Sign inSign up

bingsin/nginx_tcp

By bingsin

•Updated almost 6 years ago

这是自己做的一个nginx-tcp转发镜像

Image
0

93

bingsin/nginx_tcp repository overview

⁠关于此镜像

只是想简单的使用nginx,通过主机名进行tcp转发。就是为了创造cloudflare加速节点

⁠镜像环境
  • nginx:1.19.3
  • ubuntu: 18.04
  • user: www-data
  • 主目录为 /etc/nginx
  • 日志为 /var/logs/nginx
⁠目录结构
/etc/nginx/
├── fastcgi.conf
├── fastcgi_params
├── html
│   ├── 50x.html
│   └── index.html
├── koi-utf
├── koi-win
├── mime.types
├── modules
│   └── ngx_stream_module.so
├── nginx.conf
├── sbin
│   └── nginx
├── scgi_params
├── temp
│   ├── client_temp
│   ├── fastcgi_temp
│   ├── proxy_temp
│   ├── scgi_temp
│   └── uwsgi_temp
├── uwsgi_params
└── win-ut
⁠nginx.conf配置文件
load_module /etc/nginx/modules/ngx_stream_module.so;
worker_processes  1;
events {
    worker_connections  1024;
}
stream {
    include /etc/nginx/stream/*.conf;
}
http {
    include       mime.types;
    default_type  application/octet-stream;
    sendfile        on;
    tcp_nopush     on;
    keepalive_timeout  65;
    gzip  on;
    include /etc/nginx/conf/*.conf;

}
⁠./configure
./configure                \
    --prefix=/etc/nginx \
    --sbin-path=/etc/nginx/sbin/nginx \
    --modules-path=/etc/nginx/modules \
    --conf-path=/etc/nginx/nginx.conf \
    --error-log-path=/var/log/nginx/error.log \
    --http-log-path=/var/log/nginx/access.log \
    --pid-path=/var/run/nginx.pid \
    --lock-path=/var/run/nginx.lock \
    --http-client-body-temp-path=/etc/nginx/temp/client_temp \
    --http-proxy-temp-path=/etc/nginx/temp/proxy_temp \
    --http-fastcgi-temp-path=/etc/nginx/temp/fastcgi_temp \
    --http-uwsgi-temp-path=/etc/nginx/temp/uwsgi_temp \
    --http-scgi-temp-path=/etc/nginx/temp/scgi_temp \
    --user=www-data \
    --group=www-data  \
    --with-compat \
    --with-file-aio \
    --with-threads \
    --with-http_addition_module \
    --with-http_auth_request_module \
    --with-http_dav_module \
    --with-http_flv_module \
    --with-http_gunzip_module \
    --with-http_gzip_static_module \
    --with-http_mp4_module \
    --with-http_random_index_module \
    --with-http_realip_module \
    --with-http_secure_link_module \
    --with-http_slice_module \
    --with-http_ssl_module \
    --with-http_stub_status_module \
    --with-http_sub_module \
    --with-http_v2_module \
    --with-mail \
    --with-mail_ssl_module \
    --with-stream  --with-stream=dynamic  --with-stream_realip_module   \
    --with-stream_ssl_module \
   --with-stream_ssl_preread_module \
    --with-cpp_test_module \
    --add-module=/opt/openssl-1.1.1h \
    --with-openssl=/opt/openssl-1.1.1h 

⁠用法

⁠1、简单的作为web服务器

在主机上新建一个目录,作为存放nginx的配置文件,新建一个web目录,作为存放网页文件

mkdir /www/conf /www/wwwroot
touch /www/conf/vhost.conf
docker run -idt -p 80:80 -p 443:443 -v /www/wwwroot:/www/wwwroot --name=nginx --restart=always bingsin/nginx_tcp:1.19.3
docker exec -it nginx chown -R www-data:www-data /www/wwwroot
⁠2、转发TCP\UDP

在主机上新建一个目录,作为存放stream配置的位置。

mkdir /www/stream 
touch /www/stream/rules.conf
docker run -idt -p 80:80 -p 443:443 -v /www/stream:/etc/nginx/stream --name=nginx-tcp --restart=always bingsin/nginx_tcp:1.19.3
⁠conf一般配置写法如下
    #转发数据库端口
    upstream mysql {
      server 10.13.14.254:3306;
    }
    server {
      listen 2321;
      proxy_pass mysql;
    }
    # 转发SSH端口  
    upstream mysql {
       server 10.13.14.254:3306;
    }
    server {
      listen 2321;
      proxy_pass mysql;
    }
⁠转发UDP
 upstream dns {
               server 10.13.14.254:53;
       }
       server {
               listen 53 udp;
               proxy_pass dnsl;
       }
⁠根据域名进行转发
#先定义map
map $ssl_preread_server_name $name {
        node1.baidu.com node1;
        node2.baidu.com node2;
        default node3;
    }
    #设定stream
    upstream node1 {
        #目标服务器地址
        server 1.0.0.1:443;
    }

    upstream node2 {
        #这里可以填入域名,但是会存在域名动态解析导致ip变了,nginx无法正确代理的问题,静态ip不存在。
        server node2.baidu.com:443; 
    }

    upstream node3 {
        server 9.9.9.9:443;
    }
    #配置转发
    server {
        listen [::]:443;
        listen 443;
        proxy_pass $name;
        ssl_preread on;
    }

此时nginx就会监听443端口,并且根据请求的主机名,进行转发

  • 请求域名 >>> 最后转发的域名
  • node1.baidu.com >>> node1.baidu.com
  • node2.baidu.com >>> node2.baidu.com
  • 其他任何域名访 >>>9.9.9.9:443

Tag summary

Content type

Image

Digest

Size

30.5 MB

Last updated

almost 6 years ago

docker pull bingsin/nginx_tcp:1.19.3