1. Install Nginx

1.1 Choose the Stable Version

We compile and install Nginx to customize our own modules, on a CentOS 6.2 x86_64 machine. First, install the missing dependency packages:

# yum -y install gcc gcc-c++ make libtool zlib zlib-devel openssl openssl-devel pcre pcre-devel

If these packages are not available in yum, you can download the source code to compile and install them. Just pay attention to the default installation directory during compilation, and make sure the dynamic library files can be found when installing Nginx below (ldconfig).

nginx 服务器安装及配置文件详解

fromhttp://nginx.org/en/download.htmlDownload the stable version nginx-1.6.3.tar.gz to /usr/local/src and extract it.

For subsequent preparation, we also download 2 plugin modules:nginx_upstream_check_module-0.3.0.tar.gz— Check the status of backend servers,nginx-goodies-nginx-sticky-module-ng-bd312d586752.tar.gz(It is recommended to rename the directory to nginx-sticky-module-ng-1.2.5 after extracting it under /usr/local/src) — for the backendload balancingSolve the session sticky problem (when used with the upstream_check module, an additional patch is needed, please refer toNginx Load Balancing Configuration in Practice)。

Please note the version compatibility between plugins and Nginx. Generally, the newer the plugin, the better; Nginx does not need to chase the newest version, stability comes first. nginx-1.4.7, nginx-sticky-module-1.1, nginx_upstream_check_module-0.2.0, this combination is also fine. sticky-1.1 with nginx-1.6 versions caused compilation errors due to updates not keeping up. (You can directly use Tengine, which includes these modules by default)

[root@cachets nginx-1.6.3]# pwd
/usr/local/src/nginx-1.6.3
[root@cachets nginx-1.6.3]# ./configure --prefix=/usr/local/nginx-1.6 --with-pcre /
> --with-http_stub_status_module --with-http_ssl_module /
> --with-http_gzip_static_module --with-http_realip_module /
> --add-module=../nginx_upstream_check_module-0.3.0
[root@cachets nginx-1.6.3]# make && make install

1.2 Description of Common Compilation Options

Most of Nginx's commonly used modules are installed by default when compiling; those starting with --without in ./configure --help are installed by default.

  • --prefix=PATH: Specifies the Nginx installation directory. Default is /usr/local/nginx
  • --conf-path=PATH: Sets the path of the nginx.conf configuration file. Nginx allows starting with different configuration files via the -c option on the command line. Default isprefix/conf/nginx.conf
  • --user=name: Sets the user of the Nginx worker processes. After installation, you can change the user directive in the nginx.conf configuration file at any time. The default user name is nobody. --group=name is similar.
  • --with-pcre: Sets the source code path of the PCRE library. If it has been installed via yum, use --with-pcre to automatically find the library files. When using --with-pcre=PATH, you need to download the source code of the pcre library (versions 4.4 – 8.30) from the PCRE website and extract it; the rest is left to Nginx's ./configure and make. Perl regular expressions are used in the location directive and the ngx_http_rewrite_module module.
  • --with-zlib=PATH: Specifies the source extraction directory of zlib (versions 1.1.3 – 1.2.5). zlib is required for the network transmission compression module ngx_http_gzip_module, which is enabled by default.
  • --with-http_ssl_module: Uses the HTTPS protocol module. By default, this module is not built. The prerequisite is that openssl and openssl-devel are installed.
  • --with-http_stub_status_module: Used to monitor the current status of Nginx
  • --with-http_realip_module: This module allows us to change the client IP address value in the client request headers (such as X-Real-IP or X-Forwarded-For). The significance is that it enables backend servers to record the original client IP address.
  • --add-module=PATH: Adds third-party external modules, such as nginx-sticky-module-ng or cache modules. Every time a new module is added, recompilation is required (Tengine can add new modules without recompilation).

