|
|
@@ -1,30 +1,13 @@
|
|
|
-# ============================================================================
|
|
|
-# Nginx Stream + SSL Preread 自动分流主配置
|
|
|
-# 架构:TCP层协议检测 → TLS/HTTP分流 → SSL终结 → 反向代理内网服务
|
|
|
-# 版本:v2.0
|
|
|
-# 最后更新:2026-10-06
|
|
|
-#
|
|
|
-# 配置结构:
|
|
|
-# nginx.conf — 主配置(40130 端口 + 基础架构)
|
|
|
-# zhonjin_http.conf — 子域名 HTTP 服务配置(include 到 http 块)
|
|
|
-# zhonjin_stream.conf — 子域名 Stream 分流配置(include 到 stream 块)
|
|
|
-# zhonjin.com.conf — 配置总览说明文档
|
|
|
-# ============================================================================
|
|
|
-
|
|
|
load_module /usr/lib/nginx/modules/ngx_stream_module.so;
|
|
|
-
|
|
|
user www-data; # Debian: www-data / CentOS: nginx
|
|
|
worker_processes auto;
|
|
|
pid /run/nginx.pid;
|
|
|
error_log /var/log/nginx/error.log warn;
|
|
|
-
|
|
|
+worker_rlimit_nofile 16384;
|
|
|
events {
|
|
|
- worker_connections 8192;
|
|
|
+ worker_connections 8192; #1024;
|
|
|
}
|
|
|
|
|
|
-# ============================================================================
|
|
|
-# HTTP 块:SSL 终结 + 反向代理 + HTTP→HTTPS 跳转
|
|
|
-# ============================================================================
|
|
|
http {
|
|
|
include /etc/nginx/mime.types;
|
|
|
default_type application/octet-stream;
|
|
|
@@ -40,25 +23,20 @@ http {
|
|
|
'proto=$ssl_protocol sni=$ssl_server_name';
|
|
|
access_log /var/log/nginx/access.log main;
|
|
|
|
|
|
- # WebSocket 升级映射(全局定义,各 location 引用)
|
|
|
+ # WebSocket map,http全局可以保留,只在使用proxy的location引用
|
|
|
map $http_upgrade $connection_upgrade {
|
|
|
default upgrade;
|
|
|
'' close;
|
|
|
}
|
|
|
|
|
|
- # ========================================================================
|
|
|
- # 服务组 1:外网端口 40130 → 内网服务 http://127.0.0.1:5004
|
|
|
- # 域名:chanking.zhonjin.com
|
|
|
- # ========================================================================
|
|
|
-
|
|
|
- # HTTPS 服务:SSL 终结,反代内网 5004
|
|
|
+ # ---------- HTTPS 服务:SSL 终结,反代内网 5004 ----------
|
|
|
server {
|
|
|
listen 127.0.0.1:5005 ssl;
|
|
|
- http2 on;
|
|
|
+ http2 on;
|
|
|
server_name chanking.zhonjin.com;
|
|
|
|
|
|
- ssl_certificate /etc/letsencrypt/live/zhonjin.com/fullchain.pem;
|
|
|
- ssl_certificate_key /etc/letsencrypt/live/zhonjin.com/privkey.pem;
|
|
|
+ ssl_certificate /etc/letsencrypt/live/zhonjin.com/fullchain.pem;
|
|
|
+ ssl_certificate_key /etc/letsencrypt/live/zhonjin.com/privkey.pem;
|
|
|
ssl_session_cache shared:SSL:10m;
|
|
|
ssl_session_timeout 1d;
|
|
|
ssl_session_tickets off;
|
|
|
@@ -70,6 +48,8 @@ http {
|
|
|
|
|
|
location / {
|
|
|
proxy_pass http://127.0.0.1:5004;
|
|
|
+
|
|
|
+ # proxy参数全部收拢在这里,不污染全局http和跳转server
|
|
|
proxy_http_version 1.1;
|
|
|
proxy_set_header Host $host;
|
|
|
proxy_set_header X-Real-IP $remote_addr;
|
|
|
@@ -77,28 +57,25 @@ http {
|
|
|
proxy_set_header X-Forwarded-Proto $scheme;
|
|
|
proxy_set_header Upgrade $http_upgrade;
|
|
|
proxy_set_header Connection $connection_upgrade;
|
|
|
+
|
|
|
proxy_connect_timeout 5s;
|
|
|
+ #60s;
|
|
|
proxy_read_timeout 3600s;
|
|
|
proxy_send_timeout 60s;
|
|
|
}
|
|
|
}
|
|
|
|
|
|
- # HTTP 服务:301 跳转到 HTTPS(端口 40130)
|
|
|
+ # ---------- HTTP 服务:仅做301跳转,不使用proxy ----------
|
|
|
server {
|
|
|
listen 127.0.0.1:5006;
|
|
|
server_name chanking.zhonjin.com;
|
|
|
+
|
|
|
return 301 https://$host:40130$request_uri;
|
|
|
}
|
|
|
+#zhonjin_http.conf include 到 nginx.conf 的 http 块中!
