RASPBERRYPI_SETUP.md 11 KB

树莓派 5 8G 部署指南

Nginx Stream + SSL Preread 自动分流方案在树莓派 5 上的完整安装、编译和运行指南。

适用系统:Ubuntu 24.04 for Raspberry Pi / Raspberry Pi OS (Bookworm)
硬件:Raspberry Pi 5 8GB
最后更新:2026-10-06


目录

  1. 系统准备
  2. Nginx 安装
  3. 从源码编译 Nginx(可选)
  4. SSL 证书配置
  5. 配置部署
  6. 防火墙设置
  7. 性能优化
  8. 开机自启与守护进程
  9. 验证与测试
  10. 常见问题

1. 系统准备

1.1 系统更新

sudo apt update && sudo apt upgrade -y
sudo apt install -y curl wget git vim htop net-tools build-essential

1.2 确认系统版本

lsb_release -a
uname -r
uname -m          # 应为 aarch64
free -h           # 应为 8GB

1.3 设置静态 IP(推荐)

sudo vim /etc/netplan/50-cloud-init.yaml
network:
  version: 2
  ethernets:
    eth0:
      dhcp4: no
      addresses:
        - 192.168.1.100/24
      routes:
        - to: default
          via: 192.168.1.1
      nameservers:
        addresses: [8.8.8.8, 114.114.114.114]
sudo netplan apply

1.4 设置时区

sudo timedatectl set-timezone Asia/Shanghai
timedatectl

2. Nginx 安装

2.1 方式一:APT 安装(推荐)

sudo apt install -y nginx-full
nginx -v
nginx -V 2>&1 | grep -o "with-stream"

2.2 方式二:PPA 安装(获取更新版本)

sudo add-apt-repository ppa:nginx/stable
sudo apt update
sudo apt install -y nginx-full

2.3 验证模块完整性

nginx -V 2>&1 | grep -E "with-stream|with-http_ssl_module|with-http_v2_module"

必需模块清单:

模块 用途
with-stream TCP/UDP 代理
with-stream_ssl_module Stream SSL 支持
with-stream_ssl_preread_module TLS ClientHello 预读
with-http_ssl_module HTTP SSL 终结
with-http_v2_module HTTP/2 支持

3. 从源码编译 Nginx(可选)

3.1 安装编译依赖

sudo apt install -y \
    build-essential libpcre3 libpcre3-dev \
    zlib1g zlib1g-dev libssl-dev \
    libgd-dev libgeoip-dev libxml2-dev libxslt1-dev

3.2 下载源码

NGINX_VERSION="1.26.3"
cd /tmp
wget https://nginx.org/download/nginx-${NGINX_VERSION}.tar.gz
tar -xzf nginx-${NGINX_VERSION}.tar.gz
cd nginx-${NGINX_VERSION}

3.3 编译配置

./configure \
    --prefix=/etc/nginx \
    --sbin-path=/usr/sbin/nginx \
    --modules-path=/usr/lib/nginx/modules \
    --conf-path=/etc/nginx/nginx.conf \
    --error-log-path=/var/log/nginx/error.log \
    --http-log-path=/var/log/nginx/access.log \
    --pid-path=/var/run/nginx.pid \
    --lock-path=/var/run/nginx.lock \
    --user=www-data \
    --group=www-data \
    --with-stream \
    --with-stream_ssl_module \
    --with-stream_ssl_preread_module \
    --with-http_ssl_module \
    --with-http_v2_module \
    --with-http_geoip_module \
    --with-http_realip_module \
    --with-http_gzip_static_module \
    --with-http_sub_module \
    --with-http_stub_status_module \
    --with-pcre-jit \
    --with-cc-opt="-march=armv8-a+crc -mtune=cortex-a76" \
    --with-ld-opt="-Wl,-z,relro -Wl,-z,now"

树莓派特定编译优化:

参数 说明
-march=armv8-a+crc 利用 ARMv8 CRC 指令加速
-mtune=cortex-a76 针对树莓派 5 的 Cortex-A76 优化
-Wl,-z,relro 只读重定位,安全加固
--with-pcre-jit PCRE JIT 编译,正则加速

3.4 编译安装

make -j4    # 4 核并行编译,约 5-15 分钟
sudo make install
nginx -V

3.5 创建 Systemd 服务

sudo vim /etc/systemd/system/nginx.service
[Unit]
Description=The nginx HTTP and reverse proxy server
After=network-online.target remote-fs.target nss-lookup.target
Wants=network-online.target

