9 ms·
Nginx 1.12.0 stable
- Zikes 9y agoI'm surprised by the lack of first-class ACME/Let's Encrypt support. I figured once Caddy paved the way in that regard that nginx wouldn't be far behind.
- jxi 9y agoThanks for the reference to Caddy! Looks like a pretty neat project. I'm also bummed by nginx's lack of end-to-end HTTP/2 support.
- lprd 9y agoI was just thinking the same thing. I've been using Caddy for about a year now and love it.
- pfg 9y agoI'm all for adding native ACME support to web servers, but I can understand that they'd rather wait till ACME reaches RFC status (which hopefully won't be long now - the draft is in WG Last-Call). Once that's done, I'd definitely be disappointed if web servers still decide it's not in scope for their core product.
- Zikes 9y agoI don't think it's unreasonable to expect an officially supported optional module, at the very least. It's how they've handled experimental features in the past.
- _mikz 9y agoThere is lua-resty-auto-ssl [1] providing exactly that. Sure, it is not plain Nginx, but OpenResty. [1] https://github.com/GUI/lua-resty-auto-ssl https://github.com/GUI/lua-resty-auto-ssl
- frik 9y agoThe only thing pretty bitter about Nginx is that the access to the server status in the open source community edition. You get only so much with "ngx_http_stub_status_module" that you have to compile in yourself, as distros don't compile it in: https://nginx.org/en/docs/http/ngx_http_stub_status_module.html https://nginx.org/en/docs/http/ngx_http_stub_status_module.h... With Nginx plus you get access to so much more ("ngx_http_status_module") of the server status. It's not about the pretty frontend, it's about the values. http://nginx.org/en/docs/http/ngx_http_status_module.html http://nginx.org/en/docs/http/ngx_http_status_module.html Why isn't there a CentOS-style distro apt/rpm package of Nginx (think of free RedHat) with the status module enabled, as based on open source Nginx?
- LinuxFreedom 9y agoIt does not make any sense to complain. The constructive approach that lead us to open source world domination goes like this: just build what you need. Start today, publish early, others will chime in and you will have the best status module you could dream of.
- daenney 9y ago> Why isn't there a CentOS-style distro apt/rpm package of Nginx (think of free RedHat) with the status module enabled, as based on open source Nginx? The code of ngx_http_status_module isn't open source (as far as I know). Getting access to it means you need an Nginx Plus license. Someone packaging that up and distributing it for free would be a rather big violation.
- simonw 9y agoThis is the classic downside of open source that's supported by a "pro" edition: it encourages maintainers to actively avoid adding features that would compete with the paid product.
- inopinatus 9y agoThis is similar to the classic blunder by service product strategists who tier pricing by both capability and scale, rather than one or the other. This results in nonselection of the product rather than the hoped-for upsell.
- jsiepkes 9y agoWe used NGINX with Consul (template) and Vault quite extensively until I recently found out about eBay's Fabio ( https://github.com/eBay/fabio https://github.com/eBay/fabio ). Fabio is really great as an NGINX reverse proxy alternative in an environment with Consul or etcd. I highly recommend it.
- MHordecki 9y agoWhat made you switch?
- jsiepkes 9y agoHome made consul template duct tape with NGINX vs. solution that was designed from the ground up to be what we mangled NGINX to be with Consul template. Concrete example; Fabio is far more resilient to operator mistakes then our own NGINX Consul template duct tape solution (which is totally unforgiving).
- magiconair 9y agoGlad you like it. :) Disclaimer: I'm the author.
