本文主要介绍nginx的负载均衡、nginx网页重定向以及nginx网页web用户认证:负载均衡(load balance)就是将负载分摊到多个服务器上执行,从而提高服务的可用性和响应速度,通过模块upstream和四种调度算法来介绍nginx的负载均衡;实现nginx网页重定向,如 xuptip.qq.com --> www.xuptip.qq.com;实现nginx网页web用户认证控制,指定用户输入密码才可访问该网页,从而加固了网页私密性。
upstream 模块负债负载均衡模块,通过一个简单的调度算法来实现客户端IP到后端服务器的负载均衡。
测试负载均衡,两台服务器部署Nginx
server1 172.25.20.11 主
server2 172.25.20.12 页面: www.server2.com
server3 172.25.20.13 页面: www.server3.com
[root@server1 ~]# cat /usr/local/lnmp/nginx/conf/nginx.conf
#user nobody;
worker_processes 1;
#error_log logs/error.log;
#error_log logs/error.log notice;
#error_log logs/error.log info;
#pid logs/nginx.pid;
events {
worker_connections 1024;
}
http {
upstream sunnyhttp{
server 172.25.20.12;
server 172.25.20.13;
}
include mime.types;
default_type application/octet-stream;
sendfile on;
#tcp_nopush on;
#keepalive_timeout 0;
keepalive_timeout 65;
#gzip on;
server {
listen 80;
server_name www.xuptip.qq.com;
location / {
root html;
index index.html index.htm;
proxy_pass http://sunnyhttp;
}
}
}
例子中,通过upstream指令指定了一个负载均衡器的名称sunnyhttp。这个名称可以任意指定,在后面需要的地方直接调用即可。
[root@server1 ~]# /usr/local/lnmp/nginx/sbin/nginx -t
nginx: the configuration file /usr/local/lnmp/nginx/conf/nginx.conf syntax is ok
nginx: configuration file /usr/local/lnmp/nginx/conf/nginx.conf test is successful
[root@server1 ~]# /usr/local/lnmp/nginx/sbin/nginx -s reload
[root@server1 ~]# cat /etc/hosts
127.0.0.1 localhost localhost.localdomain localhost4 localhost4.localdomain4
::1 localhost localhost.localdomain localhost6 localhost6.localdomain6
172.25.20.11 www.xuptip.qq.com
利用调度算法:weight
upstream sunnyhttp{
server 172.25.20.12 weight=2;
server 172.25.20.13 weight=1;
}
[root@server1 ~]# /usr/local/lnmp/nginx/sbin/nginx -s reload
upstream sunnyhttp{
ip_hash;
server 172.25.20.12;
server 172.25.20.13;
}
[root@server1 ~]# /usr/local/lnmp/nginx/sbin/nginx -s reload
Nginx的负载均衡模块目前支持4种调度算法:
在HTTP Upstream模块中,可以通过server指令指定后端服务器的IP地址和端口,同时还可以设定每个后端服务器在负载均衡调度中的状态。常用的状态有:
注意 当负载调度算法为ip_hash时,后端服务器在负载均衡调度中的状态不能是weight和backup。
[root@server1 ~]# cat /usr/local/lnmp/nginx/conf/nginx.conf
#user nobody;
worker_processes 1;
#error_log logs/error.log;
#error_log logs/error.log notice;
#error_log logs/error.log info;
#pid logs/nginx.pid;
events {
worker_connections 1024;
}
http {
include mime.types;
default_type application/octet-stream;
#access_log logs/access.log main;
sendfile on;
#tcp_nopush on;
#keepalive_timeout 0;
keepalive_timeout 65;
#gzip on;
server {
listen 80;
server_name xuptip.qq.com;
root /data/bbs;
}
# another virtual host using mix of IP-, name-, and port-based configuration
server {
listen 80;
server_name www.xuptip.qq.com;
root /data/www;
}
}
[root@server1 ~]# cat /data/bbs/index.html
xuptip.qq.com
[root@server1 ~]# cat /data/www/index.html
www.xuptip.qq.com
##添加域名解析
[root@server1 ~]# cat /etc/hosts
127.0.0.1 localhost localhost.localdomain localhost4 localhost4.localdomain4
