Kyle's Notebook

Nginx Cheat Sheet

Word count: 369Reading time: 2 min
2020/02/16

Nginx 是一种开源工具,用于 Web 服务、反向代理、缓存、负载平衡、媒体流等,本文将提到一些经常使用的 Nginx 配置。

Nginx Cheat Sheet

监听端口

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
server {
# Standard HTTP Protocol
listen 80;

# Standard HTTPS Protocol
listen 443 ssl;

# For http2
listen 443 ssl http2;

# Listen on 80 using IPv6
listen [::]:80;

# Listen only on using IPv6
listen [::]:80 ipv6only=on;
}

访问日志

1
2
3
4
5
6
7
8
server {
# Relative or full path to log file
access_log /path/to/file.log;

# Turn 'on' or 'off'
access_log on;
}

域名

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
server {
# Listen to yourdomain.com
server_name yourdomain.com;

# Listen to multiple domains
server_name yourdomain.com www.yourdomain.com;

# Listen to all domains
server_name *.yourdomain.com;

# Listen to all top-level domains
server_name yourdomain.*;

# Listen to unspecified Hostnames (Listens to IP address itself)
server_name "";

}

静态资源

1
2
3
4
5
6
7
8
server {
listen 80;
server_name yourdomain.com;

location / {
root /path/to/website;
}
}

重定向

1
2
3
4
5
server {
listen 80;
server_name www.yourdomain.com;
return 301 http://yourdomain.com$request_uri;
}
1
2
3
4
5
6
7
8
server {
listen 80;
server_name www.yourdomain.com;

location /redirect-url {
return 301 http://otherdomain.com;
}
}

反向代理

1
2
3
4
5
6
7
8
9
10
server {
listen 80;
server_name yourdomain.com;

location / {
proxy_pass http://0.0.0.0:3000;
# where 0.0.0.0:3000 is your application server (Ex: node.js) bound on 0.0.0.0 listening on port 3000
}

}

负载均衡

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
upstream node_js {
server 0.0.0.0:3000;
server 0.0.0.0:4000;
server 123.131.121.122;
}

server {
listen 80;
server_name yourdomain.com;

location / {
proxy_pass http://node_js;
}
}

HTTPS

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
server {
listen 443 ssl;
server_name yourdomain.com;

ssl on;

ssl_certificate /path/to/cert.pem;
ssl_certificate_key /path/to/privatekey.pem;

ssl_stapling on;
ssl_stapling_verify on;
ssl_trusted_certificate /path/to/fullchain.pem;

ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
ssl_session_timeout 1h;
ssl_session_cache shared:SSL:50m;
add_header Strict-Transport-Security max-age=15768000;
}

# Permanent Redirect for HTTP to HTTPS
server {
listen 80;
server_name yourdomain.com;
return 301 https://$host$request_uri;
}
CATALOG
  1. 1. Nginx Cheat Sheet
    1. 1.1. 监听端口
    2. 1.2. 访问日志
    3. 1.3. 域名
    4. 1.4. 静态资源
    5. 1.5. 重定向
    6. 1.6. 反向代理
    7. 1.7. 负载均衡
    8. 1.8. HTTPS