流水线部署(废弃)
upstream backend {
server 127.0.0.1:9991;
}
server {
listen 80;
server_name your.domain;
rewrite ^(.*) https://$server_name$1 permanent;
}
# https 配置,没有则将后续配置剪切到上面的80服务里
server {
listen 443 ssl;
server_name your.domain;
charset utf-8;
access_log /var/log/nginx/app.fb.todomvc.access.log;
error_log /var/log/nginx/app.fb.todomvc.error.log;
# https://github.com/darktable/html5-boilerplate-server-configs/blob/master/nginx.conf
# Enable Gzip
gzip on;
gzip_http_version 1.0;
gzip_comp_level 2;
gzip_min_length 1100;
gzip_buffers 4 8k;
gzip_proxied any;
gzip_types
# text/html is always compressed by HttpGzipModule
text/css
text/javascript
text/xml
text/plain
text/x-component
application/javascript
application/json
application/xml
application/rss+xml
font/truetype
font/opentype
application/vnd.ms-fontobject
image/svg+xml;
gzip_static on;
gzip_proxied expired no-cache no-store private auth;
gzip_disable "MSIE [1-6]\.";
gzip_vary on;
# 根据实际情况修改
ssl_certificate /etc/nginx/cert/1_app.fb.todomvc.crt;
ssl_certificate_key /etc/nginx/cert/2_app.fb.todomvc.key;
ssl_session_timeout 5m;
ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
ssl_ciphers ECDHE-RSA-AES128-GCM-SHA256:HIGH:!aNULL:!MD5:!RC4:!DHE;
ssl_prefer_server_ciphers on;
location / {
root /path/to/deploy/web;
index index.html;
try_files $uri $uri/ /index.html;
}
location /operations {
proxy_pass http://backend/operations;
proxy_set_header X-Real_IP $remote_addr;
proxy_set_header Host $host;
proxy_set_header X_Forward_For $proxy_add_x_forwarded_for;
client_max_body_size 0;
}
location /auth {
proxy_pass http://backend/auth;
proxy_set_header X-Real_IP $remote_addr;
proxy_set_header Host $host;
proxy_set_header X_Forward_For $proxy_add_x_forwarded_for;
client_max_body_size 0;
}
}
最后更新于