::1 localhost localhost.localdomain localhost6 localhost6.localdomain6
172.25.20.11 www.xuptip.qq.com xuptip.qq.com
[root@server1 ~]# /usr/local/lnmp/nginx/sbin/nginx -s reload
添加重定向配置
server {
listen 80;
server_name xuptip.qq.com;
# root /data/bbs;
rewrite ^(.*) http://www.xuptip.qq.com;
}
# another virtual host using mix of IP-
server {
listen 80;
server_name www.xuptip.qq.com;
root /data/www;
}
[root@server1 ~]# /usr/local/lnmp/nginx/sbin/nginx -s reload
##curl测试,可以看到状态码是302重定向
[root@server1 ~]# curl xuptip.qq.com
302 Found
302 Found
nginx/1.10.1
浏览器输入 xuptip.qq.com 直接转到 www.xuptip.qq.com
同理,可以令域名 xuptip.qq.com和www.xuptip.qq.com都自动跳转至https://www.xuptip.qq.com
[root@server1 ~]# cat /usr/local/lnmp/nginx/conf/nginx.conf
#user nobody;
worker_processes 1;
#error_log logs/error.log;
#error_log logs/error.log notice;
#error_log logs/error.log info;
#pid logs/nginx.pid;
events {
worker_connections 1024;
}
http {
include mime.types;
default_type application/octet-stream;
#access_log logs/access.log main;
sendfile on;
#tcp_nopush on;
#keepalive_timeout 0;
keepalive_timeout 65;
#gzip on;
server {
listen 80;
server_name xuptip.qq.com www.xuptip.qq.com;
# root /data/bbs;
rewrite ^(.*) https://www.xuptip.qq.com;
}
# HTTPS server
server {
listen 443 ssl;
server_name www.xuptip.qq.com;
ssl_certificate cert.pem;
ssl_certificate_key cert.pem;
ssl_session_cache shared:SSL:1m;
ssl_session_timeout 5m;
ssl_ciphers HIGH:!aNULL:!MD5;
ssl_prefer_server_ciphers on;
root /data/www;
}
}
[root@server1 ~]# /usr/local/lnmp/nginx/sbin/nginx -s reload
[root@server1 ~]# curl www.xuptip.qq.com
302 Found
302 Found
nginx/1.10.1
[root@server1 ~]# yum install -y httpd-tools
[root@server1 ~]# htpasswd -b -c /usr/local/webdev/nginx/conf/htpasswd admin test@007
## -b 命令行输入用户与密码
## -c 创建文件,注意:首次使用则创建,第二次使用即为覆盖
##追加用户和密码
[root@server1 ~]# htpasswd -b /usr/local/lnmp/nginx/conf/htpasswd xixi 123
##删除用户和密码
[root@server1 ~]# htpasswd -D /usr/local/lnmp/nginx/conf/htpasswd xixi
##配置文件
[root@server1 ~]# cat /usr/local/lnmp/nginx/conf/nginx.conf
#user nobody;
worker_processes 1;
#error_log logs/error.log;
#error_log logs/error.log notice;
#error_log logs/error.log info;
#pid logs/nginx.pid;
events {
worker_connections 1024;
}
http {
include mime.types;
default_type application/octet-stream;
sendfile on;
#tcp_nopush on;
keepalive_timeout 65;
#gzip on;
server {
listen 80;
server_name xuptip.qq.com www.xuptip.qq.com;
#root /data/bbs;
rewrite ^(.*) https://www.xuptip.qq.com;
auth_basic "Please input your name and password";
auth_basic_user_file /usr/local/lnmp/nginx/conf/htpasswd;
}
# HTTPS server
server {
listen 443 ssl;
server_name www.xuptip.qq.com;
ssl_certificate cert.pem;
ssl_certificate_key cert.pem;
ssl_session_cache shared:SSL:1m;
ssl_session_timeout 5m;
ssl_ciphers HIGH:!aNULL:!MD5;
ssl_prefer_server_ciphers on;
root /data/www;
}
}
[root@server1 ~]# /usr/local/lnmp/nginx/sbin/nginx -s reload