nginx技术使用
nginx技术使用
- 因为在同一个服务器部署了多个网站,而多个网站是通过不同的技术来开发,为了避免相互间的冲突,则采用nginx技术来实现代理转发
- 配置文件放置在/etc/nginx/sites-enabled目录下,内容如下
server {
listen 80;
server_name www.liufeisheng.cn;
location / {
proxy_pass http://127.0.0.1:82;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
}
location /crm {
proxy_pass http://127.0.0.1:83;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
}
location /messages {
proxy_pass http://127.0.0.1:8082;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
}
}
server {
listen 80;
server_name blog.liufeisheng.cn;
location /blog {
proxy_pass http://127.0.0.1:81;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
}
}
server {
listen 84;
server_name dh.liufeisheng.cn;
root /usr/local/digitalhum;
index index.html;
location / {
try_files $uri $uri/ =404;
}
}
server {
listen 80;
server_name dh.liufeisheng.cn;
location / {
proxy_pass http://127.0.0.1:84;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
}
}
server {
listen 80;
server_name jp.liufeisheng.cn;
location / {
proxy_pass http://127.0.0.1:8888;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
}
}
server {
listen 80;
server_name nas.liufeisheng.cn;
location / {
proxy_pass http://127.0.0.1:8080;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
}
}
server{
listen 80;
server_name jxcg.liufeisheng.cn;
root /usr/local/www/jxcg;
index index.html;
location / {
try_files $uri $uri/ = 404;
}
}
- 从上面可以知道,目前已经代理了多个网站,具体如下:
- 80端口,监控所有网站内容
- 81端口,blog网站,blog.liufeisheng.cn
- 82端口,主网站,www.liufeisheng.cn
- 83端口,crm网站,crm.liufeisheng.cn 。博士论文
- 8082端口,messages网站,spring boot教学过程中的演示内容
- 84端口,dh数字人文化网站,dh.liufeisheng.cn; 科研内容
- jxcg.liufeisheng.cn,没有采用端口,直接用子域名转移
Caddy技术使用
- 获取证书,将http访问转化为https使用,增强安全性及可访问性
- 配置文件位置/etc/caddy/Caddyfile,配置内容如下
{
http_port 8081
https_port 443
}
# 主域名配置
liufeisheng.cn, www.liufeisheng.cn {
reverse_proxy 127.0.0.1:82
}
# 子域名配置 - Blog
blog.liufeisheng.cn {
reverse_proxy 127.0.0.1:81
}
# 子域名配置 - CRM
crm.liufeisheng.cn {
reverse_proxy 127.0.0.1:83
}
# 子域名配置 - DH
dh.liufeisheng.cn {
reverse_proxy 127.0.0.1:84
}
# 子域名配置 - jxcg
jxcg.liufeisheng.cn {
root * /usr/local/www/jxcg
file_server
file_server browse
}
# 自动将 HTTP 流量重定向到 HTTPS
http://www.liufeisheng.cn {
redir https://www.liufeisheng.cn{uri}
}
http://blog.liufeisheng.cn {
redir https://blog.liufeisheng.cn{uri}
}
http://crm.liufeisheng.cn {
redir https://crm.liufeisheng.cn{uri}
}
http://dh.liufeisheng.cn {
redir https://dh.liufeisheng.cn{uri}
}
http://jxcg.liufeisheng.cn {
redir https://jxcg.liufeisheng.cn{uri}
}
http://nas.liufeisheng.cn {
redir https://nas.liufeisheng.cn{uri}
}
优化建议
为避免重复和冲突,建议选择 Nginx 或 Caddy 作为主要代理服务器,统一配置。以下是两种方案的建议:(
方案 1:仅使用 Caddy(推荐,简化 HTTPS 管理)
Caddy 自动管理 SSL 证书,支持 HTTPS,且配置更简洁。可以通过扩展 Caddy 配置覆盖 Nginx 的所有功能。
修改后的 Caddy 配置:
{
http_port 8081
https_port 443
}
# 主域名和子域名配置
www.liufeisheng.cn {
reverse_proxy / 127.0.0.1:82
reverse_proxy /crm 127.0.0.1:83
