nginx.conf 3.4 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102
  1. #user nobody;
  2. worker_processes 1;
  3. #error_log logs/error.log;
  4. #error_log logs/error.log notice;
  5. #error_log logs/error.log info;
  6. #pid logs/nginx.pid;
  7. events {
  8. worker_connections 1024;
  9. }
  10. http {
  11. include mime.types;
  12. default_type application/octet-stream;
  13. #log_format main '$remote_addr - $remote_user [$time_local] "$request" '
  14. # '$status $body_bytes_sent "$http_referer" '
  15. # '"$http_user_agent" "$http_x_forwarded_for"';
  16. #access_log logs/access.log main;
  17. sendfile on;
  18. tcp_nopush on;
  19. tcp_nodelay on;
  20. #keepalive_timeout 0;
  21. keepalive_timeout 65;
  22. server
  23. {
  24. listen 80;
  25. server_name www.lowflow.vip lowflow.vip;
  26. rewrite ^(.*)$ https://$host$1 permanent;
  27. }
  28. server
  29. {
  30. listen 443 ssl;
  31. server_name www.lowflow.vip lowflow.vip;
  32. ssl_certificate /etc/nginx/ssl/lowflow.vip_cert_chain.pem;
  33. ssl_certificate_key /etc/nginx/ssl/lowflow.vip_key.key;
  34. # 发送数据缓冲区大小
  35. ssl_buffer_size 4k;
  36. # 会话缓存区大小,每1m可以缓存4000个会话,大大减少了SSL握手的次数,提高了性能
  37. ssl_session_cache shared:SSL:50m;
  38. # 缓存SSL握手产生的参数和加密密钥的时长
  39. ssl_session_timeout 5h;
  40. # 表示使用的TLS协议的类型
  41. ssl_protocols TLSv1.2 TLSv1.3;
  42. add_header Strict-Transport-Security "max-age=63072000; includeSubDomains; preload";
  43. # 使用的加密套件的类型
  44. #TLS协议版本越高,HTTPS通信的安全性越高,但是相较于低版本TLS协议,高版本TLS协议对浏览器的兼容性较差。
  45. ssl_ciphers TLS13-CHACHA20-POLY1305-SHA256:TLS13-AES-256-GCM-SHA384:TLS13-AES-128-GCM-SHA256:EECDH+CHACHA20:EECDH+AESGCM:EECDH+AES;
  46. # 加密套件优先选择服务器的加密套件。默认开启
  47. ssl_prefer_server_ciphers on;
  48. location / {
  49. root /usr/share/nginx/html;
  50. index index.html index.htm;
  51. try_files $uri $uri/ /index.html;
  52. }
  53. }
  54. server
  55. {
  56. listen 80;
  57. server_name git.lowflow.vip;
  58. rewrite ^(.*)$ https://$host$1 permanent;
  59. }
  60. server
  61. {
  62. listen 443 ssl;
  63. server_name git.lowflow.vip;
  64. ssl_certificate /etc/nginx/ssl/git.lowflow.vip_cert_chain.pem;
  65. ssl_certificate_key /etc/nginx/ssl/git.lowflow.vip_key.key;
  66. # 发送数据缓冲区大小
  67. ssl_buffer_size 4k;
  68. # 会话缓存区大小,每1m可以缓存4000个会话,大大减少了SSL握手的次数,提高了性能
  69. ssl_session_cache shared:SSL:50m;
  70. # 缓存SSL握手产生的参数和加密密钥的时长
  71. ssl_session_timeout 5h;
  72. # 表示使用的TLS协议的类型
  73. ssl_protocols TLSv1.2 TLSv1.3;
  74. add_header Strict-Transport-Security "max-age=63072000; includeSubDomains; preload";
  75. # 使用的加密套件的类型
  76. #TLS协议版本越高,HTTPS通信的安全性越高,但是相较于低版本TLS协议,高版本TLS协议对浏览器的兼容性较差。
  77. ssl_ciphers TLS13-CHACHA20-POLY1305-SHA256:TLS13-AES-256-GCM-SHA384:TLS13-AES-128-GCM-SHA256:EECDH+CHACHA20:EECDH+AESGCM:EECDH+AES;
  78. # 加密套件优先选择服务器的加密套件。默认开启
  79. ssl_prefer_server_ciphers on;
  80. location / {
  81. proxy_pass http://:20080;
  82. }
  83. }
  84. }