10 ms·
Nginx 1.6.0 stable released
- marshallford 12y agoI figure this is as good of place as any to ask my question: Where can I find someone to hire that is able to write Nginx cofigs well. I have spent literally 40ish hours trying to create a Nginx conf that holds up to my OCD. I have been told numerous times on IRC that I am too picky and clean urls are a challenge to write. I am college student and System Administration isn't even my job! Help!
- cheald 12y agoI'm pretty sure the best way to accomplish this is to jump into IRC and declare that it is impossible to be done. You will have 6 answers in 3 minutes.
- marshallford 12y agoI wish, I have tried multiple times and no one wants/can do it.
- gaoshan 12y agoOr say, "Well, this is the only way to do it... nothing else works for nginx." and then present an inefficient solution. You will get ripped but solutions will arrive.
- faster 12y agoCunningham's Law to the rescue! https://meta.wikimedia.org/wiki/Cunningham's_Law https://meta.wikimedia.org/wiki/Cunningham's_Law
- DrJ 12y agothis is literally happening in this thread
- ShaneOG 12y agoHave you checked out https://github.com/h5bp/server-configs-nginx https://github.com/h5bp/server-configs-nginx ?
- marshallford 12y agoYes I have, however I always find it very challenging to modify it to support clean urls and PHP-FPM in an OCD fashion.
- w-ll 12y agoHave you tried handling your urls in php? Most apps/frameworks I've worked on in the past few years all do better url mgmt then you are probably going to get with just nginx configs.
- leeoniya 12y agoalso check out https://gist.github.com/plentz/6737338 https://gist.github.com/plentz/6737338
- deleted 12y ago[deleted]
- michaelbuckbee 12y agoAsk on StackOverflow or ServerFault, offer a bounty if no one answers within a day.
- marshallford 12y agonot a bad idea. Does either have an official way to offer a bounty? If not, any sites that do? Also, what would you say is a fair price range for this kind of request?
- lazyant 12y agoA bounty in those sites is not monetary but you use "karma" points that you win by answering questions etc.
- scragg 12y agoI bet it will get closed for being too localized.
- odonnellryan 12y agoWhat problems exactly with "clean URLs" are you running into?
- marshallford 12y agoIt is a lot to get into now, but here is a taste. foo.com/index > foo.com foo.com/ > foo.com foo.com/folder/index > foo.com/folder/ foo.com/bar.html > foo.com/bar foo.com/bar.htm > foo.com/bar foo.com/bar.php > foo.com/bar www.foo.com/ANY OF THE ABOVE TESTS > foo.com/* other rules: Never add trailing slash unless it is an index file of a directory. Order: .PHP,.HTML,.HTM. Use h5bp/server-configs-nginx as a base. PHP-FPM should be fully supported and not exploitable by the foo.com/random.gif.php bug. 403 and 404 send to /404.html. I am sure I am forgetting something, but that is a start.
- richardjs 12y agoYour specs look a lot like ours (we have a CMS that adds a trailing /index to every page that is part of the core navigation, and we don't want that). Here's the three primary rewrite rules we use for the issue; they don't match your spec exactly, but they might help you get started: # - Remove trailing slashes (except root /) # e.g. /foo/bar/ -> /foo/bar # ([^^] matches every character but the start of the string) rewrite [^^](.*)/$ /$1 permanent; # - Remove .html and .htm extensions # e.g. /foo/bar.htm -> /foo/bar rewrite ^(.*)\.html?$ $1 permanent; # - Remove index file URLs # e.g. /foo/bar/index -> /foo/bar/ # (the trailing slash is then removed by the first rewrite) rewrite ^(.*/)index$ $1 permanent; Edit: There's a couple extra directives that go along with the above to make it work that I neglected to include: # Try the request URI, and a potential index file in the URI (in the case of a directory). # This lets you hit the file WEBROOT/foo/bar/index with the URI /foo/bar, # and hit the file WEBROOT/foo/bar.html with the URI /foo/bar try_files $uri $uri/index $uri.html =404; # You need this (or some other way to provide the type information) # if you don't have extensions on your files. default_type text/html; Also, for error pages, you can probably just use the error_page directive: error_page 404 403 /404; # The .html in your spec will be stripped off by the above rewrite rule
- jafaku 12y agoYou should let your web framework of choice do that. You should be able to find any directives you need to add to your nginx conf in your framework's docs. Typically they will use a Front Controller (eg: app.php or index.php), so you need a directive to map all the dynamic traffic (ie. usually not images or other static files) to that file. Everything else is done by the framework.
