Linux系统NGINX软件配置练习
- 1.总结nginx的配置结构和流量访问逻辑过程
- Nginx 配置是分层嵌套结构,外层作用域包含内层。
- 全局段(main)最顶层,配置nginx本身
- event段:连接,并发,网络相关
- http段(核心):所有网站,代理,缓存都写在这里面
- server段(虚拟主机):一个 server = 一个网站
- location段(匹配访问具体路径)匹配用户访问的 URL,决定怎么处理
- 全局块
- └── events 块
- └── http 块
- ├── server 块(虚拟主机 1)
- │ ├── location /
- │ └── location /api
- └── server 块(虚拟主机 2)
- └── location /
- 流量访问逻辑过程:
- 用户请求
- ↓
- 匹配 listen 端口
- ↓
- 匹配 server_name 域名
- ↓
- 匹配 location 路径
- ↓
- 执行配置(静态文件/代理/重定向)
- ↓
- 返回响应给用户
- 2.搭建nginx完成二进制安装和多OS下的软件包安装过程
- Ubuntu系统软件二进制方式安装
- apt install nginx nginx-core fcgiwrap nginx-doc -y
- 查看服务状态
- systemctl is-active nginx
- netstat -tnulp | grep nginx
- Rocky10系统软件二进制方式安装
- yum install nginx nginx-core -y
- 查看状态
- systemctl is-active nginx
- 设置为开机自启动
- systemctl enable --now nginx
- 源码方式安装软件(Ubuntu)
- 编译环境准备
- apt install build-essential gcc g++ libc6 libc6-dev libpcre3 libpcre3-dev libssldev libsystemd-dev zlib1g-dev
- apt install libxml2 libxml2-dev libxslt1-dev php-gd libgd-dev geoip-database libgeoip-dev
- 创建运行用户
- useradd -r -s /usr/sbin/nologin nginx
- 下载最新版源码并解压
- wget https://nginx.org/download/nginx-1.22.1.tar.gz
- 定制配置
- tar xf nginx-1.22.1.tar.gz
- cd nginx-1.24.0/
- ./configure
- 编译安装
- make && make install
- 修改目录属主属组并查看
- chown -R nginx:nginx /data/server/nginx/
- 环境收尾
- ln -sv /data/server/nginx/sbin/nginx /usr/sbin/nginx '/usr/sbin/nginx' -> '/data/server/nginx/sbin/nginx'
- 查看版本
- nginx -v
- 定制专属管理
- mkdir /data/server/nginx/run
- chown -R nginx:nginx /data/server/nginx/run
- 修改配置文件,设置pid文件路径
- vim /data/server/nginx/conf/nginx.conf
- pid /data/server/nginx/run/nginx.pid;
- 创建nginx服务脚本
- cat /usr/lib/systemd/system/nginx.service
- [Unit]
- Description=nginx - high performance web server
- Documentation=http://nginx.org/en/docs/
- After=network-online.target remote-fs.target nss-lookup.target
- Wants=network-online.target
- [Service]
- Type=forking
- PIDFile=/data/server/nginx/run/nginx.pid
- ExecStart=/data/server/nginx/sbin/nginx -c /data/server/nginx/conf/nginx.conf
- ExecReload=/bin/kill -s HUP $MAINPID
- ExecStop=/bin/kill -s TERM $MAINPID
- LimitNOFILE=100000
- [Install]
- WantedBy=multi-user.target
- 3.完成nginx https配置,防盗链,重定向相关实践过程
- https实践
- 准备秘钥环境
- apt install easy-rsa -y
- 创建秘钥
- cd /usr/share/easy-rsa/
- ./easyrsa init-pki
- 查看效果
- tree pki/
- 生成CA机构证书,不使用密码
- ./easyrsa build-ca nopass
- 生成私钥和证书申请文件
- ./easyrsa gen-req sswang.magedu.com nopass
- 签发证书
- ./easyrsa sign-req server sswang.magedu.com
- 合并证书
- cat pki/issued/sswang.magedu.com.crt pki/ca.crt > pki/sswang.magedu.com.pem
- 给私钥加读权限
- chmod +r pki/private/sswang.magedu.com.key
- 定制配置文件
- cat > /etc/nginx/conf.d/vhost.conf <<-eof
- server {
- listen 80 default_server;
- server_name sswang.magedu.com;
- root /data/server/nginx/web1;
-
return 301 https://$host$request_uri; # 301重定向
- rewrite ^(.*) https://$server_name$1 permanent; #rewrite 重定向,二选一
- }
- server{
- listen 443 ssl;
- server_name sswang.magedu.com;
- root /data/server/nginx/web1;
-
定制ssl的能力
- ssl_certificate /usr/share/easy-rsa/pki/sswang.magedu.com.pem;
- ssl_certificate_key /usr/share/easy-rsa/pki/private/sswang.magedu.com.key;
- ssl_session_cache shared:sslcache:20m;
- ssl_session_timeout 10m;
- }
- eof
- 重启服务
- systemctl restart nginx
- 防盗链实践
- 准备工作-上传一个图片文件到nginx的静态目录
- ls /data/server/nginx/web1/static/
- favicon.ico picture.png
- 定制访问页面
- echo '
' >> /data/server/nginx/web2/index.html - echo '
' >> /data/server/nginx/web1/index.html - 定制配置文件
- cat > /etc/nginx/conf.d/vhost.conf <<-eof
- server {
- listen 80 default_server;
- root /data/server/nginx/web2;
- }
- server {
- listen 81 default_server;
- root /data/server/nginx/web1;
- }
- eof
- 重启服务
- systemctl restart nginx
- 4.完成nginx虚拟主机配置,包括ip 多端口 多域名相关的配置
