
[root@localhost ~]# vi /vhosts/web1/test.html 
<!DOCTYPE html>
<html lang="en">
<head><meta charset="UTF-8"><meta name="viewport" content="width=device-width, initial-scale=1.0"><title>Document</title><html lang="en">
<head><meta charset="UTF-8"><meta name="viewport" content="width=device-width, initial-scale=1.0"><title>Document</title><link rel="stylesheet" href="dist/css/bootstrap.min.css"><link rel="stylesheet" href="01-index.css">
</head>
<body>This is test
</body>[root@localhost ~]# /usr/local/nginx/sbin/nginx -t
[root@localhost ~]# /usr/local/nginx/sbin/nginx -s reload

实践

文件服务器

核心的代码:

[root@www nginx]# mkdir /etc/nginx/conf.d/
[root@www nginx]# vi /etc/nginx/conf.d/autoindex.conf
server {listen 8004;server_name localhost;autoindex on;charset utf-8;autoindex_localtime on;autoindex_exact_size on;location /2{root /data/www;}
}# 放行防火墙
[root@www nginx]# firewall-cmd --zone=public --add-port=8004/tcp --permanent
[root@www nginx]# firewall-cmd --reload# 设置nginx.conf
[root@www nginx]# vi /etc/nginx/nginx.conf
http {include       mime.types;# 在这里下面添加include       /etc/nginx/conf.d/*.conf;# 加载配置文件
[root@localhost ~]# /usr/local/nginx/sbin/nginx -t
[root@localhost ~]# /usr/local/nginx/sbin/nginx -s reload# 创建文件
[root@www nginx]# mkdir -pv /data/www/2
[root@www nginx]# cp -rf /etc/nginx/* /data/www/2

反向代理

把一个请求反向代理到另外一个请求,nginx支持七层反向代理,四层反向代理

四层反向代理

stream { server { listen 8005;# 访问本机的8005,就被转发到了远程的80 proxy_pass 192.168.100.3:80; }****}

[root@www ~]# grep -Ev "#|^$" /etc/nginx/nginx.conf
user  nginx ;
worker_processes  2;
worker_cpu_affinity 0101 1010;
worker_rlimit_nofile 65535;
pid        logs/nginx.pid;
events {worker_connections  20480;use epoll;multi_accept on;
}
stream {server {listen 8005;proxy_pass 192.168.100.3:80;}
}
http {include       mime.types;include       /etc/nginx/conf.d/*.conf;

七层反向代理

七层反向代理就是代理到域名上面

server { listen 8088; server_name localhost****; location / { proxy_pass https://www.baidu.com; }****}

[root@www ~]# vi /etc/nginx/nginx.confserver {listen       80;server_name  localhost;#charset koi8-r;#access_log  logs/host.access.log  main;location / {#root   html;#index  index.html index.htm;proxy_pass https://www.baidu.com;}

平滑升级/平滑替换

比如:我有一个需求就是我有一个模块忘记添加了,我需要添加怎么办?

