Nginx 1.28 源码编译与反向代理配置(openEuler 24.03 信创环境)
一、本篇目标
前一篇完成了 Redis 部署。本篇开始部署第二个核心依赖 —— Nginx。
Nginx 在 JeecgBoot 前后端分离架构中承担:
- 前端静态资源服务(Vue3 编译产物)
- 后端接口反向代理(
/jeecgboot/→127.0.0.1:8080) - WebSocket 支持(JeecgBoot 消息推送)
- HTTPS 终止(如果启用)
本篇完成:
- Nginx 1.28.3 源码编译
- 15+ 模块启用
- master/worker 权限模型
- systemd 服务
- JeecgBoot 反向代理配置模板
二、为什么源码编译
Nginx 安装方式的对比:
| 方式 | 优点 | 缺点 |
|---|---|---|
| 系统包(dnf install) | 简单 | 版本旧、模块固定、路径分散 |
| 官方源(nginx.org) | 版本新 | 和系统包混装容易冲突 |
| 源码编译 | 模块可控、自包含 | 需 2-3 分钟编译 |
选源码编译的理由:
- 二进制、配置、html 都在
/usr/local/nginx,一目了然 - 可精确启用所需模块
- 重装系统后从
/data/packages/nginx/解压即恢复
版本选择:Nginx 1.28.x 是最新稳定版(偶数版本),本次用 1.28.3。
三、编译环境
3.1 依赖安装
Nginx 源码编译需要三个核心库:
dnf install -y pcre2-devel zlib-devel openssl-devel
说明:
| 包 | 用途 |
|---|---|
| pcre2-devel | rewrite 正则表达式 |
| zlib-devel | gzip 压缩 |
| openssl-devel | SSL/TLS(HTTPS) |
3.2 下载源码
cd /data/packages
VERSION=1.28.3
wget https://mirrors.huaweicloud.com/nginx/nginx-${VERSION}.tar.gz
3.3 configure
cd /usr/local/src
tar -xzf /data/packages/nginx-1.28.3.tar.gz
cd nginx-1.28.3
./configure \
--prefix=/usr/local/nginx \
--user=nginx \
--group=nginx \
--with-http_ssl_module \
--with-http_v2_module \
--with-http_realip_module \
--with-http_stub_status_module \
--with-http_gzip_static_module \
--with-http_sub_module \
--with-http_dav_module \
--with-http_flv_module \
--with-http_mp4_module \
--with-http_gunzip_module \
--with-http_auth_request_module \
--with-http_random_index_module \
--with-http_secure_link_module \
--with-http_slice_module \
--with-stream \
--with-stream_ssl_module \
--with-stream_realip_module \
--with-threads \
--with-file-aio \
--with-pcre \
--with-pcre-jit
关键模块说明:
| 模块 | 用途 |
|---|---|
| http_ssl_module | HTTPS |
| http_v2_module | HTTP/2 |
| http_realip_module | 获取真实客户端 IP(前置 CDN/负载均衡时) |
| http_stub_status_module | 状态页监控 |
| http_gzip_static_module | 读取预压缩的 .gz 文件 |
| http_sub_module | 响应内容替换 |
| http_auth_request_module | 子请求鉴权(对接 JeecgBoot Token 校验) |
| stream | TCP/UDP 代理 |
| threads | 线程池(大文件 IO) |
| file_aio | 异步文件 IO |
3.4 编译安装
make -j$(nproc)
make install
# 属主
chown -R nginx:nginx /usr/local/nginx
# 版本验证
/usr/local/nginx/sbin/nginx -v
期望:nginx version: nginx/1.28.3
四、权限模型(重点)
Nginx 官方推荐的安全模式:
master 进程(root) → 绑定 80/443 特权端口
worker 进程(nginx) → 处理实际请求
为什么这么设计:
- 只有 master 用 root,权限最小化
- worker 降权到 nginx 用户,即使有漏洞也不扩散
- 不需要 setcap,这是官方标准做法
验证:
ps -ef | grep nginx | grep -v grep
期望:
root 2213 ... nginx: master process /usr/local/nginx/sbin/nginx
nginx 2214 ... nginx: worker process
五、测试启动
# 检查配置
/usr/local/nginx/sbin/nginx -t
# 启动
/usr/local/nginx/sbin/nginx
# 看端口
ss -lntp | grep ':80'
# 访问
curl -sI http://127.0.0.1/ | head -3
# 停掉(后面用 systemd)
/usr/local/nginx/sbin/nginx -s stop
期望:HTTP/1.1 200 OK
六、systemd 服务
cat > /etc/systemd/system/nginx.service <<'EOF'
[Unit]
Description=The nginx HTTP and reverse proxy server