[Service]
Type=forking
PIDFile=/var/run/nginx.pid
ExecStartPre=/usr/sbin/nginx -t
ExecStart=/usr/sbin/nginx
ExecReload=/bin/kill -s HUP $MAINPID
ExecStop=/bin/kill -s QUIT $MAINPID
PrivateTmp=true
TimeoutStopSec=5
KillMode=mixed

[Install]
WantedBy=multi-user.target
sudo systemctl daemon-reload
sudo systemctl enable nginx

4. SSL 证书配置

4.1 安装 Certbot

sudo apt install -y certbot python3-certbot-nginx

4.2 申请通配符证书

sudo certbot certonly --manual --preferred-challenges dns \
    -d zhonjin.com -d "*.zhonjin.com"

按提示添加 DNS TXT 记录,覆盖所有子域名:

  • zhonjin.com
  • chanking.zhonjin.com
  • mqtt.zhonjin.com
  • baolin.zhonjin.com

4.3 证书目录权限

sudo chmod 755 /etc/letsencrypt/live/
sudo chmod 644 /etc/letsencrypt/live/zhonjin.com/fullchain.pem
sudo chmod 600 /etc/letsencrypt/live/zhonjin.com/privkey.pem
sudo chown root:root /etc/letsencrypt/live/zhonjin.com/privkey.pem

4.4 自动续期

sudo certbot renew --dry-run    # 测试续期
sudo crontab -e
# 添加:
0 3 * * * certbot renew --quiet --post-hook "nginx -s reload"

5. 配置部署

5.1 部署配置文件

# 创建配置目录
sudo mkdir -p /etc/nginx/conf.d /etc/nginx/stream.d

# 备份原始配置
sudo cp /etc/nginx/nginx.conf /etc/nginx/nginx.conf.bak

# 部署新配置
sudo cp nginx.conf /etc/nginx/nginx.conf
sudo cp zhonjin_http.conf /etc/nginx/conf.d/zhonjin_http.conf
sudo cp zhonjin_stream.conf /etc/nginx/stream.d/zhonjin_stream.conf

# 测试并重载
sudo nginx -t
sudo systemctl reload nginx

5.2 验证端口监听

sudo ss -tlnp | grep nginx

# 预期输出应包含:
# 0.0.0.0:40130    (stream 外网 - chanking)
# 0.0.0.0:40715    (stream 外网 - mqtt)
# 0.0.0.0:40716    (stream 外网 - baolin)
# 0.0.0.0:40719    (stream 外网 - baolin)
# 127.0.0.1:5005   (HTTPS 内网)
# 127.0.0.1:5006   (HTTP 跳转)
# ... 其他内部端口

6. 防火墙设置

6.1 UFW 防火墙(推荐)

sudo ufw enable
sudo ufw allow 22/tcp          # SSH
sudo ufw allow 40130/tcp       # chanking
sudo ufw allow 40715/tcp       # mqtt
sudo ufw allow 40716/tcp       # baolin
sudo ufw allow 40719/tcp       # baolin
sudo ufw default deny incoming
sudo ufw default allow outgoing
sudo ufw status verbose

6.2 iptables(备选)

sudo iptables -A INPUT -p tcp --dport 40130 -j ACCEPT
sudo iptables -A INPUT -p tcp --dport 40715 -j ACCEPT
sudo iptables -A INPUT -p tcp --dport 40716 -j ACCEPT
sudo iptables -A INPUT -p tcp --dport 40719 -j ACCEPT
sudo iptables -A INPUT -p tcp --dport 22 -j ACCEPT
sudo iptables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
sudo iptables -A INPUT -j DROP

sudo apt install -y iptables-persistent
sudo netfilter-persistent save

7. 性能优化

7.1 内核参数优化

sudo vim /etc/sysctl.d/99-nginx-performance.conf
net.core.somaxconn = 65535
net.ipv4.tcp_max_syn_backlog = 65535
net.ipv4.tcp_fin_timeout = 30
net.ipv4.tcp_tw_reuse = 1
net.ipv4.tcp_keepalive_time = 600
net.core.rmem_max = 16777216
net.core.wmem_max = 16777216
net.ipv4.tcp_rmem = 4096 87380 16777216
net.ipv4.tcp_wmem = 4096 65536 16777216
fs.file-max = 2097152
sudo sysctl -p /etc/sysctl.d/99-nginx-performance.conf

7.2 文件描述符限制

sudo vim /etc/security/limits.conf
* soft nofile 65535
* hard nofile 65535
www-data soft nofile 65535
www-data hard nofile 65535

7.3 Systemd 服务优化

sudo mkdir -p /etc/systemd/system/nginx.service.d
sudo vim /etc/systemd/system/nginx.service.d/override.conf
[Service]
LimitNOFILE=65535
Nice=-5
CPUQuota=80%
sudo systemctl daemon-reload
sudo systemctl restart nginx