# 先看编译的版本详细信息
[root@www ~]# /usr/local/nginx/sbin/nginx -V
nginx version: nginx/1.14.2
built by gcc 4.8.5 20150623 (Red Hat 4.8.5-44) (GCC)
built with OpenSSL 1.0.2k-fips  26 Jan 2017
TLS SNI support enabled
configure arguments: --prefix=/usr/local/nginx --conf-path=/etc/nginx/nginx.conf --user=nginx --group=ngin         x --error-log-path=/var/log/nginx/nginx.log --http-log-path=/var/log/nginx/access.log --pid-path=/var/run/         nginx/nginx.pid --lock-path=/var/lock/nginx.lock --with-http_ssl_module --with-http_stub_status_module --w         ith-http_gzip_static_module --with-http_flv_module --with-http_mp4_module --http-client-body-temp-path=/va         r/tmp/nginx/client --http-proxy-temp-path=/var/tmp/nginx/proxy --http-fastcgi-temp-path=/var/tmp/nginx/fas         tcgi --http-uwsgi-temp-path=/var/tmp/nginx/uwsgi# 假设我需要添加这个参数 --with-stream
[root@www ~]# cd /usr/local/src
[root@www src]#  wget http://nginx.org/download/nginx-1.14.2.tar.gz
[root@www src]#  tar zxf nginx-1.14.2.tar.gz
[root@www src]#  cd nginx-1.14.2[root@www nginx-1.14.2]# ./configure \
--prefix=/usr/local/nginx \
--conf-path=/etc/nginx/nginx.conf \
--user=nginx \
--group=nginx \
--error-log-path=/var/log/nginx/nginx.log \
--http-log-path=/var/log/nginx/access.log \
--pid-path=/var/run/nginx/nginx.pid \
--lock-path=/var/lock/nginx.lock \
--with-http_ssl_module \
--with-http_stub_status_module \
--with-http_gzip_static_module \
--with-http_flv_module \
--with-http_mp4_module \
--http-client-body-temp-path=/var/tmp/nginx/client \
--http-proxy-temp-path=/var/tmp/nginx/proxy \
--http-fastcgi-temp-path=/var/tmp/nginx/fastcgi \
--http-uwsgi-temp-path=/var/tmp/nginx/uwsgi \
--with-stream# 编译
[root@www nginx-1.14.2]# make
[root@www nginx-1.14.2]# objs/nginx -t
[root@www nginx-1.14.2]# ./objs/nginx -V# 测试
新开一个页面测试一下
[root@www ~]# while true; do curl -s -o /dev/null -w "%{http_code} %{time_total}s\n" 192.168.100.2; sleep 0.5; done# 备份原来的文件
[root@www nginx-1.14.2]# cp /usr/local/nginx/sbin/nginx /usr/local/nginx/sbin/nginx.bak.$(date +%F_%H_%M_%S)
[root@www nginx-1.14.2]# make install[root@www nginx-1.14.2]# ps aux | grep "nginx: master" | grep -v grep 或者使用cat /usr/local/nginx/logs/nginx.pid
root      92177  0.0  0.0  46084  1260 ?        Ss   17:38   0:00 nginx: master process /usr/local/nginx/sbin/nginx# 新旧版本同时运行
[root@www nginx-1.14.2]#kill -USR2 92177
应该看到两个 master 共存
[root@www nginx-1.14.2]# ps aux | grep nginx | grep -v grep
root      92177  0.0  0.0  46084  1428 ?        Ss   17:38   0:00 nginx: master process /usr/local/nginx/sbin/nginx
nginx     92178  0.0  0.5  54576 10396 ?        S    17:38   0:00 nginx: worker process
nginx     92179  0.0  0.5  54576 10392 ?        S    17:38   0:00 nginx: worker process
root      98213  0.0  0.1  45968  3456 ?        S    17:44   0:00 nginx: master process /usr/local/nginx/sbin/nginx
nginx     98214  1.1  0.5  54460 10348 ?        S    17:44   0:00 nginx: worker process
nginx     98215  1.0  0.5  54460 10348 ?        S    17:44   0:00 nginx: worker process# 停止掉旧worker
[root@www nginx-1.14.2]# kill -WINCH 92177
# 停止掉旧master
[root@www nginx-1.14.2]# kill -QUIT 92177# 验证
[root@www nginx-1.14.2]# /usr/local/nginx/sbin/nginx -V

HTTPS加密传输

HTTPS 通过加密通道保护客户端与服务端之间的数据传输,已成为当前网站部署的必选配置。在部署有 Nginx 代理集群的 HTTPS 站点,通常会把 SSL 证书部署在 Nginx 的服务器上,然后把请求代理到后端的上游服务器。这种部署方式由 Nginx 服务器负责 SSL 请求的运算,相对减轻了后端上游服务器的 CPU 运算量。

