puppet连载12:linux安装nginx、openresty

简介: 服务端在/puppet/soft 里建nginx1102setup.sh,内容:!/bin/bashyum -y install wget libtool expat-devel gcc gcc-c++ glibc automake autocon...

服务端在/puppet/soft 里建nginx1102setup.sh,内容:

!/bin/bash

yum -y install wget libtool expat-devel gcc gcc-c++ glibc automake autoconf libtool make libmcrypt-devel mhash-devel libxslt-devel libjpeg libjpeg-devel libpng libpng-devel freetype freetype-devel libxml2 libxml2-devel glibc glibc-devel glib2 glib2-devel bzip2 bzip2-devel ncurses ncurses-devel curl curl-devel e2fsprogs e2fsprogs-devel krb5 krb5-devel libidn libidn-devel openssl openssl-devel

cd /data
wget https://ftp.pcre.org/pub/pcre/pcre-8.39.tar.gz
tar -zxvf pcre-8.39.tar.gz
cd pcre-8.39
./configure
make && make install

cd /data
wget http://zlib.net/zlib-1.2.11.tar.gz
tar -zxvf zlib-1.2.11.tar.gz
cd zlib-1.2.11
./configure
make && make install

cd /data
wget https://www.openssl.org/source/openssl-1.1.0b.tar.gz
tar -zxvf openssl-1.1.0b.tar.gz
cd openssl-1.1.0b
./config
make && make install

cd /data
wget http://nginx.org/download/nginx-1.10.2.tar.gz
tar -zxvf nginx-1.10.2.tar.gz
cd nginx-1.10.2
groupadd -r nginx
useradd -r -g nginx nginx
./configure --prefix=/data/nginx --sbin-path=/data/nginx/sbin/nginx --conf-path=/data/nginx/nginx.conf --pid-path=/data/nginx/logs/nginx.pid --user=nginx --group=nginx --with-http_ssl_module --with-http_flv_module --with-http_mp4_module --with-http_stub_status_module --with-http_gzip_static_module --http-client-body-temp-path=/var/tmp/nginx/client/ --http-proxy-temp-path=/var/tmp/nginx/proxy/ --http-fastcgi-temp-path=/var/tmp/nginx/fcgi/ --http-uwsgi-temp-path=/var/tmp/nginx/uwsgi --http-scgi-temp-path=/var/tmp/nginx/scgi --with-pcre=/data/pcre-8.39 --with-zlib=/data/zlib-1.2.11 --with-openssl=/data/openssl-1.1.0b
make && make install
mkdir -p /var/tmp/nginx/client
mkdir -p /data/nginx/logs

/data/nginx/sbin/nginx

firewall-cmd --add-port=80/tcp --permanent
firewall-cmd --add-port=443/tcp --permanent
firewall-cmd --reload

mkdir -p /data/soft
mv /data/nginx-1.10.2* /data/soft
mv /data/*.tar.gz /data/soft

保存,退出。 chmod +x /puppet/soft/nginx1102setup.sh


在服务端/puppet/soft 里建 openresty1136setup.sh,内容:

!/bin/bash

yum install -y gcc gcc-c++ zlib-devel pcre-devel openssl-devel readline-devel
cd /data
wget https://openresty.org/download/openresty-1.13.6.2.tar.gz
tar -zxvf openresty-1.13.6.2.tar.gz
cd openresty-1.13.6.2
./configure --prefix=/data/openresty
--user=nginx --group=nginx
--with-http_ssl_module
--with-http_flv_module
--with-http_stub_status_module
--with-http_gzip_static_module
--with-pcre
--with-http_realip_module
gmake && gmake install

firewall-cmd --add-port=80/tcp --permanent
firewall-cmd --add-port=443/tcp --permanent
firewall-cmd --reload

mkdir -p /data/soft
mv /data/openresty-1.13.6.2.tar.gz /data/soft
mkdir -p /data/openresty/nginx/conf.d