Here is another compilation scheme:

./configure /
> --prefix=/usr /
> --sbin-path=/usr/sbin/nginx /
> --conf-path=/etc/nginx/nginx.conf /
> --error-log-path=/var/log/nginx/error.log /
> --http-log-path=/var/log/nginx/access.log /
> --pid-path=/var/run/nginx/nginx.pid  /
> --lock-path=/var/lock/nginx.lock /   
> --user=nginx /
> --group=nginx /
> --with-http_ssl_module /
> --with-http_stub_status_module /
> --with-http_gzip_static_module /
> --http-client-body-temp-path=/var/tmp/nginx/client/ /
> --http-proxy-temp-path=/var/tmp/nginx/proxy/ /
> --http-fastcgi-temp-path=/var/tmp/nginx/fcgi/ /
> --http-uwsgi-temp-path=/var/tmp/nginx/uwsgi /
> --with-pcre=../pcre-7.8
> --with-zlib=../zlib-1.2.3

1.3 Start and Stop Nginx

## 检查配置文件是否正确
# /usr/local/nginx-1.6/sbin/nginx -t 
# ./sbin/nginx -V     # 可以看到编译选项
## 启动、关闭
# ./sbin/nginx        # 默认配置文件 conf/nginx.conf,-c 指定
# ./sbin/nginx -s stop
或 pkill nginx
## 重启,不会改变启动时指定的配置文件
# ./sbin/nginx -s reload
或 kill -HUP `cat /usr/local/nginx-1.6/logs/nginx.pid`

Of course, you can also manage Nginx as a system service. Download nginx to /etc/init.d/, modify the paths inside, and then give it executable permissions.

# service nginx {start|stop|status|restart|reload|configtest}

1.4 Install via yum

Installing the RPM package via yum is much simpler than compiling and installing. Many modules are installed by default, but the downside is that if you want to install third-party modules later, there is no way to do so.

# vi /etc/yum.repo.d/nginx.repo 
[nginx] 
name=nginx repo 
baseurl=http://nginx.org/packages/centos/$releasever/$basearch/ 
gpgcheck=0 
enabled=1

The rest is done with yum install nginx. You can also use yum install nginx-1.6.3 to install a specific version (provided you see the corresponding version in packages; the default is the latest stable version).

2. nginx.conf Configuration File

The Nginx configuration file is mainly divided into four parts: main (global settings), server (host settings), upstream (upstream server settings, mainly related to reverse proxy and load balancing configurations), and location (settings after URL matches a specific location). Each part contains several directives. Directives set in the main part affect the settings of all other parts; directives in the server part are mainly used to specify virtual host domain names, IPs, and ports; directives in upstream are used to set a series of backend servers, configure reverse proxy and load balancing of backend servers; the location part is used to match web page locations (for example, root directory "/", "/images", etc.). The relationship between them is: server inherits main, location inherits server; upstream neither inherits directives nor is inherited. It has its own special directives and does not need to be applied elsewhere.

Several directive contexts currently supported by Nginx:

2.1 General

The following nginx.conf is a simple example of Nginx acting as a reverse proxy server at the front end, handling static files such as js and png, and forwarding dynamic requests such as jsp to another server, Tomcat:

user  www www;
worker_processes  2;
error_log  logs/error.log;
#error_log  logs/error.log  notice;
#error_log  logs/error.log  info;
pid        logs/nginx.pid;
events {
    use epoll;
    worker_connections  2048;
}
http {
    include       mime.types;
    default_type  application/octet-stream;
    #log_format  main  '$remote_addr - $remote_user [$time_local] "$request" '
    #                  '$status $body_bytes_sent "$http_referer" '
    #                  '"$http_user_agent" "$http_x_forwarded_for"';
    #access_log  logs/access.log  main;
    sendfile        on;
    # tcp_nopush     on;
    keepalive_timeout  65;
  # gzip压缩功能设置
    gzip on;
    gzip_min_length 1k;
    gzip_buffers    4 16k;
    gzip_http_version 1.0;
    gzip_comp_level 6;
    gzip_types text/html text/plain text/css text/javascript application/json application/javascript application/x-javascript application/xml;
    gzip_vary on;