|
|
|
+include /etc/nginx/conf.d/zhonjin_http.conf;
|
|
|
|
|
|
- # ========================================================================
|
|
|
- # 子域名扩展配置(mqtt.zhonjin.com / baolin.zhonjin.com)
|
|
|
- # ========================================================================
|
|
|
- include /etc/nginx/conf.d/zhonjin_http.conf;
|
|
|
}
|
|
|
-
|
|
|
-# ============================================================================
|
|
|
-# Stream 块:TCP 层协议检测 + 自动分流
|
|
|
-# ============================================================================
|
|
|
stream {
|
|
|
error_log /var/log/nginx/stream_error.log warn;
|
|
|
|
|
|
@@ -106,11 +83,8 @@ stream {
|
|
|
'preread=$ssl_preread_protocol status=$status '
|
|
|
'upstream=$upstream_addr bytes=$bytes_sent';
|
|
|
|
|
|
- # ========================================================================
|
|
|
- # Stream 服务组 1:外网端口 40130 → 内网 5004(chanking.zhonjin.com)
|
|
|
- # ========================================================================
|
|
|
- map $ssl_preread_protocol $backend_target_40130 {
|
|
|
- "" 127.0.0.1:5006; # 明文HTTP → 301跳转到HTTPS
|
|
|
+ map $ssl_preread_protocol $backend_target {
|
|
|
+ "" 127.0.0.1:5006; # 明文HTTP → 301跳转
|
|
|
default 127.0.0.1:5005; # TLS流量 → SSL解密入口
|
|
|
}
|
|
|
|
|
|
@@ -119,19 +93,20 @@ stream {
|
|
|
tcp_nodelay on;
|
|
|
|
|
|
ssl_preread on;
|
|
|
- # nginx >=1.23.4 才启用,低版本注释掉!当前版本 1.26.3
|
|
|
+ # nginx >=1.23.4 才启用下面一行,低版本注释掉! 当前版本 1.26.3
|
|
|
#ssl_preread_buffer_size 16k;
|
|
|
|
|
|
- proxy_pass $backend_target_40130;
|
|
|
+ proxy_pass $backend_target;
|
|
|
proxy_connect_timeout 10s;
|
|
|
- proxy_timeout 3600s;
|
|
|
+ # 3600s 和http proxy_read_timeout对齐
|
|
|
+ proxy_timeout 3600s;
|
|
|
proxy_next_upstream off;
|
|
|
|
|
|
- access_log /var/log/nginx/stream_access_40130.log stream_main;
|
|
|
+ access_log /var/log/nginx/stream_access.log stream_main;
|
|
|
}
|
|
|
-
|
|
|
- # ========================================================================
|
|
|
- # 子域名扩展 Stream 配置(mqtt / baolin)
|
|
|
- # ========================================================================
|
|
|
+# 指向新的独立stream配置目录,不要用conf.d!!
|
|
|
+# include /etc/nginx/stream-conf/*.conf;
|
|
|
include /etc/nginx/stream.d/zhonjin_stream.conf;
|
|
|
}
|
|
|
+# ==========新增这一行include,其他全部不动==========
|
|
|
+#include /etc/nginx/conf.d/zhonjin.stream.conf;
|