Nginx 是一个高性能的 HTTP 和反向代理 web 服务器,同时也提供了 IMAP/POP3/SMTP 服务,其因丰富的功能集、稳定性、示例配置文件和低系统资源的消耗受到了开发者的欢迎。
本文,我们总结了一些常用的 Nginx 配置代码,希望对大家有所帮助。
监听端口
server {
# Standard HTTP Protocol 标准HTTP协议
listen 80;
# Standard HTTPS Protocol 标准HTTPS协议
listen 443 ssl;
# For http2
listen 443 ssl http2;
# Listen on 80 using IPv6
listen [::]:80;
# Listen only on using IPv6
listen [::]:80 ipv6only=on;
}
访问日志
server {
# Relative or full path to log file
access_log /path/to/file.log;
# Turn 'on' or 'off'
access_log on;
}
域名
server {
# Listen to domains(域名)
server_name www.domain.com;
# Listen to multiple domains
server_name www.domain.com www.domain.com;
# Listen to all domains
server_name *.domain.com;
# Listen to all top-level domains
server_name domain.*;
# Listen to unspecified Hostnames (Listens to IP address itself)
server_name "";
}
静态资产
server {
listen 80;
server_name domain.com;
location / {
root /z/workspace/builduis/web-b/dist;
}
}
重定向
server {
listen 80;
server_name www.domain.com;
return 301 http://domain.com$request_uri;
}
server {
listen 80;
server_name www.domain.com;
location /redirect-url {
return 301 http://otherdomain.com;
}
}
反向代理
server {
listen 80;
server_name domain.com;
location / {
proxy_pass http://192.168.5.110:8010;
}
}
负载均衡
upstream app-server {
server 0.0.0.0:8010;
server 0.0.0.0:8011;
server 192.168.5.110;
}
server {
listen 80;
server_name domain.com;
location / {
proxy_pass http://app-server;
}
}
SSL 协议
server {
listen 443 ssl;
server_name domain.com;
ssl on;
ssl_certificate /path/to/cert.pem;
ssl_certificate_key /path/to/privatekey.pem;
ssl_stapling on;
ssl_stapling_verify on;
ssl_trusted_certificate /path/to/fullchain.pem;
ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
ssl_session_timeout 1h;
ssl_session_cache shared:SSL:50m;
add_header Strict-Transport-Security max-age=15768000;
}
# Permanent Redirect for HTTP to HTTPS
server {
listen 80;
server_name domain.com;
return 301 https://$host$request_uri;
}
前后端配置示例
server {
listen 80;
server_name 192.168.5.110; #项目域名
root /z/workspace/builduis/web-a/dist; #vue项目打包后的dist
location / {
try_files $uri $uri/ /index.html; #解决页面刷新404问题
index index.html;
}
location /prod-api/ { #后端服务
proxy_pass http://192.168.5.110:8080/;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_set_header X-Real-IP $remote_addr;
proxy_connect_timeout 600;
proxy_read_timeout 600;
proxy_send_timeout 600;
proxy_buffer_size 64k;
proxy_buffers 4 32k;
proxy_busy_buffers_size 64k;
proxy_temp_file_write_size 64k;
}
error_page 500 502 503 504 /50x.html;
location = /50x.html {
root /usr/share/nginx/html;
}
}