nginx技术使用

写于 2025-09-24

nginx技术使用

  • 因为在同一个服务器部署了多个网站,而多个网站是通过不同的技术来开发,为了避免相互间的冲突,则采用nginx技术来实现代理转发
  • 配置文件放置在/etc/nginx/sites-enabled目录下,内容如下
server {
    listen 80;
    server_name www.liufeisheng.cn;

    location / {
        proxy_pass http://127.0.0.1:82;
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;
    }

    location /crm {
        proxy_pass http://127.0.0.1:83;
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;
    }

    location /messages {
        proxy_pass http://127.0.0.1:8082;
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;
    }
}


server {
    listen 80;
    server_name blog.liufeisheng.cn;

    location /blog {
        proxy_pass http://127.0.0.1:81;
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;
    }
}

server {
            listen 84;
            server_name dh.liufeisheng.cn;

            root /usr/local/digitalhum;
            index index.html;


            location / {
                    try_files $uri $uri/ =404;
            }
    }

server {
            listen 80;
            server_name dh.liufeisheng.cn;

            location / {
                    proxy_pass http://127.0.0.1:84;
                    proxy_set_header Host $host;
                    proxy_set_header X-Real-IP $remote_addr;
                    proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
                    proxy_set_header X-Forwarded-Proto $scheme;
                        }
        }

server {
    listen 80;
    server_name jp.liufeisheng.cn;

    location / {
        proxy_pass http://127.0.0.1:8888;
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;
    }
}



server {
    listen 80;
    server_name nas.liufeisheng.cn;

    location / {
        proxy_pass http://127.0.0.1:8080;
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;
    }
}


server{
    listen 80;
    server_name jxcg.liufeisheng.cn;

    root /usr/local/www/jxcg;
    index index.html;

    location / {
        try_files $uri $uri/ = 404;
    }
}
  • 从上面可以知道,目前已经代理了多个网站,具体如下:
  • 80端口,监控所有网站内容
    • 81端口,blog网站,blog.liufeisheng.cn
    • 82端口,主网站,www.liufeisheng.cn
    • 83端口,crm网站,crm.liufeisheng.cn 。博士论文
  • 8082端口,messages网站,spring boot教学过程中的演示内容
  • 84端口,dh数字人文化网站,dh.liufeisheng.cn; 科研内容
  • jxcg.liufeisheng.cn,没有采用端口,直接用子域名转移

Caddy技术使用

  • 获取证书,将http访问转化为https使用,增强安全性及可访问性
  • 配置文件位置/etc/caddy/Caddyfile,配置内容如下
{
  http_port 8081
  https_port 443
}

# 主域名配置
liufeisheng.cn, www.liufeisheng.cn {
    reverse_proxy 127.0.0.1:82
}

# 子域名配置 - Blog
blog.liufeisheng.cn {
    reverse_proxy 127.0.0.1:81
}

# 子域名配置 - CRM
crm.liufeisheng.cn {
    reverse_proxy 127.0.0.1:83
}

# 子域名配置 - DH
dh.liufeisheng.cn {
    reverse_proxy 127.0.0.1:84
}


# 子域名配置 - jxcg
jxcg.liufeisheng.cn {
    root * /usr/local/www/jxcg
    file_server
    file_server browse
}

# 自动将 HTTP 流量重定向到 HTTPS
http://www.liufeisheng.cn {
    redir https://www.liufeisheng.cn{uri}
}

http://blog.liufeisheng.cn {
    redir https://blog.liufeisheng.cn{uri}
}

http://crm.liufeisheng.cn {
    redir https://crm.liufeisheng.cn{uri}
}

http://dh.liufeisheng.cn {
    redir https://dh.liufeisheng.cn{uri}
}

http://jxcg.liufeisheng.cn {
    redir https://jxcg.liufeisheng.cn{uri}
}

http://nas.liufeisheng.cn {
    redir https://nas.liufeisheng.cn{uri}
}

优化建议

为避免重复和冲突,建议选择 Nginx 或 Caddy 作为主要代理服务器,统一配置。以下是两种方案的建议:(

方案 1:仅使用 Caddy(推荐,简化 HTTPS 管理)

Caddy 自动管理 SSL 证书,支持 HTTPS,且配置更简洁。可以通过扩展 Caddy 配置覆盖 Nginx 的所有功能。

修改后的 Caddy 配置:

{
  http_port 8081
  https_port 443
}

# 主域名和子域名配置
www.liufeisheng.cn {
    reverse_proxy / 127.0.0.1:82
    reverse_proxy /crm 127.0.0.1:83
    reverse_proxy /messages 127.0.0.1:8082
}

blog.liufeisheng.cn {
    reverse_proxy 127.0.0.1:81
}

jp.liufeisheng.cn {
    reverse_proxy 127.0.0.1:8888
}

nas.liufeisheng.cn {
    reverse_proxy 127.0.0.1:8080
}

dh.liufeisheng.cn {
    root * /usr/local/digitalhum
    file_server
}

jxcg.liufeisheng.cn {
    root * /usr/local/www/jxcg
    file_server
    file_server browse
}