  # http_proxy 设置
    client_max_body_size   10m;
    client_body_buffer_size   128k;
    proxy_connect_timeout   75;
    proxy_send_timeout   75;
    proxy_read_timeout   75;
    proxy_buffer_size   4k;
    proxy_buffers   4 32k;
    proxy_busy_buffers_size   64k;
    proxy_temp_file_write_size  64k;
    proxy_temp_path   /usr/local/nginx/proxy_temp 1 2;
  # 设定负载均衡后台服务器列表 
    upstream  backend  { 
              #ip_hash; 
              server   192.168.10.100:8080 max_fails=2 fail_timeout=30s ;  
              server   192.168.10.101:8080 max_fails=2 fail_timeout=30s ;  
    }
  # 很重要的虚拟主机配置
    server {
        listen       80;
        server_name  itoatest.example.com;
        root   /apps/oaapp;
        charset utf-8;
        access_log  logs/host.access.log  main;
        #对 / 所有做负载均衡+反向代理
        location / {
            root   /apps/oaapp;
            index  index.jsp index.html index.htm;
            proxy_pass        http://backend;  
            proxy_redirect off;
            # 后端的Web服务器可以通过X-Forwarded-For获取用户真实IP
            proxy_set_header  Host  $host;
            proxy_set_header  X-Real-IP  $remote_addr;  
            proxy_set_header  X-Forwarded-For  $proxy_add_x_forwarded_for;
            proxy_next_upstream error timeout invalid_header http_500 http_502 http_503 http_504;

        }
        #静态文件,nginx自己处理,不去backend请求tomcat
        location  ~* /download/ {  
            root /apps/oa/fs;  

        }
        location ~ .*/.(gif|jpg|jpeg|bmp|png|ico|txt|js|css)$   
        {   
            root /apps/oaapp;   
            expires      7d; 
        }
           location /nginx_status {
            stub_status on;
            access_log off;
            allow 192.168.10.0/24;
            deny all;
        }
        location ~ ^/(WEB-INF)/ {   
            deny all;   
        }
        #error_page  404              /404.html;
        # redirect server error pages to the static page /50x.html
        #
        error_page   500 502 503 504  /50x.html;
        location = /50x.html {
            root   html;
        }
    }
  ## 其它虚拟主机,server 指令开始
}

2.2 Description of Common Directives

2.2.1 main Global Configuration

Some parameters of Nginx at runtime that are unrelated to specific business functions (such as HTTP service or email service proxy), for example, the number of worker processes, the running identity, etc.

  • woker_processes 2
    In the top-level section of the configuration file, the number of worker processes in the worker role. The master process receives requests and assigns them to workers for processing. To keep it simple, this value can be set to the number of CPU cores `grep ^processor /proc/cpuinfo | wc -l`, which is also the `auto` value. If SSL and gzip are enabled, it should be set to the same as the number of logical CPUs or even twice as many, which can reduce I/O operations. If the Nginx server also runs other services, consider reducing it appropriately.mainAlso written in the main section.
  • worker_cpu_affinity
    In high-concurrency situations, set CPU affinity to reduce the performance loss caused by the reconstruction of registers and other contexts due to multi-core CPU switching. For example: worker_cpu_affinity 0001 0010 0100 1000; (four cores).mainWritten in the
  • worker_connections 2048
    section. Each worker process can concurrently handle (initiate) the maximum number of connections (including all connections with clients or proxied backend servers). When Nginx acts as a reverse proxy server, the calculation formula is: maximum connections = worker_processes * worker_connections / 4, so the maximum client connections here is 1024. This can be increased to 8192 without issue, depending on the situation, but it cannot exceed the later worker_rlimit_nofile. When Nginx acts as an HTTP server, the calculation formula is divided by 2.eventsWritten in the
  • worker_rlimit_nofile 10240
    section. By default it is not set, and can be limited to the operating system maximum 65535.mainWritten in the events section. On Linux, Nginx uses the epoll event model by default. Thanks to this, Nginx is quite efficient on Linux. At the same time, Nginx uses kqueue, a high-efficiency event model similar to epoll, on OpenBSD or FreeBSD systems. select is used only when the operating system does not support these high-efficiency models.
  • use epoll
    2.2.2 HTTP Server

Some configuration parameters related to providing HTTP services. For example: whether to use keepalive, whether to use gzip for compression, etc.

