一、本篇目标

前一篇完成了 Redis 部署。本篇开始部署第二个核心依赖 —— Nginx。

Nginx 在 JeecgBoot 前后端分离架构中承担:

  • 前端静态资源服务(Vue3 编译产物)
  • 后端接口反向代理(/jeecgboot/ → 127.0.0.1:8080)
  • WebSocket 支持(JeecgBoot 消息推送)
  • HTTPS 终止(如果启用)

本篇完成:

  • Nginx 1.28.3 源码编译
  • 15+ 模块启用
  • master/worker 权限模型
  • systemd 服务
  • JeecgBoot 反向代理配置模板

二、为什么源码编译

Nginx 安装方式的对比:

方式优点缺点
系统包(dnf install)简单版本旧、模块固定、路径分散
官方源(nginx.org)版本新和系统包混装容易冲突
源码编译模块可控、自包含需 2-3 分钟编译

选源码编译的理由:

  • 二进制、配置、html 都在 /usr/local/nginx,一目了然
  • 可精确启用所需模块
  • 重装系统后从 /data/packages/nginx/ 解压即恢复

版本选择:Nginx 1.28.x 是最新稳定版(偶数版本),本次用 1.28.3。

三、编译环境

3.1 依赖安装

Nginx 源码编译需要三个核心库:

dnf install -y pcre2-devel zlib-devel openssl-devel

说明:

包用途
pcre2-develrewrite 正则表达式
zlib-develgzip 压缩
openssl-develSSL/TLS(HTTPS)

3.2 下载源码

cd /data/packages
VERSION=1.28.3
wget https://mirrors.huaweicloud.com/nginx/nginx-${VERSION}.tar.gz

3.3 configure

cd /usr/local/src
tar -xzf /data/packages/nginx-1.28.3.tar.gz
cd nginx-1.28.3

./configure \
    --prefix=/usr/local/nginx \
    --user=nginx \
    --group=nginx \
    --with-http_ssl_module \
    --with-http_v2_module \
    --with-http_realip_module \
    --with-http_stub_status_module \
    --with-http_gzip_static_module \
    --with-http_sub_module \
    --with-http_dav_module \
    --with-http_flv_module \
    --with-http_mp4_module \
    --with-http_gunzip_module \
    --with-http_auth_request_module \
    --with-http_random_index_module \
    --with-http_secure_link_module \
    --with-http_slice_module \
    --with-stream \
    --with-stream_ssl_module \
    --with-stream_realip_module \
    --with-threads \
    --with-file-aio \
    --with-pcre \
    --with-pcre-jit

关键模块说明:

模块用途
http_ssl_moduleHTTPS
http_v2_moduleHTTP/2
http_realip_module获取真实客户端 IP(前置 CDN/负载均衡时)
http_stub_status_module状态页监控
http_gzip_static_module读取预压缩的 .gz 文件
http_sub_module响应内容替换
http_auth_request_module子请求鉴权(对接 JeecgBoot Token 校验)
streamTCP/UDP 代理
threads线程池(大文件 IO)
file_aio异步文件 IO

3.4 编译安装

make -j$(nproc)
make install

# 属主
chown -R nginx:nginx /usr/local/nginx

# 版本验证
/usr/local/nginx/sbin/nginx -v

期望:nginx version: nginx/1.28.3

四、权限模型(重点)

Nginx 官方推荐的安全模式:

master 进程(root)  →  绑定 80/443 特权端口
worker 进程(nginx) →  处理实际请求

为什么这么设计:

  • 只有 master 用 root,权限最小化
  • worker 降权到 nginx 用户,即使有漏洞也不扩散
  • 不需要 setcap,这是官方标准做法

验证:

ps -ef | grep nginx | grep -v grep

期望:

root   2213  ... nginx: master process /usr/local/nginx/sbin/nginx
nginx  2214  ... nginx: worker process

五、测试启动

# 检查配置
/usr/local/nginx/sbin/nginx -t

# 启动
/usr/local/nginx/sbin/nginx

# 看端口
ss -lntp | grep ':80'

# 访问
curl -sI http://127.0.0.1/ | head -3

# 停掉(后面用 systemd)
/usr/local/nginx/sbin/nginx -s stop

期望:HTTP/1.1 200 OK

六、systemd 服务

cat > /etc/systemd/system/nginx.service <<'EOF'
[Unit]
Description=The nginx HTTP and reverse proxy server
After=network.target remote-fs.target nss-lookup.target