- marshallford 12y agoI am designing this Ngnix conf for use on small vanilla sites and static generated sites like Jekyll. (Yes I know Jekyll puts all blog posts in separate folders to solve the URL issue, but I don't want that).
- mrweasel 12y agoYou could pay the Nginx guys to help I suppose.
- eggnet 12y agoYou didn't really specify what you meant by clean URLs but, maybe this will be helpful to you or someone else. I have a static site served via nginx, but I don't like seeing .html in the URLs. It's a little tricky serving a static site without the .html extension because you may have a directory and an html page with the same name. The way to deal with that is to actually use the .html extension in the file system but not URLs. location / { if ($uri ~ ^/google) { break; } if ($uri ~ ^/y_key_) { break; } if ($uri ~ \.html$) { return 404; } if ($uri = /index) { return 404; } if (!-f $request_filename) { rewrite ^/$ /index.html break; rewrite .* $uri.html break; } }
- Spittie 12y agoBy the way, the nginx wiki says that you should avoid ifs when possible: http://wiki.nginx.org/IfIsEvil http://wiki.nginx.org/IfIsEvil Wouldn't something like this accomplish the same thing? (Sorry if I'm totally wrong, I'm not really good) location /google/ { } location /y_key_/ { } location ~ \.html$ { return 404; } location = /index { return 404; } location / { try_files $uri @rewrite } location @rewrite { rewrite ^/$ /index.html break; rewrite .* $uri.html break; }
- marshallford 12y agoThis is yet another concern of mine. Most of my solutions involve at least 3 if statements. But I need them in order to check if a requested url is a directory or a file and such.
- sondr3 12y agoWhat kind of app are you running that requires you to do something like this for clean URLs?
- eggnet 12y agoThanks, I will try this, it looks like it will work.
- nilsbunger 12y agoTry odesk? If you have a clear spec for what you want you can probably get a fixed-price bid.
- marshallford 12y agoEven the word "odesk" leaves a bad taste in my mouth. I have heard a lot of bad things about these kinds of freelance sites.
- nilsbunger 12y agoHave you used them? Like anything, odesk/elance/etc require an investment on your side to make successful. We've found good people through odesk to take on tasks we weren't good at -- front-end javascript, document translation, audio transcription, to name a few.
- wbond 12y agoNice to see we once again have a stable nginx release that supports a version of spdy that browsers currently support!
- vbartathn 12y agoThere's also a survey from Nginx Team: http://mailman.nginx.org/pipermail/nginx/2014-April/043282.html http://mailman.nginx.org/pipermail/nginx/2014-April/043282.h... Your opinion is needed for a great future of nginx!
- reidrac 12y agoI wonder what is the policy regarding their Debian repositories now that 1.6 is stable (currently we have 1.4.x installed from that same repo). They broke some stuff in the past moving to 1.4 from an older release, it would be nice to have a "release notes" so we can check what can possibly go wrong (if anything). The changelog is huge, congratulations to the nginx team! EDIT: nginx twitter account confirmed that there's no expected disruption upgrading from 1.4 to 1.6. Excellent!
- gog 12y agoI just upgraded one smaller site to 1.6 to test the waters before doing it elsewhere. So far everything works as expected.
- pedrocr 12y agoI'm currently running apache 2.2.22 on my Ubuntu 12.04 servers. It works fine. I'll be moving them to 14.04 and thus getting apache 2.4.7. I mostly use it for mod_passenger webapps and static sites. 14.04 includes nginx 1.4.6 but I'm sure the phusion guys will package 1.6 soon so I can easily upgrade to that. Is there any killer feature in nginx that I'm missing, staying with apache 2.4?
