nginx.conf 3.9 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112
  1. load_module /usr/lib/nginx/modules/ngx_stream_module.so;
  2. user www-data; # Debian: www-data / CentOS: nginx
  3. worker_processes auto;
  4. pid /run/nginx.pid;
  5. error_log /var/log/nginx/error.log warn;
  6. worker_rlimit_nofile 16384;
  7. events {
  8. worker_connections 8192; #1024;
  9. }
  10. http {
  11. include /etc/nginx/mime.types;
  12. default_type application/octet-stream;
  13. sendfile on;
  14. tcp_nopush on;
  15. tcp_nodelay on;
  16. keepalive_timeout 65;
  17. server_tokens off;
  18. log_format main '$remote_addr - $remote_user [$time_local] "$request" '
  19. '$status $body_bytes_sent "$http_referer" "$http_user_agent" '
  20. 'proto=$ssl_protocol sni=$ssl_server_name';
  21. access_log /var/log/nginx/access.log main;
  22. # WebSocket map,http全局可以保留,只在使用proxy的location引用
  23. map $http_upgrade $connection_upgrade {
  24. default upgrade;
  25. '' close;
  26. }
  27. # ---------- HTTPS 服务:SSL 终结,反代内网 5004 ----------
  28. server {
  29. listen 127.0.0.1:5005 ssl;
  30. http2 on;
  31. server_name chanking.zhonjin.com;
  32. ssl_certificate /etc/letsencrypt/live/zhonjin.com/fullchain.pem;
  33. ssl_certificate_key /etc/letsencrypt/live/zhonjin.com/privkey.pem;
  34. ssl_session_cache shared:SSL:10m;
  35. ssl_session_timeout 1d;
  36. ssl_session_tickets off;
  37. ssl_protocols TLSv1.2 TLSv1.3;
  38. ssl_ciphers ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384;
  39. ssl_prefer_server_ciphers off;
  40. add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always;
  41. location / {
  42. proxy_pass http://127.0.0.1:5004;
  43. # proxy参数全部收拢在这里,不污染全局http和跳转server
  44. proxy_http_version 1.1;
  45. proxy_set_header Host $host;
  46. proxy_set_header X-Real-IP $remote_addr;
  47. proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
  48. proxy_set_header X-Forwarded-Proto $scheme;
  49. proxy_set_header Upgrade $http_upgrade;
  50. proxy_set_header Connection $connection_upgrade;
  51. proxy_connect_timeout 5s;
  52. #60s;
  53. proxy_read_timeout 3600s;
  54. proxy_send_timeout 60s;
  55. }
  56. }
  57. # ---------- HTTP 服务:仅做301跳转,不使用proxy ----------
  58. server {
  59. listen 127.0.0.1:5006;
  60. server_name chanking.zhonjin.com;
  61. return 301 https://$host:40130$request_uri;
  62. }
  63. #zhonjin_http.conf include 到 nginx.conf 的 http 块中!
  64. include /etc/nginx/conf.d/zhonjin_http.conf;
  65. }
  66. stream {
  67. error_log /var/log/nginx/stream_error.log warn;
  68. log_format stream_main '$remote_addr [$time_local] $protocol '
  69. 'preread=$ssl_preread_protocol status=$status '
  70. 'upstream=$upstream_addr bytes=$bytes_sent';
  71. map $ssl_preread_protocol $backend_target {
  72. "" 127.0.0.1:5006; # 明文HTTP → 301跳转
  73. default 127.0.0.1:5005; # TLS流量 → SSL解密入口
  74. }
  75. server {
  76. listen 40130 backlog=4096;
  77. tcp_nodelay on;
  78. ssl_preread on;
  79. # nginx >=1.23.4 才启用下面一行,低版本注释掉! 当前版本 1.26.3
  80. #ssl_preread_buffer_size 16k;
  81. proxy_pass $backend_target;
  82. proxy_connect_timeout 10s;
  83. # 3600s 和http proxy_read_timeout对齐
  84. proxy_timeout 3600s;
  85. proxy_next_upstream off;
  86. access_log /var/log/nginx/stream_access.log stream_main;
  87. }
  88. # 指向新的独立stream配置目录,不要用conf.d!!
  89. # include /etc/nginx/stream-conf/*.conf;
  90. include /etc/nginx/stream.d/zhonjin_stream.conf;
  91. }
  92. # ==========新增这一行include,其他全部不动==========
  93. #include /etc/nginx/conf.d/zhonjin.stream.conf;