Sign inSign up

rusxakep/nginx

By rusxakep

•Updated about 6 years ago
Archived

Docker Full featured Nginx Image w/Zabbix agent monitoring, S6 init, logrotate based on Alpine

Image
0

10K+

rusxakep/nginx repository overview

⁠hub.docker.com/r/rusxakep/nginx

Build Status Docker Pulls Docker Stars Docker Layers

⁠Introduction

This will build a container for Nginx⁠

  • Tracks Mainline release channel
  • Many options configurable including compression, performance
  • Includes Zabbix Monitoring (nginx status) on port 73
  • Logrotate Included to roll over log files at 23:59, compress and retain for 7 days
  • Ability to Password Protect (Basic), LDAP Authenticate or use LemonLDAP:NG Handler

This Container uses rusxakep/alpine⁠ as a base.

Changelog⁠

⁠Authors

⁠Table of Contents

⁠Prerequisites

This image assumes that you are using a reverse proxy such as jwilder/nginx-proxy⁠ and optionally the Let's Encrypt Proxy Companion @ https://github.com/JrCs/docker-letsencrypt-nginx-proxy-companion⁠ in order to serve your pages. However, it will run just fine on it's own if you map appropriate ports.

⁠Installation

Automated builds of the image are available on Docker Hub⁠ and is the recommended method of installation.

docker pull rusxakep/nginx
⁠Quick Start

⁠Configuration

⁠Data-Volumes

The container starts up and reads from /etc/nginx/nginx.conf for some basic configuration and to listen on port 73 internally for Nginx Status responses. /etc/nginx/conf.d contains a sample configuration file that can be used to customize a nginx server block.

The following directories are used for configuration and can be mapped for persistent storage.

DirectoryDescription
/www/htmlDrop your Datafiles in this Directory to be served by Nginx
/www/logsLogfiles for Nginx error and Access
⁠Environment Variables

Along with the Environment Variables from the Base image⁠, below is the complete list of available options that can be used to customize your installation.

⁠Authentication Options

You can choose to request visitors be authenticated before accessing your site. Options are below.

ParameterDescriptionDefault
NGINX_AUTHENTICATION_TYPEProtect the site with BASIC, LDAP, LLNGNONE
NGINX_AUTHENTICATION_TITLEChallenge response when visiting protected sitePlease login
NGINX_AUTHENTICATION_BASIC_USER1If BASIC chosen enter this for the username to protect siteadmin
NGINX_AUTHENTICATION_BASIC_PASS1If BASIC chosen enter this for the password to protect sitepassword
NGINX_AUTHENTICATION_BASIC_USER2As above, increment for more users
NGINX_AUTHENTICATION_BASIC_PASS2As above, increment for more users
NGINX_AUTHENTICATION_LDAP_HOSTHostname and port number of LDAP Server - eg ldap://ldapserver:389
NGINX_AUTHENTICATION_LDAP_BIND_DNUser to Bind to LDAP - eg cn=admin,dc=orgname,dc=org
NGINX_AUTHENTICATION_LDAP_BIND_PWPassword for Above Bind User - eg password
NGINX_AUTHENTICATION_LDAP_BASE_DNBase Distringuished Name - eg dc=hostname,dc=com
NGINX_AUTHENTICATION_LDAP_ATTRIBUTEUnique Identifier Attrbiute -ie uid
NGINX_AUTHENTICATION_LDAP_SCOPELDAP Scope for searching - eg sub
NGINX_AUTHENTICATION_LDAP_FILTERDefine what object that is searched for (ie objectClass=person)
NGINX_AUTHENTICATION_LDAP_GROUP_ATTRIBUTEIf searching inside of a group what is the Group Attribute - eg uniquemember
NGINX_AUTHENTICATION_LLNG_HANDLER_HOSTIf LLNG chosen use hostname of handlerllng-handler
NGINX_AUTHENTICATION_LLNG_HANDLER_PORTIf LLNG chosen use this port for handler2884
NGINX_AUTHENTICATION_LLNG_ATTRIBUTE1Syntax: HEADER_NAME, Variable, Upstream Variable - See note below
NGINX_AUTHENTICATION_LLNG_ATTRIBUTE2Syntax: HEADER_NAME, Variable, Upstream Variable - See note below

