You can not select more than 25 topics
Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
3.8 KiB
3.8 KiB
10.76.108.14 源码安装 nginx-1.26.3(麒麟V10 ARM64)
一、卸载旧版 yum 安装的 Nginx(如存在)
systemctl stop nginx
yum remove nginx nginx-mod-stream -y
二、安装编译依赖
yum install -y gcc gcc-c++ make pcre pcre-devel zlib zlib-devel openssl openssl-devel
三、下载并解压源码
cd /usr/local/src
wget https://nginx.org/download/nginx-1.26.3.tar.gz
tar -zxvf nginx-1.26.3.tar.gz
cd nginx-1.26.3
如服务器无法访问外网,可先在本地下载后通过 scp 上传到
/usr/local/src/目录。
四、配置编译参数
./configure \
--prefix=/etc/nginx \
--sbin-path=/usr/sbin/nginx \
--modules-path=/usr/lib64/nginx/modules \
--conf-path=/etc/nginx/nginx.conf \
--error-log-path=/var/log/nginx/error.log \
--http-log-path=/var/log/nginx/access.log \
--pid-path=/run/nginx.pid \
--lock-path=/var/run/nginx.lock \
--user=nginx \
--group=nginx \
--with-http_ssl_module \
--with-http_v2_module \
--with-http_realip_module \
--with-http_gzip_static_module \
--with-http_stub_status_module \
--with-stream \
--with-stream_ssl_module \
--with-pcre
五、编译并安装
make -j$(nproc)
make install
六、创建 nginx 用户(如不存在)
id nginx 2>/dev/null || (groupadd nginx && useradd -r -g nginx -s /sbin/nologin nginx)
七、验证安装
/usr/sbin/nginx -v
# 应输出: nginx version: nginx/1.26.3
/usr/sbin/nginx -V 2>&1 | grep stream
# 应看到: --with-stream
八、配置 systemd 服务
cat > /usr/lib/systemd/system/nginx.service << 'EOF'
[Unit]
Description=nginx - high performance web server
Documentation=http://nginx.org/en/docs/
After=network-online.target remote-fs.target nss-lookup.target
Wants=network-online.target
[Service]
Type=forking
PIDFile=/run/nginx.pid
ExecStartPre=/usr/sbin/nginx -t -c /etc/nginx/nginx.conf
ExecStart=/usr/sbin/nginx -c /etc/nginx/nginx.conf
ExecReload=/bin/kill -s HUP $MAINPID
ExecStop=/bin/kill -s QUIT $MAINPID
PrivateTmp=true
LimitNOFILE=65535
[Install]
WantedBy=multi-user.target
EOF
九、部署业务配置文件
将业务 nginx.conf 覆盖到配置路径:
# 备份默认配置
cp /etc/nginx/nginx.conf /etc/nginx/nginx.conf.bak
# 上传或编辑业务配置(注意:必须移除 include /usr/share/nginx/modules/*.conf; 这行)
vi /etc/nginx/nginx.conf
重要:源码编译安装后,模块(stream、ssl等)已静态链接到二进制文件中,无需动态加载。 必须移除或注释掉配置文件中的
include /usr/share/nginx/modules/*.conf;否则启动报错。
十、启动并设置开机自启
systemctl daemon-reload
systemctl start nginx
systemctl enable nginx
systemctl status nginx
十一、防火墙设置
firewall-cmd --state
firewall-cmd --list-all
firewall-cmd --add-port={80,85,445,81,12001,12002,12003,12004,12005}/tcp --permanent
firewall-cmd --reload
firewall-cmd --list-all
十二、常用命令
| 操作 | 命令 |
|---|---|
| 测试配置并重载 | /usr/sbin/nginx -t && systemctl reload nginx |
| 查看状态 | systemctl status nginx |
| 启动 | systemctl start nginx |
| 停止 | systemctl stop nginx |
| 查看版本 | /usr/sbin/nginx -v |
| 查看错误日志 | tail -f /var/log/nginx/error.log |
路径说明
| 项目 | 路径 |
|---|---|
| 二进制文件 | /usr/sbin/nginx |
| 配置文件 | /etc/nginx/nginx.conf |
| 日志目录 | /var/log/nginx/ |
| PID 文件 | /run/nginx.pid |
注意事项
- 系统平台:银河麒麟 V10 ARM64 (aarch64)
- nginx 1.26.3 已修复 CVE-2022-41742 安全漏洞
- 配置文件中需添加
server_tokens off;隐藏版本号进行安全加固 - 使用绝对路径
/usr/sbin/nginx调用,因 sudo 的 secure_path 默认不包含 /usr/sbin