https://github.com/kaltura/nginx-vod-module + https://github.com/kaltura/nginx-secure-token-module
361
ENV ERROR_LOG=logs/error.log
ENV ACCESS_LOG=off
ENV IP_HEADER=
ENV REAL_IP_FROM=
ENV ROOT_PATH=/data
ENV LISTEN_PORT=80
ENV LOCATION_PATH=/
ENV ALLOW_ORIGIN=*
ENV SSL_KEY_PATH=
ENV SSL_CERT_PATH=
ENV TOKEN_URI_IV=
ENV TOKEN_URI_KEY=
ENV AIO=off
ENV SENDFILE=on
ENV DIRECTIO=512
ENV VOD_MODE=local
ENV VOD_CACHE=off
ENV VOD_BASE_URL=
ENV VOD_SECRET_KEY=
ENV VOD_SEGMENT_DURATION=10000
ENV VOD_METADATA_CACHE=512m
ENV VOD_RESPONSE_CACHE=128m
ENV VOD_MAPPING_CACHE=5m
ENV VOD_UPSTREAM_LOCATION=/json
ENV VOD_UPSTREAM_LOCATION_PATH="/json(.*)"
ENV VOD_UPSTREAM_PROXY_PASS="http://localhost/api/playlist/?path=\$1&response=json"
ENV VOD_REMOTE_UPSTREAM_LOCATION=/proxy
ENV VOD_REMOTE_UPSTREAM_LOCATION_PATH="/proxy(.+?):\\/\\/(.+?)\\/(.+)"
ENV VOD_REMOTE_UPSTREAM_PROXY_PASS=\$1://\$2/\$3
ENV VOD_HLS_ENCRYPTION_METHOD="aes-128"
ENV OPEN_FILE_CACHE="max=1000 inactive=5m"
ENV OPEN_FILE_CACHE_VALID=2m
ENV OPEN_FILE_CACHE_MIN_USES=1
ENV OPEN_FILE_CACHE_ERRORS=on
#user nobody;
worker_processes auto;
error_log {{ default(ERROR_LOG, "logs/error.log") }};
#error_log logs/error.log notice;
#error_log logs/error.log info;
#pid logs/nginx.pid;
events {
worker_connections 1024;
}
http {
#log_format main '$remote_addr - $remote_user [$time_local] "$request" '
# '$status $body_bytes_sent "$http_referer" '
# '"$http_user_agent" "$http_x_forwarded_for"';
access_log {{ default(ACCESS_LOG, "off") }};
sendfile {{ default(SENDFILE, "on") }};
tcp_nopush on;
directio {{ default(DIRECTIO, "512") }};
default_type application/octet-stream;
#keepalive_timeout 65;
{% if length(default(REAL_IP_FROM, "")) > 0 %}
set_real_ip_from {{ REAL_IP_FROM }};
real_ip_header {{ default(IP_HEADER, "X-Real-IP") }};
{% endif %}
server {
{% if length(default(SSL_KEY_PATH, "")) > 0 %}
listen 443;
ssl_certificate {{ SSL_CERT_PATH }};
ssl_certificate_key {{ SSL_KEY_PATH }};
{% else %}
listen {{ default(LISTEN_PORT, 80) }};
{% endif %}
root {{ default(ROOT_PATH, "/data") }};
vod_mode {{ default(VOD_MODE, "local") }};
vod_segment_duration {{ default(VOD_SEGMENT_DURATION, "10000") }};
#gzip on;
#gzip_types application/vnd.apple.mpegurl;
{% if default(VOD_CACHE, "off") == "on" %}
vod_metadata_cache metadata_cache {{ default(VOD_METADATA_CACHE, "512m") }};
vod_response_cache response_cache {{ default(VOD_RESPONSE_CACHE, "128m") }};
vod_mapping_cache mapping_cache {{ default(VOD_MAPPING_CACHE, "5m") }};
open_file_cache {{ default(OPEN_FILE_CACHE, "max=1000 inactive=5m") }};