When working with NGINX_AUTHENTICATION_LLNG_ATTRIBUTE2 you will need to omit any $ chracters from your string. It will be added in upon container startup. Example: NGINX_AUTHENTICATION_LLNG_ATTRIBUTE1=HTTP_AUTH_USER,uid,upstream_http_uid will get converted into HTTP_AUTH_USER,$uid,$upstream_http_uid and get placed in the appropriate areas in the configuration.

⁠Logging Options
ParameterDescriptionDefault
NGINX_LOG_ACCESS_FILENginx websites access logsaccess.log
NGINX_LOG_ACCESS_LOCATIONLocation inside container for saving logs/www/logs/nginx
NGINX_LOG_ERROR_FILENginx server and websites error log nameerror.log
NGINX_LOG_ERROR_LOCATIONLocation inside container for saving logs/www/logs/nginx
NGINX_LOG_LEVEL_ERRORHow much verbosity to use with error logswarn
⁠Compression Options

Presently you can compress your served content with gzip and brotli. More compression options to come in future..

ParameterDescriptionDefault
NGINX_ENABLE_COMPRESSION_BROTLIEnable Brotli CompressionTRUE
NGINX_COMPRESSION_BROTLI_LEVELCompression Level for Brotli6
NGINX_COMPRESSION_BROTLI_MIN_LENGTHMinimum length of content before compressing20
NGINX_COMPRESSION_BROTLI_TYPESWhat filetypes to compresstext/plain text/css text/xml text/javascript application/x-javascript application/json application/xml
NGINX_COMPRESSION_BROTLI_WINDOW512k
NGINX_ENABLE_COMPRESSION_GZIPEnable GZIP CompressionTRUE
NGINX_COMPRESSION_GZIP_BUFFERS16 8k
NGINX_COMPRESSION_GZIP_DISABLEDon't compress for these user agentsMSIE [1-6].(?!.*SV1)
NGINX_COMPRESSION_GZIP_HTTP_VERSION1.1
NGINX_COMPRESSION_GZIP_LEVELCompression Level6
NGINX_COMPRESSION_GZIP_MIN_LENGTHMinimum length of content before compressing10240
NGINX_COMPRESSION_GZIP_PROXIEDexpired no-cache no-store private auth
NGINX_COMPRESSION_GZIP_TYPESTypes of content to compresstext/plain text/css text/xml text/javascript application/x-javascript application/json application/xml
NGINX_COMPRESSION_GZIP_VARYTRUE
⁠DDoS Options
ParameterDescriptionDefault
NGINX_ENABLE_DDOS_PROTECTIONEnable simple DDoS ProtectionFALSE
NGINX_DDOS_CONNECTIONS_PER_IPLimit amount of connections per IP10m
NGINX_DDOS_REQUESTS_PER_IPLimit amount of requests per IP5r/s
⁠Reverse Proxy Options
ParameterDescriptionDefault
NGINX_ENABLE_FASTCGI_HTTPSSet fastcgi_param HTTPS 'on'FALSE
NGINX_ENABLE_REVERSE_PROXYHelpers for when behind a reverse proxyTRUE
NGINX_REAL_IP_HEADERWhat is the header passed containing the visitors IPX-Forwarded-For
NGINX_SET_REAL_IP_FROMSet the network of your Docker Network if having IP lookup issues172.16.0.0/12
⁠Container Options
ParameterDescriptionDefault
NGINX_ENABLE_APPLICATION_CONFIGURATIONDon't automatically setup /etc/nginx/conf.d files - Useful for volume mapping/overridingTRUE
NGINX_ENABLE_CREATE_SAMPLE_HTMLIf no index.html found - create a sample one to prove container worksTRUE
NGINX_ENABLE_SITE_OPTIMIZATIONSDeny access to some files and URLs, send caching tagsTRUE
NGINX_INCLUDE_CONFIGURATIONInclude configuration in your website application file. eg /www/website/nginx.conf
NGINX_RELOAD_ON_CONFIG_CHANGEAutomatically reload nginx on configuration file changeFALSE
NGINX_LISTEN_PORTNginx listening port80
NGINX_WEBROOTWhere to serve content from inside the container/www/html
⁠Functionality Options
ParameterDescriptionDefault
FORCE_RESET_PERMISSIONSForce setting Nginx files ownership to web server userTRUE
NGINX_MODESet to NORMAL, MAINTENANCE , PROXY, REDIRECTNORMAL
NGINX_REDIRECT_URLIf REDIRECT set enter full url to forward all traffic to eg https://example.com
NGINX_PROXY_URLIf REDIRECT set enter full url to proxy all traffic to eg https://example.com:443
NGINX_USERWhat user to run nginx as inside containernginx
NGINX_GROUPWhat group to run nginx as inside containerwww-data