7.4 树莓派特定优化

# 禁用 swap(减少 SD 卡写入)
sudo dphys-swapfile swapoff
sudo apt remove -y dphys-swapfile

# 使用 tmpfs 存储日志(减少 SD 卡写入)
sudo vim /etc/fstab
# 添加:
tmpfs /var/log/nginx tmpfs defaults,noatime,size=50m 0 0

注意:使用 tmpfs 存储日志时,日志在重启后会丢失。如需持久化日志,建议使用外接 USB 存储。


8. 开机自启与守护进程

8.1 启用开机自启

sudo systemctl enable nginx
sudo systemctl start nginx
sudo systemctl status nginx

8.2 监控脚本

sudo vim /usr/local/bin/nginx-monitor.sh
#!/bin/bash
if ! pgrep -x nginx > /dev/null; then
    echo "$(date): Nginx 进程不存在,尝试重启..." >> /var/log/nginx-monitor.log
    sudo systemctl start nginx
    echo "$(date): Nginx 已重启" >> /var/log/nginx-monitor.log
fi
sudo chmod +x /usr/local/bin/nginx-monitor.sh

# 每 5 分钟检查一次
sudo crontab -e
# 添加:
*/5 * * * * /usr/local/bin/nginx-monitor.sh

9. 验证与测试

9.1 完整功能验证

# 测试 HTTPS 访问(各域名)
curl -I https://chanking.zhonjin.com:40130
curl -I https://mqtt.zhonjin.com:40715
curl -I https://baolin.zhonjin.com:40716
curl -I https://baolin.zhonjin.com:40719

# 测试 HTTP → HTTPS 跳转(各域名)
curl -I http://chanking.zhonjin.com:40130    # 应返回 301
curl -I http://mqtt.zhonjin.com:40715        # 应返回 301
curl -I http://baolin.zhonjin.com:40716      # 应返回 301
curl -I http://baolin.zhonjin.com:40719      # 应返回 301

# 验证 SSL 证书
echo | openssl s_client -connect chanking.zhonjin.com:40130 -servername chanking.zhonjin.com 2>/dev/null | openssl x509 -noout -dates
echo | openssl s_client -connect mqtt.zhonjin.com:40715 -servername mqtt.zhonjin.com 2>/dev/null | openssl x509 -noout -dates

9.2 性能基准测试

sudo apt install -y apache2-utils

# 压力测试
ab -n 1000 -c 50 https://chanking.zhonjin.com:40130/
ab -n 1000 -c 50 https://mqtt.zhonjin.com:40715/

10. 常见问题

Q1: 编译时报内存不足

# 添加临时 swap
sudo fallocate -l 2G /tmp/swapfile
sudo chmod 600 /tmp/swapfile
sudo mkswap /tmp/swapfile
sudo swapon /tmp/swapfile
# 编译完成后移除
sudo swapoff /tmp/swapfile && sudo rm /tmp/swapfile

Q2: stream 模块报 "unknown directive"

dpkg -l | grep nginx
sudo apt install -y nginx-full    # 替换 nginx-light

Q3: include 文件找不到

sudo mkdir -p /etc/nginx/conf.d /etc/nginx/stream.d
sudo cp zhonjin_http.conf /etc/nginx/conf.d/
sudo cp zhonjin_stream.conf /etc/nginx/stream.d/

Q4: 通配符证书不生效

# 检查证书覆盖域名
openssl x509 -in /etc/letsencrypt/live/zhonjin.com/fullchain.pem \
    -noout -text | grep -A1 "Subject Alternative Name"
# 应包含 *.zhonjin.com

Q5: 树莓派 SD 卡写入寿命

  • 将日志目录挂载为 tmpfs
  • 使用外接 SSD/USB 存储持久化日志
  • 关闭不必要的日志

快速部署脚本

#!/bin/bash
set -e
echo "=== 树莓派 5 Nginx 快速部署 ==="
sudo apt update && sudo apt upgrade -y
sudo apt install -y nginx-full certbot python3-certbot-nginx
sudo mkdir -p /etc/nginx/conf.d /etc/nginx/stream.d
sudo cp nginx.conf /etc/nginx/nginx.conf
sudo cp zhonjin_http.conf /etc/nginx/conf.d/zhonjin_http.conf
sudo cp zhonjin_stream.conf /etc/nginx/stream.d/zhonjin_stream.conf
sudo nginx -t && sudo systemctl reload nginx
sudo ufw allow 40130/tcp 40715/tcp 40716/tcp 40719/tcp
echo "=== 部署完成,请配置 SSL 证书 ==="