- cheald 12y agoGenerally speaking, nginx is lighter/faster/less flexible (though no less powerful). It really shines on low-RAM VPSes where the RAM eaten up by a big list of httpd processes really adds up. For example, here are numbers from Apache+mod_passenger on my dev box: VSW RSS root 20050 0.0 0.1 416524 21020 ? Ss Apr18 0:13 /usr/sbin/httpd root 13370 0.0 0.0 217068 1984 ? Ssl Apr21 0:00 \_ PassengerWatchdog root 13373 0.0 0.0 503104 2324 ? Sl Apr21 0:04 | \_ PassengerHelperAgent nobody 13381 0.0 0.0 218208 3508 ? Sl Apr21 0:00 | \_ PassengerLoggingAgent apache 13388 0.0 0.2 500060 33888 ? S Apr21 0:00 \_ /usr/sbin/httpd apache 13389 0.0 0.2 500060 33888 ? S Apr21 0:00 \_ /usr/sbin/httpd apache 13390 0.0 0.2 500060 33888 ? S Apr21 0:00 \_ /usr/sbin/httpd apache 13391 0.0 0.2 500060 34140 ? S Apr21 0:00 \_ /usr/sbin/httpd apache 13392 0.0 0.2 500132 33924 ? S Apr21 0:00 \_ /usr/sbin/httpd And those same numbers on one of my production Linode instances, running nginx + passenger: VSW RSS root 17824 0.0 0.0 7988 328 ? Ss Apr10 0:00 nginx: master process nobody 31676 0.0 0.5 8732 3248 ? S Apr23 0:08 \_ nginx: worker process nobody 9103 0.0 0.5 8684 3288 ? S Apr23 0:03 \_ nginx: worker process nobody 9106 0.0 0.5 8876 3416 ? S Apr23 0:04 \_ nginx: worker process nobody 22077 0.0 0.4 8400 3004 ? S 01:23 0:02 \_ nginx: worker process (yes, I know that ps auxf isn't the best measure of memory usage, but it ballparks to make the point)
- pedrocr 12y agoLinode just upgraded me to 2GB RAM for the same price, and apache doesn't seem to be taking all that much RAM. I guess the benefits aren't all that important for my setup. I may as well spend the time improving other things.
- chiachun 12y agoSupplement: http://nginx.org/en/CHANGES-1.6 http://nginx.org/en/CHANGES-1.6
- mixedbit 12y agoWow, finally auth_request is an official module. Thank you!
- deleted 12y ago[deleted]
- pfg 12y agoSlightly OT: Does anyone know if packages for Ubuntu 14.04 are coming soon? We're using the official (mainline) repository[1] on Ubuntu 12.04, but Trusty doesn't seem to be supported yet. I've always preferred the official repository because I didn't want to start compiling nginx just for stuff like SPDY support. [1]: http://nginx.org/en/linux_packages.html http://nginx.org/en/linux_packages.html
- jolan 12y agoLooks like they exist, just not mentioned on that page yet. http://nginx.org/packages/ubuntu/dists/trusty/nginx/binary-amd64/ http://nginx.org/packages/ubuntu/dists/trusty/nginx/binary-a...
- jallmann 12y agoIt's a good idea to be comfortable compiling/packaging your infra from source (including interpreters, libraries, etc), if only for the ability to quickly apply and deploy emergency patches. To demonstrate the importance of that capability, look no farther than Heartbleed. While distros are usually pretty good about updating critical software, they shouldn't be your only line of defense, except perhaps if you have a SLA or something.
- pfg 12y agoI agree, although I'd stick with packages for almost anything as it's just too much work to keep up with every release of every piece of software in your stack (except for, as you mentioned, special circumstances like Geartbleed). Plus, since in this case the repository is managed by nginx.org, it's hard to beat them to a new release even if you compile from source.
- nlindblad_se 12y agohttps://niklaslindblad.se/2014/03/build-statically-compiled-nginx-147-with-spdy/ https://niklaslindblad.se/2014/03/build-statically-compiled-...
- rhoml 12y agoAgree on this, and also most of the production apps don't require the same modules.
- DiabloD3 12y agoThe big feature, imo, is it finally implements a new version of SPDY (as Chrome and Firefox are discontinuing the version 1.4.x implements).
- leccine 12y agoMost of the best features are in the paid version. I am leaning towards replacing Nginx with Haproxy for the reverse proxying part, unless they move at least the advanced load-balancing features to the free version.
- pedrogk 12y agoWaiting for package for Ubuntu 12.04 and crossing my fingers that it comes with SPDY enabled so I don't have to compile it. I know, I am lazy :P.
- pilif 12y agoyou can use http://pilif.me/nginx.tar.bz2 http://pilif.me/nginx.tar.bz2 to build a debian package from 1.6.0 that is built from the Ubuntu 12.04 source package, so it's a drop-in replacement.