[root@www nginx]# mkdir ssl
[root@www nginx]# cd ssl/
# 创建私钥
[root@www ssl]# openssl genrsa -out /usr/local/nginx/ssl/https.key 2048
# 创建签名请求证书:
[root@www ssl]# openssl req -new -key https.key -out https.csr
You are about to be asked to enter information that will be incorporated
into your certificate request.
What you are about to enter is what is called a Distinguished Name or a DN.
There are quite a few fields but you can leave some blank
For some fields there will be a default value,
If you enter '.', the field will be left blank.
-----
Country Name (2 letter code) [XX]:CN
State or Province Name (full name) []:Beijing
Locality Name (eg, city) [Default City]:Beijing
Organization Name (eg, company) [Default Company Ltd]:
Organizational Unit Name (eg, section) []:
Common Name (eg, your name or your server's hostname) []:192.168.100.2
Email Address []:Please enter the following 'extra' attributes
to be sent with your certificate request
A challenge password []:
An optional company name []:# 去掉私钥口令
[root@www ssl]# cp https.key https.key.org
[root@www ssl]# openssl rsa -in https.key.org -out https.key# 自签名证书
[root@www ssl]# openssl x509 -req -days 365 -in https.csr -signkey https.key -out https.crt# 编辑nginx.conf文件
[root@www ssl]# vi /etc/nginx/nginx.confserver {listen       443 ssl;server_name  localhost;ssl_certificate      /usr/local/nginx/ssl/https.crt;ssl_certificate_key  /usr/local/nginx/ssl/https.key;ssl_session_cache    shared:SSL:1m;ssl_session_timeout  5m;ssl_ciphers  HIGH:!aNULL:!MD5;ssl_prefer_server_ciphers  on;location /1 {default_type text/html;return 200 "https-----";}}

测试:

负载均衡

在下面的图中,是现有我们的架构,但是我发现一个问题:

keeplived主要是用来解决硬件问题,当这台硬件宕机了,keeplived可以实现漂移。

但是如果流量非常的大的话,两台机器都会keeplived漂移后,两台机器都会挂机 ---> 引入负载均衡(专门为大流量做的)

思考个问题:现在一共有3台服务器,但是真正工作的只有一台服务器。另外一台服务器还处于待机备战状态,能不能把它也利用起来,干点活呢?

如果加了负载均衡LB, 那么keeplived可以取消了,因为负载均衡可以实现keeplived的一些功能

如果两台机器抵挡不住的话,这个架构是可以无限延伸

官方文档:https://nginx.org/en/docs/http/ngx_http_upstream_module.html

OSI分层 实现方式
七层 Nginx+Haproxy
四层 LVS+HAproxy
[root@www ~]# vi /etc/nginx/nginx.confupstream shop{server 192.168.100.3; # 负载到web01# 如果有两台机器server IP_2; }server {listen       80;server_name  localhost;#charset koi8-r;#access_log  logs/host.access.log  main;location / {#root   html;#index  index.html index.htm;#proxy_pass https://www.baidu.com;proxy_pass http://shop; # 代理转化到shop字段,匹配上面的upstreamproxy_set_header Host $host; #传输域名给后端服务器 进行识别 方便匹配对应server虚拟主proxy_set_header X-Real-IP $remote_addr; # 发送客户端IP 给后端服务器 用来方便后端服务器识别用户真实}

负载均衡后获取客户端

负载均衡之后,在后端的web服务器获取到的是负载均衡服务器的IP,而不能够获取到客户端的真实IP。

需要进行以下特殊配置:

①首先在负载均衡服务器中配置,转发客户端IP给后端web服务器

②后端web服务器需要配置,识别从负载均衡服务器传输过来的客户端真实IP

官方网址:http://nginx.org/en/docs/http/ngx_http_realip_module.html

使用--with-http_realip_module模块提供的set_real_ip_from语法 面试的时候问过我

# 负载均衡的IP
set_real_ip_from 192.168.100.2

Nginx的负载均衡算法

Nginx 官方默认3种负载均衡的算法

  1. 轮询(默认):一个一个的来
  2. weight权重: 权重高多分发一些 服务器硬件更好的设置权重更高一些
  3. ip_hash:同一个IP,所有的访问都分发到同一个web服务器
示例配置
upstream shop {  #web1 server01  server 192.168.17.102 weight=5;  #web2 server02  server 192.168.17.101 weight=3; 
}

server01 web 1 2 1 1

server03 web 2 6 1 1 1 1 1 1

8次中,server01分发5次,server03分发3次

高可用的负载均衡