甲方IT的成长之路--nginx实战--2604

vi /etc/nginx/conf.d/oa.conf

cd /etc/nginx/conf.d/

下面可以很多配置文件,oa.conf,crm.conf

server {

listen 80;

server_name _;

#server_name sh.cloudfutures.cn;

#add_header 'Access-Control-Allow-Origin' *;

#add_header 'Access-Control-Allow-Headers' *;

#add_header 'Access-Control-Allow-Credentials' 'true';

#add_header 'Access-Control-Allow-Methods' *;

proxy_http_version 1.1;

#location / {

root /data/nginx/html;

index index.html index.htm;

try_files uri uri/ /index.html last;

}

location /mobile {

alias /data/nginx/dist;

index index.html index.htm;

try_files uri uri/ /index.html last;

}

location /material {

alias /data/nginx/h5;

index index.html index.htm;

try_files uri uri/ /index.html last;

}

location /cffcapi/ {

proxy_set_header Host "wxapi.qq.com";

proxy_set_header X-Real-IP $remote_addr;

proxy_set_header User-Agent $http_user_agent;

proxy_hide_header "X-Content-Type-Options";

proxy_hide_header "Strict-Transport-Security";

proxy_hide_header "Content-Security-Policy";

proxy_ssl_server_name on;

proxy_ssl_protocols TLSv1.2 TLSv1.3;

proxy_pass https://qyapi.weixin.qq.com/;

proxy_connect_timeout 30s;

proxy_read_timeout 60s;

proxy_send_timeout 60s;

}

location /material/api/ {

proxy_set_header Host $http_host;

proxy_set_header X-Real-IP $remote_addr;

proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;

proxy_set_header X-Forwarded-Proto $scheme;

proxy_connect_timeout 900s;

proxy_read_timeout 15m;

proxy_send_timeout 15m;

proxy_pass http://172.168.27.19:80/;

}

location /promotionapi/ {

proxy_set_header Host $http_host;

proxy_set_header X-Real-IP $remote_addr;

proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;

proxy_set_header X-Forwarded-Proto $scheme;

proxy_connect_timeout 900s;

proxy_read_timeout 15m;

proxy_send_timeout 15m;

proxy_pass http://127.0.0.1:88/;

}

location /api/hwapi/ {

proxy_set_header Host $http_host;

proxy_set_header X-Real-IP $remote_addr;

proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;

proxy_set_header X-Forwarded-Proto $scheme;

proxy_connect_timeout 900s;

proxy_read_timeout 15m;

proxy_send_timeout 15m;

proxy_pass http://172.168.27.19:6618/hwapi/;

}

location /hwapi/ {

proxy_set_header Host $http_host;

proxy_set_header X-Real-IP $remote_addr;

proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;

proxy_set_header X-Forwarded-Proto $scheme;

这里需要特别注意安全层面,nginx可以作为跳板,去攻击其他主机,而且是主机层面上,网络无法封堵

相关推荐
云水一下1 小时前
从零开始学 PHP 系列(六):MySQL 数据库与 PHP 交互——让数据真正“住”进服务器
数据库·mysql·php
fofantasy1 小时前
NSK LH25FL 升级至 NH25EM 技术规格指南
服务器·网络·数据库·经验分享·规格说明书
炘爚1 小时前
Linux——Redis
数据库·redis·缓存
Oo_行者_oO2 小时前
删库先别跑路,万一修复呢?MySQL 误删数据恢复可落地运维文档
数据库·面试
曾阿伦2 小时前
深入了解MongoDB 两地三中心架构
数据库·mongodb·架构
facaixxx20242 小时前
雨云服务器区域选择终极指南:地域速度、节点带宽、延迟及防御说明
服务器·云服务器·雨云服务器·云服务器区域·云服务器地域·云服务器节点
小坏蛋至尊宝2 小时前
如何优化文件传输的性能?
运维·服务器
代码雕刻家2 小时前
1.24.MySQL-idea中连接MySQL的基本操作
数据库·mysql·intellij-idea