After=network.target remote-fs.target nss-lookup.target
[Service]
Type=forking
PIDFile=/usr/local/nginx/logs/nginx.pid
ExecStartPre=/usr/local/nginx/sbin/nginx -t
ExecStart=/usr/local/nginx/sbin/nginx
ExecReload=/usr/local/nginx/sbin/nginx -s reload
ExecStop=/usr/local/nginx/sbin/nginx -s quit
PrivateTmp=true
Restart=on-failure
RestartSec=5
[Install]
WantedBy=multi-user.target
EOF
systemctl daemon-reload
systemctl enable --now nginx
systemctl status nginx
注意:
Type=forking,因为 Nginx 是 master/worker 模式ExecStartPre每次启动前自动检查配置ExecReload支持热重载PrivateTmp=true使用独立临时目录
七、JeecgBoot 反向代理配置
这是本篇的核心 —— 为 JeecgBoot 前后端分离架构配置反代。
在 /usr/local/nginx/conf/nginx.conf 的 http {} 块内添加:
server {
listen 80;
server_name _;
# 前端静态文件
root /usr/local/jeecg/frontend;
index index.html;
# Vue3 SPA 路由
location / {
try_files $uri $uri/ /index.html;
}
# 后端接口反向代理
location /jeecgboot/ {
proxy_pass http://127.0.0.1:8080/jeecg-boot/;
proxy_redirect off;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
# WebSocket 支持(JeecgBoot 消息推送必需)
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "upgrade";
}
}
关键配置说明:
| 配置 | 作用 |
|---|---|
try_files $uri $uri/ /index.html | Vue3 前端路由(刷新不 404) |
proxy_pass .../jeecg-boot/ | 把 /jeecgboot/ 转发到后端 |
X-Real-IP / X-Forwarded-For | 后端能拿到真实客户端 IP |
Upgrade / Connection | WebSocket 协议升级 |
重载配置:
/usr/local/nginx/sbin/nginx -t
systemctl reload nginx
八、验证
8.1 服务状态
systemctl is-enabled nginx
systemctl is-active nginx
8.2 端口和版本
ss -lntp | grep ':80'
/usr/local/nginx/sbin/nginx -v
8.3 HTTP 响应
curl -sI http://127.0.0.1/ | head -3
期望:HTTP/1.1 200 OK
8.4 进程权限
ps -ef | grep nginx | grep -v grep
期望:master 是 root,worker 是 nginx。
九、踩坑记录
9.1 pcre2-devel 未安装
报错:
./configure: error: the HTTP rewrite module requires the PCRE library.
原因:openEuler 24.03 默认没有 pcre-devel,需要显式装 pcre2-devel。
解决:
dnf install -y pcre2-devel
9.2 Worker 进程属主
现象:ps -ef | grep nginx 看到 worker 属主是 nginx,不是 root。
说明:这是正常且官方推荐的权限模型。master 是 root(绑特权端口),worker 降权到 nginx。看到 worker 是 nginx 用户不用惊慌。
9.3 配置重载 vs 重启
# 修改配置后,优先用 reload(不断连接)
systemctl reload nginx
# 只有换二进制、改监听端口才需要 restart
systemctl restart nginx
reload 的原理:master 进程读新配置,启动新 worker,旧 worker 处理完当前请求后退出。用户无感知。
十、总结
Nginx 1.28 部署完成:
- ✅ 源码编译,15+ 模块全启用
- ✅ master/worker 官方权限模型
- ✅ systemd 服务,开机自启
- ✅ JeecgBoot 反向代理配置就绪(等后端启动后生效)
- ✅ 版本 1.28.3
关键理解:
- master 用 root 是必须的(绑 80/443)
- worker 降权到 nginx 是官方推荐的
- WebSocket 反代配置不能省,否则 JeecgBoot 消息推送失效
下一篇部署 PostgreSQL 17 + pgvector。
项目地址:https://gitee.com/dboru/jeecgboot-pg-converter
本系列文章:
- 第 1 篇:为什么从 3.8.3 升级到 3.9.5
- 第 2 篇:环境准备与数据盘规划
- 第 3 篇:Redis 7.4 源码编译与内核参数调优
- 第 4 篇:Nginx 1.28 源码编译与反向代理配置(本文)
- 第 5 篇:PostgreSQL 17 源码编译 + pgvector + SQL 转换
- 第 6 篇:JeecgBoot 后端编译与 systemd 部署
- 第 7 篇:JeecgBoot 前端编译与 Nginx 部署
- 第 8 篇:部署归档与一键恢复方案
openEuler 是由开放原子开源基金会孵化的全场景开源操作系统项目,面向数字基础设施四大核心场景(服务器、云计算、边缘计算、嵌入式),全面支持 ARM、x86、RISC-V、loongArch、PowerPC、SW-64 等多样性计算架构
更多推荐


所有评论(0)