- Afforess 12y agoNginx has an Ubuntu PPA. http://wiki.nginx.org/Install#Ubuntu_PPA http://wiki.nginx.org/Install#Ubuntu_PPA
- atom7 12y agoIt hasn't. "This PPA is maintained by volunteers and is not distributed by nginx.org."
- clarkevans 12y agoI wish there were better authentication options with Nginx. The ngx_http_auth_request_module is limited: First, it assumes that the authentication agent doesn't need to talk to the user. Second, it doesn't cache the authentication. Perhaps nginx might instead check all requests for a particular signed cookie, verify the signature, if the signature matches, verify that the cookie isn't too old, and then unpack variables from the cookie that the application server might want, such as REMOTE_USER. It seems nginx would then want to freshen-up the cookie. If the cookie doesn't exist, signature doesn't match, or the cookie has expired, then, nginx should proxy the request to a delegate... but, it should return the results of that delegation directly to the user agent. It'd be the job of the delegate to set/sign the cookie with the information needed when authentication succeeds. In this way, the authentication agent has full control over the process (so it doesn't have to be in nginx), and, heavyweight authentication is cached. EDIT: Thanks mixedbit -- you're correct that nginx will forward 3xx onto the client. However, I recall patches are needed to support headers; and, without 200 going to the client, how do you support LDAP form authentication? Even so, an extra sub-request to authenticate each request is still heavyweight.
- tetrep 12y ago>Perhaps nginx might instead check all requests for a particular signed cookie... That's called session handling, which is something you want to implement in your web application, not your web server. http://en.wikipedia.org/wiki/HTTP#HTTP_session_state http://en.wikipedia.org/wiki/HTTP#HTTP_session_state http://en.wikipedia.org/wiki/Stateless_protocol http://en.wikipedia.org/wiki/Stateless_protocol
- deleted 12y ago[deleted]
- omh 12y agoIn some cases it would be useful to perform session handling like this in nginx. I like the idea of building a reverse proxy which handles authentication and sessions, in front of a backend web page which wasn't designed to handle it. Something like giving access to an old internal intranet without having to change the app.
- atom7 12y agobut "In general, you should deploy the NGINX mainline branch at all times." @ http://nginx.com/blog/nginx-1-6-1-7-released/ http://nginx.com/blog/nginx-1-6-1-7-released/
- sandGorgon 12y agoIs anybody here using nginx as a REPLACEMENT for varnish ? I'm not an expert in devops, but will be deploying a webapp pretty soon - I was wondering if anyone is replacing varnish with nginx cache (memcached backed?) nginx seems to be increasingly irreplaceable (with ssl caching,etc.) - so was looking to not having to deal with varnish. I did some google searches, but was not able to find anything - including nginx configs, etc. Nginx Plus claims to be an accelerator, but again there isnt a lot of info around that.
- simonz05 12y agoHave not used NGINX cache, but are a heavy user of Varnish + NGINX. Varnish is really good at caching and together with NGINX it makes a solid solution. NGINX cache seems (from skimming the docs) simple and it might be enough for your requirements, with Varnish you know it can do a whole lot and more. As always, it depends.
- ashray 12y agoI've been using nginx+memcached for about 2 years on a high traffic site in production. It's been pretty great and runs without a hiccup. However bear in mind that Varnish is far more capable as nginx's memcached integration is fairly simplistic. You'll have to manage all your keys in the application layer as all nginx can do is send a certain request to a certain key and failover if it's not found. Varnish ACLs allow much finer control. Also, I've come across benchmarks that say Varnish is faster. I just don't want to deal with a complex setup for something that gets the job done. (Job = lower the load on the app server)
- lewaldman 12y agoNginx+memc+cosistent_hashing+memcache :)
- jbergstroem 12y agoTo get a more accurate response, I'd list a few use cases here. If you want better control over cache in general (expiration, purge, etc) or have strong gains (use-case specific) of using VCL or ESI its pretty hard to stay clear of using Varnish. Those are at least my caveats when choosing whether to include it or not in my stack.
- d0ugie 12y agoFyi to those oh-so-lucky to be stuck on Windows systems, while nginx.org offers a 32 bit build, you can get yourself 64 bit build (no extra modules compiled) of the current releases, including 1.7, from http://kevinworthington.com/nginx-for-windows/ http://kevinworthington.com/nginx-for-windows/.
- kolev 12y agoAll good, but Nginx is really playing a nasty game now. Basic features such as proxy_cache_purge are available in the commercial version only.