Enable high-efficiency file transfer mode. The sendfile directive specifies whether Nginx calls the sendfile function to output files, reducing context switches from user space to kernel space. For ordinary applications, set it to on; for applications with heavy disk I/O load such as downloads, it can be set to off to balance disk and network I/O processing speeds and reduce system load.

  • sendfile on
    Enable efficient file transfer mode. The sendfile directive specifies whether nginx calls the sendfile function to output files, reducing context switches from user space to kernel space. For normal applications, set it to on; if used for applications with heavy disk I/O load such as downloads, it can be set to off to balance disk and network I/O processing speeds and reduce system load.
  • keepalive_timeout 65 : keep-alive timeout in seconds. This parameter is very sensitive, involving browser types, backend server timeout settings, and operating system settings; it could be the subject of another article. With keep-alive, when requesting many small files, the overhead of re-establishing connections can be reduced. However, if there is a large file upload and it is not completed within 65 seconds, it will fail. If the timeout is set too long and there are many users, holding connections for a long time will consume a lot of resources.
  • send_timeout : used to specify the timeout for responding to the client. This timeout is limited to the time between two connection activities. If the client has no activity beyond this time, Nginx will close the connection.
  • client_max_body_size 10m
    The maximum single-file byte size allowed for client requests. If there are large file uploads, set its limit.
  • client_body_buffer_size 128k
    The maximum number of bytes for buffering client requests in the proxy buffer.
Module http_proxy:

This module implements the functionality of Nginx as a reverse proxy server, including caching (also seearticle)

  • proxy_connect_timeout 60
    Timeout for Nginx connecting to backend servers (proxy connection timeout)
  • proxy_read_timeout 60
    After a successful connection, the timeout between two successful response operations with the backend server (proxy receive timeout)
  • proxy_buffer_size 4k
    Set the buffer size for the proxy server (nginx) to read and save userheadinformation from the backend realserver. The default is the same as the proxy_buffers size; in fact, you can set this directive value a bit smaller.
  • proxy_buffers 4 32k
    proxy_buffers buffer: nginx caches from the backend realserver for a single connectionresponsesIf the average web page is below 32k, configure it like this
  • proxy_busy_buffers_size 64k
    Buffer size under high load (proxy_buffers*2)
  • proxy_max_temp_file_size
    When proxy_buffers cannot hold the response content from the backend server, part of it will be saved to a temporary file on disk. This value sets the maximum temporary file size; the default is 1024M. It has nothing to do with proxy_cache. If larger than this value, the content will be transmitted back from the upstream server. Setting it to 0 disables it.
  • proxy_temp_file_write_size 64k
    When cached proxied server responses are written to temporary files, this option limits the size of each write to the temporary file. proxy_temp_path (which can be set at compile time) specifies the directory to write to.

proxy_pass and proxy_redirect, see the location section.

Module http_gzip:
  • gzip on : enable gzip compressed output to reduce network transmission.
    • gzip_min_length 1k : set the minimum page byte size allowed for compression. The page byte size is obtained from the content-length in the header. The default value is 20. It is recommended to set it to a byte size greater than 1k; below 1k, the file may become larger after compression.
    • gzip_buffers 4 16k : set how many units of cache the system obtains to store the gzip compressed result data stream. "4 16k" means using 16k as a unit, allocating memory 4 times the original data size in 16k units.
    • gzip_http_version 1.0 : used to identify the HTTP protocol version. Early browsers do not support gzip compression, and users would see garbled text. So this option was added to support earlier versions. If you use Nginx as a reverse proxy and want to enable gzip compression as well, since the backend communication is http/1.0, please set it to 1.0.
    • gzip_comp_level 6 : gzip compression ratio. 1 has the smallest compression ratio and the fastest processing speed; 9 has the largest compression ratio but the slowest processing speed (faster transmission but more CPU-intensive).
    • gzip_types : match MIME types for compression. Whether specified or not, the "text/html" type is always compressed.
    • gzip_proxied any : enabled when Nginx acts as a reverse proxy. It decides whether to enable or disable compression of the results returned from the backend server. The prerequisite for matching is that the backend server must return a header containing "Via".
    • gzip_vary on : related to HTTP headers. It adds a "Vary: Accept-Encoding" response header, allowing front-end cache servers to cache gzip-compressed pages. For example, use Squid to cache data compressed by Nginx.