- cat > /etc/nginx/conf.d/vhost.conf <<-eof
- server {
- listen 80;
- server_name www.test.com;
- root /data/server/nginx/web1;
- index index.html;
- location / {
- try_files $uri $uri/ =404;
- }
- }
- server {
- listen 81;
- server_name blog.test.com;
- root /data/server/nginx/web2;
- index index.html;
- location / {
- try_files $uri $uri/ =404;
- }
- }
- server {
- listen 82;
- server_name api.test.com;
- root /data/server/nginx/web3;
- index index.html;
- location / {
- try_files $uri $uri/ =404;
- }
- }
- eof
- 5.完成nginx方向代理和动静分离相关的演示
- Nginx的动静分离是一种在Web服务器架构中优化资源处理和提高系统性能的方法。动静分离是指将Web服务器上的静态页面与动态页面或者静态内容接口和动态内容接口分开,由不同的系统或服务器进行处理。这样做的目的是提升整个服务访问的性能和可维护性。
- 准备nginx环境
- yum install nginx -y
- echo "Static Web Server" > /usr/share/nginx/html/index.html
- 启动nginx服务,关闭防火墙、selinux
- systemctl start nginx;systemctl stop firewalld
- Ubuntu24实现 apiserver的配置
- 定制python服务用于做动态网页
- 运行python服务
- root@apiserver:~# python3 simple_http_server.py >/dev/null 2>&1 &
- 定制nginx配置文件
- cat > /etc/nginx/conf.d/vhost.conf <<-eof
- server {
- listen 80 default_server;
- server_name sswang.magedu.com;
- root /data/server/nginx/web1;
- location /api {
- proxy_pass http://10.0.0.16:8080;
- proxy_set_header Host "api.magedu.com";
- }
- location /static {
- rewrite ^/static(.*)$ /index.html break; # 重写url
- proxy_pass http://10.0.0.14;
- proxy_set_header Host "static.magedu.com";
- }
- location /static1/ {
-
/static1/index.html 转发给后端 /index.html
- proxy_pass http://10.0.0.14/; # 以/为结尾
- proxy_set_header Host "static.magedu.com";
- }
- }
- eof
- 重启服务
- 测试效果
- 6.完成nginx四层代理实践,代理mysql和redis
- 四层代理前提确认nginx环境是否存在stream功能
- vim /etc/nginx/nginx.conf
-
文件最后,增加如下测试代码
- stream {}
- nginx -t
- 2024/12/06 18:43:40 [emerg] 6918#6918: unknown directive "stream" in
- /etc/nginx/nginx.conf:84
- nginx: configuration file /etc/nginx/nginx.conf test failed
- 结果显示:
- 默认情况下,nginx内部没有加载stream模块。
- 如果没有该模块的化,重新编译nginx即可
- ./configure --with-cc-opt=... --withhttp_
- image_filter_module=dynamic --with-http_perl_module=dynamic --withhttp_
- xslt_module=dynamic --with-mail=dynamic --with-stream=dynamic --withstream_geoip_module=dynamic
- 编译
- make
- 确认模块
- ls objs/ngx_stream_module.so
- 转移模块文件
- cp objs/ngx_stream_module.so /usr/lib/nginx/modules/
- 编辑配置文件
- vim /etc/nginx/nginx.conf
-
下面的配置,一定要在全局配置段里面,不要放置到http配置段后面,或者最后采取加载。
- load_module /usr/lib/nginx/modules/ngx_stream_module.so;
- 准备Mysql环境
- apt update;apt install mysql-server
- 修改配置,注释掉这两行
- vim /etc/mysql/mysql.conf.d/mysqld.cnf
-
bind-address = 127.0.0.1
-
mysqlx-bind-address = 127.0.0.1
- skip-name-resolve #添加此行,跳过主机名反解
- 重启mysql
- systemctl restart mysql
- 创建对应的用户
- mysql
- create user proxyer@'10.0.0.%' identified by '123456';
- flush privileges;
- 检测效果
- mysql -h 10.0.0.16 -uproxyer -p123456 -e "select version();"
- 检测服务
- ss -tnlp | grep 3306
- 准备redis环境
- yum install redis -y
- 修改配置
- vim /etc/redis.conf
-
bind 127.0.0.1 # 注释掉
- protected-mode no #关闭保护模式
- 启动redis
- systemctl start redis
- 检测效果
- ss -tnlp | grep 6379
- 客户端安装mysql和redis的客户端命令
- apt install mysql-client redis-tools或
- yum install mysql redis
- redis连接测试
- redis-cli -h 10.0.0.14 -p 6379 info server
- NGINX四层代理配置
- cat >> /etc/nginx/nginx.conf <<-eof
- stream {
- include /etc/nginx/conf.d/stream_configs/*.conf;
- }
- eof
- 创建目录
- mkdir -p /etc/nginx/conf.d/stream_configs
- 定制nginx的四层代理配置
- cat > /etc/nginx/conf.d/stream_configs/tcp.conf <<-eof
- upstream mysqlserver{
- server 10.0.0.16:3306;
- }
- upstream redisserver{
- server 10.0.0.14:6379;
- }
- server{
- listen 3306;
- proxy_pass mysqlserver;
- }
- server{
- listen 6379;
- proxy_pass redisserver;
- }
- eof
- 检查配置
- nginx -t
- 重启服务
- systemctl restart nginx
- 检查进程
- netstat -tnulp | grep nginx

浙公网安备 33010602011771号