[Service]
Type=forking
PIDFile=/usr/local/nginx/logs/nginx.pid
ExecStartPre=/usr/local/nginx/sbin/nginx -t
ExecStart=/usr/local/nginx/sbin/nginx
ExecReload=/usr/local/nginx/sbin/nginx -s reload
ExecStop=/usr/local/nginx/sbin/nginx -s quit
PrivateTmp=true
Restart=on-failure
RestartSec=5

[Install]
WantedBy=multi-user.target
EOF

systemctl daemon-reload
systemctl enable --now nginx
systemctl status nginx

注意:

  • Type=forking,因为 Nginx 是 master/worker 模式
  • ExecStartPre 每次启动前自动检查配置
  • ExecReload 支持热重载
  • PrivateTmp=true 使用独立临时目录

七、JeecgBoot 反向代理配置

这是本篇的核心 —— 为 JeecgBoot 前后端分离架构配置反代。

在 /usr/local/nginx/conf/nginx.conf 的 http {} 块内添加:

server {
    listen 80;
    server_name _;

    # 前端静态文件
    root /usr/local/jeecg/frontend;
    index index.html;

    # Vue3 SPA 路由
    location / {
        try_files $uri $uri/ /index.html;
    }

    # 后端接口反向代理
    location /jeecgboot/ {
        proxy_pass http://127.0.0.1:8080/jeecg-boot/;
        proxy_redirect off;
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;

        # WebSocket 支持(JeecgBoot 消息推送必需)
        proxy_http_version 1.1;
        proxy_set_header Upgrade $http_upgrade;
        proxy_set_header Connection "upgrade";
    }
}

关键配置说明:

配置作用
try_files $uri $uri/ /index.htmlVue3 前端路由(刷新不 404)
proxy_pass .../jeecg-boot/把 /jeecgboot/ 转发到后端
X-Real-IP / X-Forwarded-For后端能拿到真实客户端 IP
Upgrade / ConnectionWebSocket 协议升级

重载配置:

/usr/local/nginx/sbin/nginx -t
systemctl reload nginx

八、验证

8.1 服务状态

systemctl is-enabled nginx
systemctl is-active nginx

8.2 端口和版本

ss -lntp | grep ':80'
/usr/local/nginx/sbin/nginx -v

8.3 HTTP 响应

curl -sI http://127.0.0.1/ | head -3

期望:HTTP/1.1 200 OK

8.4 进程权限

ps -ef | grep nginx | grep -v grep

期望:master 是 root,worker 是 nginx。

九、踩坑记录

9.1 pcre2-devel 未安装

报错:

./configure: error: the HTTP rewrite module requires the PCRE library.

原因:openEuler 24.03 默认没有 pcre-devel,需要显式装 pcre2-devel。

解决:

dnf install -y pcre2-devel

9.2 Worker 进程属主

现象:ps -ef | grep nginx 看到 worker 属主是 nginx,不是 root。

说明:这是正常且官方推荐的权限模型。master 是 root(绑特权端口),worker 降权到 nginx。看到 worker 是 nginx 用户不用惊慌。

9.3 配置重载 vs 重启

# 修改配置后,优先用 reload(不断连接)
systemctl reload nginx

# 只有换二进制、改监听端口才需要 restart
systemctl restart nginx

reload 的原理:master 进程读新配置,启动新 worker,旧 worker 处理完当前请求后退出。用户无感知。

十、总结

Nginx 1.28 部署完成:

  • ✅ 源码编译,15+ 模块全启用
  • ✅ master/worker 官方权限模型
  • ✅ systemd 服务,开机自启
  • ✅ JeecgBoot 反向代理配置就绪(等后端启动后生效)
  • ✅ 版本 1.28.3

关键理解:

  • master 用 root 是必须的(绑 80/443)
  • worker 降权到 nginx 是官方推荐的
  • WebSocket 反代配置不能省,否则 JeecgBoot 消息推送失效

下一篇部署 PostgreSQL 17 + pgvector。


项目地址:https://gitee.com/dboru/jeecgboot-pg-converter

本系列文章:

Logo

openEuler 是由开放原子开源基金会孵化的全场景开源操作系统项目,面向数字基础设施四大核心场景(服务器、云计算、边缘计算、嵌入式),全面支持 ARM、x86、RISC-V、loongArch、PowerPC、SW-64 等多样性计算架构

更多推荐