# HTTP 到 HTTPS 重定向
http://*.liufeisheng.cn {
    redir https://{host}{uri}
}

改动说明:

  • 合并 liufeisheng.cn 和 www.liufeisheng.cn,在 www.liufeisheng.cn 下使用路径 /crm 和 /messages 代理,匹配 Nginx 功能。
  • 添加 jp.liufeisheng.cn 和 nas.liufeisheng.cn 的代理,覆盖 Nginx 缺失的功能。
  • dh.liufeisheng.cn 改为直接服务静态文件(匹配 Nginx 的 84 端口逻辑,假设这是主要需求)。
  • 使用通配符 http://*.liufeisheng.cn 简化 HTTP 重定向,减少重复配置。
  • 优点:
  • 自动 HTTPS,简化证书管理。
  • 配置简洁,覆盖所有 Nginx 功能。
  • 统一端口(8081 和 443),避免冲突。
  • 注意:
  • 确保后端服务(如 127.0.0.1:81、127.0.0.1:82 等)接受 HTTPS 流量。
  • 若 dh.liufeisheng.cn 需要代理到 84 端口,可改为 reverse_proxy 127.0.0.1:84。

方案 2:仅使用 Nginx(添加 HTTPS 支持)

如果更倾向于使用 Nginx,可以添加 SSL 支持并移除 Caddy。以下是优化后的 Nginx 配置,合并所有子域名并启用 HTTPS。

修改后的 Nginx 配置:

nginx

# 定义 upstream 块
upstream main_site { server 127.0.0.1:82; }
upstream crm_site { server 127.0.0.1:83; }
upstream messages_site { server 127.0.0.1:8082; }
upstream blog_site { server 127.0.0.1:81; }
upstream jp_site { server 127.0.0.1:8888; }
upstream nas_site { server 127.0.0.1:8080; }

# 统一 server 块
server {
    listen 80;
    listen 443 ssl;
    server_name www.liufeisheng.cn blog.liufeisheng.cn jp.liufeisheng.cn nas.liufeisheng.cn dh.liufeisheng.cn jxcg.liufeisheng.cn;

    # SSL 配置(需使用 Let’s Encrypt 或其他证书)
    ssl_certificate /etc/letsencrypt/live/liufeisheng.cn/fullchain.pem;
    ssl_certificate_key /etc/letsencrypt/live/liufeisheng.cn/privkey.pem;

    # HTTP 重定向到 HTTPS
    if ($scheme = http) {
        return 301 https://$host$request_uri;
    }

    # 公共代理头
    proxy_set_header Host $host;
    proxy_set_header X-Real-IP $remote_addr;
    proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
    proxy_set_header X-Forwarded-Proto $scheme;

    # 主网站
    location / {
        proxy_pass http://main_site;
    }

    # CRM
    location /crm {
        proxy_pass http://crm_site;
    }

    # Messages
    location /messages {
        proxy_pass http://messages_site;
    }

    # Blog
    location ~* ^/blog($|/) {
        proxy_pass http://blog_site;
    }

    # JP
    location ~* ^/jp($|/) {
        proxy_pass http://jp_site;
    }

    # NAS
    location ~* ^/nas($|/) {
        proxy_pass http://nas_site;
    }

    # DH(静态文件)
    location ~* ^/dh($|/) {
        root /usr/local/digitalhum;
        try_files $uri $uri/ =404;
    }

    # JXCG(静态文件)
    location ~* ^/jxcg($|/) {
        root /usr/local/www/jxcg;
        try_files $uri $uri/ =404;
    }
}

改动说明:

  • 合并所有子域名到单一 server 块,监听 80 和 443 端口。
  • 添加 SSL 配置(需通过 Let’s Encrypt 获取证书)。
  • 添加 HTTP 到 HTTPS 重定向,匹配 Caddy 功能。
  • 使用 upstream 和 location 块覆盖所有代理和静态文件服务。
  • 优点:
  • 保留 Nginx 的灵活性,覆盖 Caddy 的所有功能。
  • 统一配置,减少维护成本。
  • 注意:
  • 需要手动配置 SSL 证书(例如,使用 certbot)。
  • 确保后端服务支持 HTTPS 流量。

  • 代理功能是否相同:

  • Nginx 和 Caddy 的代理功能部分重叠,但不完全相同。Nginx 支持更多子域名(jp.liufeisheng.cn、nas.liufeisheng.cn)和路径(/messages),Caddy 提供 HTTPS 和 HTTP 重定向,但缺少部分代理配置。

  • 目前服务器中采用方案1,停用nginx服务; 但是发现nas.liufeisheng.cn无法使用

  • 因此nginx仅保留了nas.liufeisheng.cn,其他都通过caddy代理
  • 发现还是不行,如何仅保存caddy方案,则http://jxcg.liufeisheng.cn无法访问,而只能访问https的链接