reverse_proxy /messages 127.0.0.1:8082
}
blog.liufeisheng.cn {
reverse_proxy 127.0.0.1:81
}
jp.liufeisheng.cn {
reverse_proxy 127.0.0.1:8888
}
nas.liufeisheng.cn {
reverse_proxy 127.0.0.1:8080
}
dh.liufeisheng.cn {
root * /usr/local/digitalhum
file_server
}
jxcg.liufeisheng.cn {
root * /usr/local/www/jxcg
file_server
file_server browse
}
# HTTP 到 HTTPS 重定向
http://*.liufeisheng.cn {
redir https://{host}{uri}
}
改动说明:
- 合并 liufeisheng.cn 和 www.liufeisheng.cn,在 www.liufeisheng.cn 下使用路径 /crm 和 /messages 代理,匹配 Nginx 功能。
- 添加 jp.liufeisheng.cn 和 nas.liufeisheng.cn 的代理,覆盖 Nginx 缺失的功能。
- dh.liufeisheng.cn 改为直接服务静态文件(匹配 Nginx 的 84 端口逻辑,假设这是主要需求)。
- 使用通配符 http://*.liufeisheng.cn 简化 HTTP 重定向,减少重复配置。
- 优点:
- 自动 HTTPS,简化证书管理。
- 配置简洁,覆盖所有 Nginx 功能。
- 统一端口(8081 和 443),避免冲突。
- 注意:
- 确保后端服务(如 127.0.0.1:81、127.0.0.1:82 等)接受 HTTPS 流量。
- 若 dh.liufeisheng.cn 需要代理到 84 端口,可改为 reverse_proxy 127.0.0.1:84。
方案 2:仅使用 Nginx(添加 HTTPS 支持)
如果更倾向于使用 Nginx,可以添加 SSL 支持并移除 Caddy。以下是优化后的 Nginx 配置,合并所有子域名并启用 HTTPS。
修改后的 Nginx 配置:
nginx
# 定义 upstream 块
upstream main_site { server 127.0.0.1:82; }
upstream crm_site { server 127.0.0.1:83; }
upstream messages_site { server 127.0.0.1:8082; }
upstream blog_site { server 127.0.0.1:81; }
upstream jp_site { server 127.0.0.1:8888; }
upstream nas_site { server 127.0.0.1:8080; }
# 统一 server 块
server {
listen 80;
listen 443 ssl;
server_name www.liufeisheng.cn blog.liufeisheng.cn jp.liufeisheng.cn nas.liufeisheng.cn dh.liufeisheng.cn jxcg.liufeisheng.cn;
# SSL 配置(需使用 Let’s Encrypt 或其他证书)
ssl_certificate /etc/letsencrypt/live/liufeisheng.cn/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/liufeisheng.cn/privkey.pem;
# HTTP 重定向到 HTTPS
if ($scheme = http) {
return 301 https://$host$request_uri;
}
# 公共代理头
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
# 主网站
location / {
proxy_pass http://main_site;
}
# CRM
location /crm {
proxy_pass http://crm_site;
}
# Messages
location /messages {
proxy_pass http://messages_site;
}
# Blog
location ~* ^/blog($|/) {
proxy_pass http://blog_site;
}
# JP
location ~* ^/jp($|/) {
proxy_pass http://jp_site;
}
# NAS
location ~* ^/nas($|/) {
proxy_pass http://nas_site;
}
# DH(静态文件)
location ~* ^/dh($|/) {
root /usr/local/digitalhum;
try_files $uri $uri/ =404;
}
# JXCG(静态文件)
location ~* ^/jxcg($|/) {
root /usr/local/www/jxcg;
try_files $uri $uri/ =404;
}
}
改动说明:
- 合并所有子域名到单一 server 块,监听 80 和 443 端口。
- 添加 SSL 配置(需通过 Let’s Encrypt 获取证书)。
- 添加 HTTP 到 HTTPS 重定向,匹配 Caddy 功能。
- 使用 upstream 和 location 块覆盖所有代理和静态文件服务。
- 优点:
- 保留 Nginx 的灵活性,覆盖 Caddy 的所有功能。
- 统一配置,减少维护成本。
- 注意:
- 需要手动配置 SSL 证书(例如,使用 certbot)。
-
确保后端服务支持 HTTPS 流量。
-
代理功能是否相同:
-
Nginx 和 Caddy 的代理功能部分重叠,但不完全相同。Nginx 支持更多子域名(jp.liufeisheng.cn、nas.liufeisheng.cn)和路径(/messages),Caddy 提供 HTTPS 和 HTTP 重定向,但缺少部分代理配置。
-
目前服务器中采用方案1,停用nginx服务; 但是发现nas.liufeisheng.cn无法使用
- 因此nginx仅保留了nas.liufeisheng.cn,其他都通过caddy代理
- 发现还是不行,如何仅保存caddy方案,则http://jxcg.liufeisheng.cn无法访问,而只能访问https的链接