open_file_cache_valid {{ default(OPEN_FILE_CACHE_VALID, "2m") }};
open_file_cache_min_uses {{ default(OPEN_FILE_CACHE_MIN_USES, "1") }};
open_file_cache_errors {{ default(OPEN_FILE_CACHE_ERRORS, "on") }};
aio {{ default(AIO, "off") }};
{% endif %}
{% if default(VOD_MODE, "local") == "mapped" %}
vod_upstream_location {{ default(VOD_UPSTREAM_LOCATION, "/json") }};
vod_remote_upstream_location {{ default(VOD_REMOTE_UPSTREAM_LOCATION, "/proxy") }};
vod_upstream_extra_args {{ default(VOD_UPSTREAM_EXTRA_ARGS, "pathOnly=1") }};
vod_max_mapping_response_size {{ default(VOD_MAX_MAPPING_RESPONSE_SIZE, "128k") }};
location ~ {{ default(VOD_UPSTREAM_LOCATION_PATH, "/json(.*)") }} {
internal;
proxy_pass {{ VOD_UPSTREAM_PROXY_PASS }};
resolver {{ default(VOD_UPSTREAM_RESOLVER, "8.8.8.8") }};
}
location ~ {{ default(VOD_REMOTE_UPSTREAM_LOCATION_PATH, "/proxy(.+?):\\/\\/(.+?)\\/(.+)") }} {
internal;
proxy_pass {{ default(VOD_REMOTE_UPSTREAM_PROXY_PASS, "$1://$2/$3") }};
resolver {{ default(VOD_UPSTREAM_RESOLVER, "8.8.8.8") }};
}
{% endif %}
location {{ default(LOCATION_PATH, "/") }} {
vod hls;
{% if length(default(VOD_SECRET_KEY, "")) > 0 %}
vod_secret_key "{{ VOD_SECRET_KEY }}";
vod_hls_encryption_method {{ default(VOD_HLS_ENCRYPTION_METHOD, "aes-128") }};
{% endif %}
{% if length(default(VOD_BASE_URL, "")) > 0 %}
vod_base_url "{{ VOD_BASE_URL }}";
vod_segments_base_url "{{ VOD_BASE_URL }}";
vod_hls_absolute_master_urls off;
vod_hls_absolute_iframe_urls off;
{% endif %}
{% if length(default(TOKEN_URI_KEY, "")) > 0 %}
secure_token_encrypt_uri on;
secure_token_encrypt_uri_key {{ TOKEN_URI_KEY }};
secure_token_encrypt_uri_iv {{ TOKEN_URI_IV }};
secure_token_encrypt_uri_part $request_uri;
secure_token_encrypt_uri_hash_size 0;
secure_token_types application/vnd.apple.mpegurl;
{% endif %}
# add_header Cache-Control no-cache;
add_header X-Frame-Options "SAMEORIGIN";
add_header Access-Control-Allow-Headers '*';
add_header Access-Control-Expose-Headers 'Server,range,Content-Length,Content-Range';
add_header Access-Control-Allow-Methods 'GET, HEAD, OPTIONS';
{% if length(default(ALLOW_ORIGIN, "*")) > 4 %}
if ($http_origin ~* "{{ ALLOW_ORIGIN }}") {
add_header Access-Control-Allow-Origin "$http_origin";
}
{% else %}
add_header Access-Control-Allow-Origin "*";
{% endif %}
if ($request_method = 'OPTIONS') {
add_header 'Content-Type' 'text/plain charset=UTF-8';
add_header 'Content-Length' 0;
return 204;
}
types {
application/vnd.apple.mpegurl m3u8;
video/mp2t ts;
}
}
}
}
Content type
Image
Digest
sha256:e06da9552…
Size
12 MB
Last updated
almost 3 years ago
docker pull eskater/nginx-vod