The Linux distribution used in this article: CentOS 6.7. Download URL:https://wiki.centos.org/Download
1. Install Nginx
Download source: wget http://nginx.org/packages/centos/6/noarch/RPMS/nginx-release-centos-6-0.el6.ngx.noarch.rpm
Install source: yum install nginx-release-centos-6-0.el6.ngx.noarch.rpm -y (note the -y parameter)
Install Nginx: yum install nginx
Start Nginx service: service nginx start
Stop Nginx service: service nginx stop
Check Nginx running status: service nginx status
Check Nginx configuration file: nginx -t
Reload configuration while service is running: nginx -s reload
Add Nginx service to auto-start: chkconfig nginx on
2. Modify Firewall Rules
Modify the firewall configuration of the host where Nginx is located: vi /etc/sysconfig/iptables, and add the port used by Nginx to the allowed list.
For example: -A INPUT -m state --state NEW -m tcp -p tcp --dport 80 -j ACCEPT (means allowing port 80 through)
Modify the firewall configuration of the host where Tomcat is located: vi /etc/sysconfig/iptables, and add the port used by Tomcat to the allowed list.
For example: -A INPUT -m state --state NEW -m tcp -p tcp --dport 8080 -j ACCEPT (means allowing port 8080 through)
If there are multiple Tomcats on the host, add multiple rules in this way and modify the corresponding port numbers.
After saving, restart the firewall: service iptables restart
3. Tomcat Load Balancing Configuration
When Nginx starts, it loads the configuration file /etc/nginx/nginx.conf by default, and nginx.conf references all .conf files in the /etc/nginx/conf.d directory.
Therefore, you can write some custom configurations into a separate .conf file. As long as the file is placed in the /etc/nginx/conf.d directory, it is convenient for maintenance.
Create tomcats.conf: vi /etc/nginx/conf.d/tomcats.conf, the content is as follows:
upstream tomcats {
ip_hash;
server 192.168.0.251:8080;
server 192.168.0.251:8081;
server 192.168.0.251:8082;
}
Modify default.conf: vi /etc/nginx/conf.d/default.conf, modify as follows:
#注释原有的配置
#location / {
# root /usr/share/nginx/html;
# index index.html index.htm;
#}
#新增配置默认将请求转发到tomcats.conf配置的upstream进行处理
location / {
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header REMOTE-HOST $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_pass http://tomcats; #与tomcats.conf里配置的upstream同名
}
After saving, reload the configuration:nginx -s reload
4. Static Resource Separation Configuration
Modify default.conf: vi /etc/nginx/conf.d/default.conf, add the following configuration:
#所有js,css相关的静态资源文件的请求由Nginx处理
location ~.*\.(js|css)$ {
root /opt/static-resources; #指定文件路径
expires 12h; #过期时间为12小时
}
#所有图片等多媒体相关静态资源文件的请求由Nginx处理
location ~.*\.(html|jpg|jpeg|png|bmp|gif|ico|mp3|mid|wma|mp4|swf|flv|rar|zip|txt|doc|ppt|xls|pdf)$ {
root /opt/static-resources; #指定文件路径
expires 7d; #过期时间为7天
}
5. Modify SELinux Security Rules
If you encounter a 502 Bad Gateway error when accessing Nginx, it may be caused by SELinux on the Nginx host restricting its HTTP access permissions. Enter the command setsebool -P httpd_can_network_connect 1 to enable the permission.
The complete configuration of the file /etc/nginx/nginx.conf is as follows:
user nginx;
worker_processes auto;
error_log /var/log/nginx/error.log warn;
pid /var/run/nginx.pid;
worker_rlimit_nofile 100000;
events {
use epoll;
multi_accept on;
worker_connections 1024;
}
http {
include /etc/nginx/mime.types;
default_type application/octet-stream;
#log_format main '$remote_addr - $remote_user [$time_local] "$request" '
# '$status $body_bytes_sent "$http_referer" '
# '"$http_user_agent" "$http_x_forwarded_for"';
#access_log /var/log/nginx/access.log main;
sendfile on;
server_tokens off;
#tcp_nopush on;
keepalive_timeout 65;
gzip on;
gzip_disable "msie6";
gzip_static on;
gzip_proxied any;
gzip_min_length 1000;
gzip_comp_level 4;
gzip_types text/plain text/css application/json application/x-javascript text/xml application/xml application/xml+rss text/javascript;
include /etc/nginx/conf.d/*.conf;
}
The complete configuration of the file /etc/nginx/conf.d/default.conf is as follows:
server {
listen 80;
server_name localhost;
#charset koi8-r;
#access_log /var/log/nginx/log/host.access.log main;
#location / {
# root /usr/share/nginx/html;
# index index.html index.htm;
#}
location / {
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header REMOTE-HOST $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_pass http://web_servers;
}
location ~.*\.(js|css)$ {
root /opt/static-resources;
expires 12h;
}
location ~.*\.(html|jpg|jpeg|png|bmp|gif|ico|mp3|mid|wma|mp4|swf|flv|rar|zip|txt|doc|ppt|xls|pdf)$ {
root /opt/static-resources;
expires 7d;
}
#error_page 404 /404.html;
# redirect server error pages to the static page /50x.html
#
error_page 500 502 503 504 /50x.html;
location = /50x.html {
root /usr/share/nginx/html;
}
# proxy the PHP scripts to Apache listening on 127.0.0.1:80
#
#location ~ \.php$ {
# proxy_pass http://127.0.0.1;
#}
# pass the PHP scripts to FastCGI server listening on 127.0.0.1:9000
#
#location ~ \.php$ {
# root html;
# fastcgi_pass 127.0.0.1:9000;
# fastcgi_index index.php;
# fastcgi_param SCRIPT_FILENAME /scripts$fastcgi_script_name;
# include fastcgi_params;
#}
# deny access to .htaccess files, if Apache's document root
# concurs with nginx's one
#
#location ~ /\.ht {
# deny all;
#}
}
Note:If you do not have root privileges when executing commands, add sudo before the commands.