If set to MAINTNENANCE a single page will show visitors that the server is being worked on.

You can also enter into the container and type maintenance ARG, where ARG is either ON,OFF, or SLEEP (seconds) which will temporarily place the site in maintenance mode and then restore it back to normal after time has passed.

⁠Performance Options
ParameterDescriptionDefault
NGINX_CLIENT_BODY_TIMEOUTRequest timed out60
NGINX_ENABLE_EPOLLOptmized to serve many clients with each thread, essential for linuxTRUE
NGINX_ENABLE_MULTI_ACCEPTAccept as many connections as possible, may flood worker connections if set too lowTRUE
NGINX_ENABLE_RESET_TIMEDOUT_CONNECTIONAllow the server to close connection on non responding client, this will free up memoryTRUE
NGINX_ENABLE_SENDFILECopies data between one FD and other from within the kernelTRUE
NGINX_ENABLE_SERVER_TOKENSShow Nginx version on responsesFALSE
NGINX_ENABLE_TCPNODELAYDon't buffer data sent, good for small data bursts in real timeTRUE
NGINX_ENABLE_TCPNOPUSHSend headers in one peace, its better then sending them one by oneTRUE
NGINX_KEEPALIVE_REQUESTSNumber of requests client can make over keep-alive100000
NGINX_KEEPALIVE_TIMEOUTServer will close connection after this time75
NGINX_SEND_TIMEOUTIf client stop responding, free up memory60
NGINX_UPLOAD_MAX_SIZEMaximum Upload Size2G
NGINX_WORKER_CONNECTIONSDetermines how much clients will be served per worker1024
NGINX_WORKER_PROCESSESHow many processes to spawnauto
NGINX_WORKER_RLIMIT_NOFILENumber of file descriptors used for nginx100000
NGINX_ENABLE_OPEN_FILE_CACHECache informations about FDs, frequently accessed filesTRUE
NGINX_ENABLE_OPEN_FILE_CACHE_ERRORSCache errors like 404TRUE
NGINX_OPEN_FILE_CACHE_INACTIVEStop caching after inactive5m
NGINX_OPEN_FILE_CACHE_MAXMaximum files to cache200000
NGINX_OPEN_FILE_CACHE_MIN_USESMinimum uses of file before cashing2
NGINX_OPEN_FILE_CACHE_VALIDCache a file if has been accessed within this window2m
NGINX_CLIENT_BODY_BUFFER_SIZEClient Buffer size16k
NGINX_FASTCGI_BUFFERSAmount of FastCGI Buffers16 16k
NGINX_FASTCGI_BUFFER_SIZEFastCGI Buffer Size32k
⁠Networking

The following ports are exposed.

PortDescription
80HTTP

⁠Maintenance

⁠Shell Access

For debugging and maintenance purposes you may want access the containers shell.

docker exec -it (whatever your container name is ie  nginx) bash

⁠References

Tag summary

Content type

Image

Digest

Size

44.2 MB

Last updated

about 6 years ago

docker pull rusxakep/nginx