Files
weiyu/deploy/nginx/weiyuai.cn/nginx.conf
jack ning b124f2d5b6 update
2025-10-13 00:18:09 +08:00

136 lines
3.9 KiB
Nginx Configuration File
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# 记得添加否则会报错unknown directive "stream" in /etc/nginx/nginx.conf
# load_module /usr/lib/nginx/modules/ngx_stream_module.so;
# apt -y install libnginx-mod-stream
#
user www-data;
# user root;
worker_processes auto;
pid /run/nginx.pid;
# https://blog.csdn.net/liupeifeng3514/article/details/79007079
# 报错500: nginx too many open files
worker_rlimit_nofile 65535;
# Enable stream module for UDP support
load_module modules/ngx_stream_module.so;
events {
use epoll;
worker_connections 65535;
accept_mutex off;
multi_accept on;
}
http {
##
# Basic Settings
##
sendfile on;
tcp_nopush on;
tcp_nodelay on;
keepalive_timeout 65;
types_hash_max_size 2048;
# server_tokens off;
# server_names_hash_bucket_size 64;
# server_name_in_redirect off;
include /etc/nginx/mime.types;
default_type application/octet-stream;
# 禁止ip黑名单访问服务器
# include blackip.conf;
##
# SSL Settings
##
# Only allow secure TLS versions
ssl_protocols TLSv1.2 TLSv1.3;
ssl_prefer_server_ciphers on;
ssl_ciphers HIGH:!aNULL:!MD5;
ssl_session_cache shared:SSL:10m;
ssl_session_timeout 10m;
##
# Logging Settings
##
access_log /var/log/nginx/access.log;
error_log /var/log/nginx/error.log;
##
# Gzip Settings
##
gzip on;
gzip_disable "msie6";
##
# Virtual Host Configs
##
## http://blog.51cto.com/freeloda/1288553
## 设置缓存
## 注意:要放在/var/www/html目录下否则会permission denied
## mkdir -p /var/www/html/nginx/cache/webserver
proxy_cache_path /var/www/html/nginx/cache/webserver levels=1:2 keys_zone=webserver:20m max_size=1g;
# use_temp_path=off;
# nginx 出现413 Request Entity Too Large问题的解决方法
client_max_body_size 1024m;
## restapi-负载均衡
upstream weiyuai {
# round_robin; # 默认,轮流分配
ip_hash; # 同一个ip访问同一台服务器, 这样来自同一个IP的访客固定访问一个后端服务器
# least_conn; # 公平分配
# server 172.16.81.2:9003 weight=2 max_fails=10 fail_timeout=60s;
server 127.0.0.1:9003 weight=2 max_fails=10 fail_timeout=60s;
}
# websocket-负载均衡
upstream weiyuaiwss {
# round_robin; # 默认,轮流分配
ip_hash; # 同一个ip访问同一台服务器, 这样来自同一个IP的访客固定访问一个后端服务器
# least_conn; # 公平分配
# server 172.16.81.2:9885 weight=2 max_fails=10 fail_timeout=60s;
server 127.0.0.1:9885 weight=2 max_fails=10 fail_timeout=60s;
}
# FreeSWITCH upstreams (HTTP/WS context)
# Note: SIP itself is NOT HTTP and must not be proxied via http { }.
# Only WS/WSS (SIP over WebSocket) should be defined here.
# FreeSWITCH external SIP upstream
upstream freeswitch_external {
server 14.103.165.199:5080; # External SIP port - public IP
}
# FreeSWITCH WebSocket upstream (WS)
upstream freeswitch_ws {
server 14.103.165.199:5066; # WebSocket port - public IP
}
# FreeSWITCH Secure WebSocket upstream (WSS)
upstream freeswitch_wss {
server 14.103.165.199:7443; # Secure WebSocket port - public IP
}
# FreeSWITCH Verto upstream (if needed)
# upstream freeswitch_verto {
# server 14.103.165.199:8081; # Verto port - public IP
# }
include /etc/nginx/conf.d/*.conf;
include /etc/nginx/sites-enabled/*;
}
# Stream module configuration for UDP
stream {
# Stream-level logging to aid troubleshooting
error_log /var/log/nginx/stream_error.log info;
# IMPORTANT: Do NOT attempt to proxy RTP via nginx stream.
# RTP uses a wide port range and should be exposed directly to FreeSWITCH
# or handled via a TURN server (e.g., coturn). Remove any single-port RTP proxy.
}