- jbergstroem 9y agoOne key missing piece in nginx is a way to interact with the configuration without having to edit the config file. This is such a vital piece of a modern infrastructure; where backends are added/removed on demand. You can interact with haproxy via lua[1] or use etcd to have traefik load its configuration[2]. Seeing how [as others also mentioned] nginx seems to favor pro customers in terms of functionality, it would only seem wise to choose another proxy/load balancer for your next project. [1]: http://www.arpalert.org/src/haproxy-lua-api/1.7/#Proxy.servers http://www.arpalert.org/src/haproxy-lua-api/1.7/#Proxy.serve... [2]: https://docs.traefik.io/toml/#etcd-backend https://docs.traefik.io/toml/#etcd-backend
- nodesocket 9y agoNGINX plus provides a simple http API to add and remove backends to an upstream block. They also have persistence of these changes. See https://www.nginx.com/products/on-the-fly-reconfiguration/ https://www.nginx.com/products/on-the-fly-reconfiguration/
- user5994461 9y agoDisclaimer: nginx plus is about $1900 per server. HaProxy is free.
- oconnore 9y agoYou can hot reload config files that you have already tested for correctness. No dropped connections.
- ploxiln 9y agonginx can reload the config files without closing the listening port or interrupting any existing requests. haproxy can't do that. So you can actually live-update on-demand much more of the nginx configuration than you can the haproxy configuration.
- paulddraper 9y ago> haproxy can't do that. HAProxy reloads don't interrupt existing connections (unless you want it to). There is a ~microsecond downtime in accepting new connections. https://engineeringblog.yelp.com/2015/04/true-zero-downtime-haproxy-reloads.html https://engineeringblog.yelp.com/2015/04/true-zero-downtime-...
- xfalcox 9y agoWas hopping to get HTTP2 server push on 1.12 since H20, Caddy and even Apache already support it.
- ehllo 9y agoyou should have a look at the Nginx fork from tabao/alibaba https://github.com/alibaba/tengine https://github.com/alibaba/tengine http://tengine.taobao.org/ http://tengine.taobao.org/
- ajuhasz 9y agoWe're having great luck using traefik (https://traefik.io https://traefik.io) as a kubernetes ingress, we just couldn't get nginx working well and ever since the switch it's been rock-solid.
- Ruud-v-A 9y agoDoes it support more advanced forms of authentication than http basic?
- nikcub 9y agoDigest. But you probably want to be doing auth on whatever Traefik is pointing at
- nikcub 9y agoTraefik is amazing - you can add it as a service with almost no config and get http2, https (with good defaults), letsencrypt and auto-discovery of services I also use it as a frontend to all local dev
- dorfsmay 9y agoWhat was the reasoning of traefik vs haproxy?
- nikcub 9y agoTraefik was written before haproxy had hot reloading configuration in 1.7 It does one thing and does it well - auto configured and discoverable lb and proxying designed to run in container environments Easy to get running, easy to know everything it can do and without much effort it gets a lot accomplished Not that nginx and HAProxy still don't have their place, but if you want to front a docker swarm or k8 stack traefik is just easy whereas nginx/haproxy have to be configured for that task
- nailer 9y agoHaven't used traefik but HAProxy doesn't have HTTP/2 support yet.
- deleted 9y ago[deleted]
- _kyran 9y agoOn the topic of Nginx, does anyone know if it's possible/how one could fire off a http request (GET or POST) to an external service to log requests in real time (rather than say logging to a text file then processing that)?
- nhumrich 9y agoSyslog
- otterley 9y agoBut you really don't want to do that if you need accurate log collection and aggregation. Having a local log file is essential to coping with backpressure from the log consumers. Consider what might happen if the remote syslog server goes down or is overburdened.
- deleted 9y ago[deleted]
- rkrzr 9y agoYou can do it using the nginx-lua module, something like: `local response = ngx.location.capture("/some/api/endpoint" )` I would not recommend doing this, though. Nginx internals are rather complicated in my experience.
- _kyran 9y agoThanks! So better off to just log to a file and monitor the tail of that and send the data off with a seperate script?
- zzzcpan 9y agoIt's undocumented, but you can do that with post_action: location /foo/ { ... post_action @mirror_request; } location @mirror_request { proxy_pass ...; }
- 9y ago
- ePierre 9y ago> Changes with nginx 1.12.0 12 Apr 2017 > *) 1.12.x stable branch. Well, thank you very much, that's a very informative changelog. :)