2.2.3 server virtual hosts

The http service supports several virtual hosts. Each virtual host has a corresponding server configuration block, which contains the configuration related to that virtual host. When providing a mail service proxy, several server blocks can also be created. Each server is distinguished by its listening address or port.

  • listen
    Listening port, default 80. Ports below 1024 must be started as root. It can be in forms such as listen *:80, listen 127.0.0.1:80, etc.
  • server_name
    Server name, such as localhost, www.example.com. It can be matched with regular expressions.
Module http_stream

This module implements load balancing from client IPs to backend servers through a simple scheduling algorithm. "upstream" is followed by the name of the load balancer, and backend realservers are organized in {} as host:port options;. If there is only one backend being proxied, it can also be written directly in proxy_pass.

2.2.4 location

In the http service, a series of configuration directives corresponding to certain specific URLs.

  • root /var/www/html
    Defines the default website root directory location for the server. If the location URL matches a subdirectory or file, root has little effect. It is usually placed in the server directive or under "/".
  • index index.jsp index.html index.htm
    Defines the default filename to access under the path. It is usually placed together with root.
  • proxy_pass http:/backend
    Forwards requests to the server list defined by backend, i.e., reverse proxy, corresponding to the upstream load balancer. It can also be proxy_pass http://ip:port.
  • proxy_redirect off;
    proxy_set_header Host $host;
    proxy_set_header X-Real-IP $remote_addr;
    proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
    For the time being, set these four like this. If you dig deeper, each involves very complex content, which will be explained in another article.

Regarding the syntax of location matching rules, it can be said to be particularly critical and fundamental. See the articleSummary of Nginx location configuration and rewrite rule syntax;

2.3 Others

2.3.1 Access control allow/deny

Nginx's access control module is installed by default, and its syntax is also very simple. There can be multiple allow and deny directives, allowing or blocking access from a specific IP or IP range. Once any rule is matched in order, matching stops. For example:

location /nginx-status {
  stub_status on;
  access_log off;
#  auth_basic   "NginxStatus";
#  auth_basic_user_file   /usr/local/nginx-1.6/htpasswd;
  allow 192.168.10.100;
  allow 172.29.73.0/24;
  deny all;
}

We also often use htpasswd from the httpd-devel tool to set a login password for the accessed path:

# htpasswd -c htpasswd admin
New passwd:
Re-type new password:
Adding password for user admin
# htpasswd htpasswd admin    //修改admin密码
# htpasswd htpasswd sean    //多添加一个认证用户

This generates a password file encrypted with CRYPT by default. Uncomment the two lines of nginx-status above, and restart Nginx for it to take effect.

2.3.2 List directory autoindex

By default, Nginx does not allow listing the entire directory. If you need this feature, open the nginx.conf file and add "autoindex on;" in the location, server, or http section. It is also best to add the other two parameters:

  • autoindex_exact_size off; The default is on, showing the exact file size in bytes. After changing to off, it shows the approximate file size in kB, MB, or GB.
  • autoindex_localtime on;
    The default is off, displaying the file time as GMT time. After changing to on, the displayed file time is the server time of the file.
location /images {
  root   /var/www/nginx-default/images;
  autoindex on;
  autoindex_exact_size off;
  autoindex_localtime on;
}

References