mirror of
https://github.com/xiaoxinpro/nginx-proxy-manager-zh.git
synced 2025-01-23 13:18:14 -05:00
106 lines
3.3 KiB
Nginx Configuration File
106 lines
3.3 KiB
Nginx Configuration File
# run nginx in foreground
|
|
daemon off;
|
|
|
|
user root;
|
|
|
|
# Set number of worker processes automatically based on number of CPU cores.
|
|
worker_processes auto;
|
|
|
|
# Enables the use of JIT for regular expressions to speed-up their processing.
|
|
pcre_jit on;
|
|
|
|
error_log /data/logs/fallback_error.log warn;
|
|
|
|
# Includes files with directives to load dynamic modules.
|
|
include /etc/nginx/modules/*.conf;
|
|
|
|
events {
|
|
worker_connections 1024;
|
|
}
|
|
|
|
http {
|
|
include /etc/nginx/mime.types;
|
|
default_type application/octet-stream;
|
|
sendfile on;
|
|
server_tokens off;
|
|
tcp_nopush on;
|
|
tcp_nodelay on;
|
|
client_body_temp_path /tmp/nginx/body 1 2;
|
|
keepalive_timeout 90s;
|
|
proxy_connect_timeout 90s;
|
|
proxy_send_timeout 90s;
|
|
proxy_read_timeout 90s;
|
|
ssl_prefer_server_ciphers on;
|
|
gzip on;
|
|
proxy_ignore_client_abort off;
|
|
client_max_body_size 2000m;
|
|
server_names_hash_bucket_size 1024;
|
|
proxy_http_version 1.1;
|
|
proxy_set_header X-Forwarded-Scheme $scheme;
|
|
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
|
proxy_set_header Accept-Encoding "";
|
|
proxy_cache off;
|
|
proxy_cache_path /var/lib/nginx/cache/public levels=1:2 keys_zone=public-cache:30m max_size=192m;
|
|
proxy_cache_path /var/lib/nginx/cache/private levels=1:2 keys_zone=private-cache:5m max_size=1024m;
|
|
|
|
lua_package_path '~/lua/?.lua;;';
|
|
|
|
lua_ssl_trusted_certificate /etc/ssl/certs/ca-certificates.crt;
|
|
lua_ssl_verify_depth 5;
|
|
|
|
# cache for discovery metadata documents
|
|
lua_shared_dict discovery 1m;
|
|
# cache for JWKs
|
|
lua_shared_dict jwks 1m;
|
|
|
|
log_format proxy '[$time_local] $upstream_cache_status $upstream_status $status - $request_method $scheme $host "$request_uri" [Client $remote_addr] [Length $body_bytes_sent] [Gzip $gzip_ratio] [Sent-to $server] "$http_user_agent" "$http_referer"';
|
|
log_format standard '[$time_local] $status - $request_method $scheme $host "$request_uri" [Client $remote_addr] [Length $body_bytes_sent] [Gzip $gzip_ratio] "$http_user_agent" "$http_referer"';
|
|
|
|
access_log /data/logs/fallback_access.log proxy;
|
|
|
|
# Dynamically generated resolvers file
|
|
include /etc/nginx/conf.d/include/resolvers.conf;
|
|
|
|
# Default upstream scheme
|
|
map $host $forward_scheme {
|
|
default http;
|
|
}
|
|
|
|
# Real IP Determination
|
|
|
|
# Local subnets:
|
|
set_real_ip_from 10.0.0.0/8;
|
|
set_real_ip_from 172.16.0.0/12; # Includes Docker subnet
|
|
set_real_ip_from 192.168.0.0/16;
|
|
# NPM generated CDN ip ranges:
|
|
include conf.d/include/ip_ranges.conf;
|
|
# always put the following 2 lines after ip subnets:
|
|
real_ip_header X-Real-IP;
|
|
real_ip_recursive on;
|
|
|
|
# Custom
|
|
include /data/nginx/custom/http_top[.]conf;
|
|
|
|
# Files generated by NPM
|
|
include /etc/nginx/conf.d/*.conf;
|
|
include /data/nginx/default_host/*.conf;
|
|
include /data/nginx/proxy_host/*.conf;
|
|
include /data/nginx/redirection_host/*.conf;
|
|
include /data/nginx/dead_host/*.conf;
|
|
include /data/nginx/temp/*.conf;
|
|
|
|
# Custom
|
|
include /data/nginx/custom/http[.]conf;
|
|
}
|
|
|
|
stream {
|
|
# Files generated by NPM
|
|
include /data/nginx/stream/*.conf;
|
|
|
|
# Custom
|
|
include /data/nginx/custom/stream[.]conf;
|
|
}
|
|
|
|
# Custom
|
|
include /data/nginx/custom/root[.]conf;
|