/data/openresty/nginx/sbin/nginx

保存退出, chmod +x openresty1136setup.sh


在服务端建立erb文件,/etc/puppet/modules/linuxnginx/templates/nginx.conf.erb,内容:

user <%= real_nginx_user %>;
worker_processes <%= processorcount %>;
error_log /data/nginx/logs/nginx_error.log crit;
pid /data/nginx/logs/nginx.pid;

events {
use epoll;
worker_connections 51200;
}

http {
include /data/nginx/mime.types;
default_type application/octet-stream;
log_format main 'remote_addr -remote_user [time_local] "request"'
'statusbody_bytes_sent "http_referer"' '"http_user_agent" "$http_x_forwarded_for"';
access_log /data/nginx/logs/nginx_access.log main;

server_names_hash_bucket_size 128;
client_header_buffer_size 32k;
large_client_header_buffers 4 32k;
client_body_buffer_size 8m;

sendfile on;

keepalive_timeout 0;

tcp_nopush on;
tcp_nodelay on;
client_max_body_size 50m;

ssi on;
ssi_types text/shtml;
fastcgi_intercept_errors on;
proxy_intercept_errors on;
fastcgi_connect_timeout 1200;
fastcgi_send_timeout 1200;
fastcgi_read_timeout 1200;
fastcgi_buffer_size 128k;
fastcgi_buffers 8 128k;
fastcgi_busy_buffers_size 256k;
fastcgi_temp_file_write_size 256k;

ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
send_timeout 1200;
proxy_connect_timeout 1200;
proxy_read_timeout 1200;
proxy_send_timeout 1200;

gzip on;
gzip_proxied any;
gzip_http_version 1.0;
gzip_vary on;
gzip_comp_level 6;
gzip_min_length 2k;
gzip_buffers 4 16k;
gzip_types text/plain text/css application/json application/x-javascript application/xml text/javascript image/jpeg image/gif image/png application/x-shockwave-flash;
gzip_disable “MSIE [1-6].(?!.*SV1)”;

include /data/nginx/conf.d/*.conf;
}


在服务端建立nginx_logrote.sh

mkdir -p /puppet/soft/nginx/huangat-test/
vi /puppet/soft/nginx/huangat-test/nginx_logrote.sh

!/bin/bash

logs_path="/data/nginx/logs/"
PIDFILE=/data/nginx/nginx.pid
ACCESS_LOG="{logs_path}(date -d "yesterday" +"%Y")/(date -d "yesterday" +"%m")/nginx_access_(date -d "yesterday" +"%Y%m%d").log"
ERROR_LOG="{logs_path}(date -d "yesterday" +"%Y")/(date -d "yesterday" +"%m")/nginx_access_(date -d "yesterday" +"%Y%m%d").log"

mkdir -p {logs_path}(date -d "yesterday" +"%Y")/$(date -d "yesterday" +"%m")/

mv {logs_path}nginx_access.logACCESS_LOG
mv {logs_path}nginx_error.logERROR_LOG

kill -USR1 cat $PIDFILE

/bin/gzip -9 ACCESS_LOG /bin/gzip -9ERROR_LOG

find ${logs_path} -name "*.log.gz" -mtime +30|xargs rm -f

保存退出


在服务端建conf.d文件夹,/puppet/soft/nginx/huangat-test/conf.d

mkdir -p /puppet/soft/nginx/huangat-test/conf.d
vi /puppet/soft/nginx/huangat-test/conf.d/huangat-test.conf
server {
listen 80;
server_name huangat-test;
root /var/www/huangat-test;

location /nginx_status {
stub_status on;
access_log off;
}
}


在服务端建立conf.d文件夹:mkdir -p /puppet/soft/openresty/pai2/nginx/conf.d
vi /puppet/soft/openresty/pai2/nginx/conf.d/api2.conf
server {
listen 80;
server_name api2;
root /var/www/api2;

location /nginx_status {
stub_status on;
access_log off;
}
}

在服务端建立nginx_logrote.sh

vi /puppet/soft/openresty/api2/nginx/nginx_logrote.sh

!/bin/bash

logs_path="/data/openresty/nginx/logs/"
PIDFILE=/data/openresty/nginx/nginx.pid
ACCESS_LOG="{logs_path}(date -d "yesterday" +"%Y")/(date -d "yesterday" +"%m")/nginx_access_(date -d "yesterday" +"%Y%m%d").log"
ERROR_LOG="{logs_path}(date -d "yesterday" +"%Y")/(date -d "yesterday" +"%m")/nginx_access_(date -d "yesterday" +"%Y%m%d").log"

mkdir -p {logs_path}(date -d "yesterday" +"%Y")/$(date -d "yesterday" +"%m")/

mv {logs_path}nginx_access.logACCESS_LOG
mv {logs_path}nginx_error.logERROR_LOG

kill -USR1 cat $PIDFILE

/bin/gzip -9 ACCESS_LOG /bin/gzip -9ERROR_LOG

find ${logs_path} -name "*.log.gz" -mtime +30|xargs rm -f

在服务端建立erb文件,/etc/puppet/modules/linuxnginx/templates/openresty.nginx.conf.erb,内容:

user <%= real_nginx_user %>;
worker_processes <%= processorcount %>;
error_log /data/openresty/nginx/logs/nginx_error.log crit;
pid /data/openresty/nginx/logs/nginx.pid;

events {
use epoll;
worker_connections 51200;
}

http {
default_type application/octet-stream;
log_format main 'remote_addr -remote_user [time_local] "request"'
'statusbody_bytes_sent "http_referer"' '"http_user_agent" "$http_x_forwarded_for"';
access_log /data/openresty/nginx/logs/nginx_access.log main;

server_names_hash_bucket_size 128;
client_header_buffer_size 32k;
large_client_header_buffers 4 32k;
client_body_buffer_size 8m;

sendfile on;

keepalive_timeout 0;

tcp_nopush on;
tcp_nodelay on;
client_max_body_size 50m;

ssi on;
ssi_types text/shtml;
fastcgi_intercept_errors on;
proxy_intercept_errors on;
fastcgi_connect_timeout 1200;
fastcgi_send_timeout 1200;
fastcgi_read_timeout 1200;
fastcgi_buffer_size 128k;
fastcgi_buffers 8 128k;
fastcgi_busy_buffers_size 256k;
fastcgi_temp_file_write_size 256k;

ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
send_timeout 1200;
proxy_connect_timeout 1200;
proxy_read_timeout 1200;
proxy_send_timeout 1200;

gzip on;
gzip_proxied any;
gzip_http_version 1.0;
gzip_vary on;
gzip_comp_level 6;
gzip_min_length 2k;
gzip_buffers 4 16k;
gzip_types text/plain text/css application/json application/x-javascript application/xml text/javascript image/jpeg image/gif image/png application/x-shockwave-flash;
gzip_disable “MSIE [1-6].(?!.*SV1)”;

include /data/openresty/nginx/conf.d/*.conf;
}


安装nginx1.10.2、openresty1.13.6,两者不能同时装

mkdir -p /etc/puppet/modules/linuxnginx/{manifests,templates,files}
vi /etc/puppet/modules/linuxnginx/manifests/init.pp
class linuxnginx::nginx1102 {

real_nginx_user =nginx_user ? {'' => 'nginx',default => nginx_user }nginx_conf = "/data/nginx/conf.d"
$nginx_logrote = "/data/nginx/conf.d/nginx_logrote.sh"

file {"/data/nginx.sh":
ensure => present,
source => "puppet:///soft/nginx1102setup.sh",
}
exec {"nginxsetup":
command => "bash /data/nginx.sh",
cwd => "/data",
user => root,
provider => shell,
logoutput => true,
timeout => 1800,
require => File["/data/nginx.sh"],
unless => "ls /data/nginx",
}
file {'nginx.conf':
ensure => present,
mode => 644,owner => root,group => root,
path => "/data/nginx/nginx.conf",
content => template('/etc/puppet/modules/linuxnginx/templates/nginx.conf.erb'),
notify => Exec["reload-nginx"],
require => Exec["nginxsetup"],
}
exec { 'reload-nginx':
command => "/data/nginx/sbin/nginx -s reload",
refreshonly => true,
}
file {nginx_conf: ensure => directory, recurse => true, purge => false, source => "puppet:///soft/nginx/hostname/conf.d",
notify => Exec["reload-nginx"],
require => Exec["nginxsetup"],
}
file { nginx_logrote: ensure => file, mode => 755,owner => root,group => root, source => "puppet:///soft/nginx/hostname/nginx_logrote.sh",
}
cron {"nginx_logrote_cron":
command => "/bin/bash $nginx_logrote > /dev/null 2>&1",
user => root,minute => '0',hour => '0',
}
}

class linuxnginx::openresty1136 {

real_nginx_user =nginx_user ? {'' => 'nginx',default => nginx_user }nginx_conf = "/data/openresty/nginx/conf.d"
$nginx_logrote = "/data/openresty/nginx/conf.d/nginx_logrote.sh"

file {"/data/openresty.sh":
ensure => present,
source => "puppet:///soft/openresty1136setup.sh",
}
exec {"openrestysetup":
command => "bash /data/openresty.sh",
cwd => "/data",
user => root,
provider => shell,
timeout => 1800,
logoutput => true,
require => File["/data/openresty.sh"],
unless => "ls /data/openresty",
}
file {'nginx.conf':
ensure => present,
mode => 644,owner => root,group => root,
path => "/data/openresty/nginx/conf/nginx.conf",
content => template('/etc/puppet/modules/linuxnginx/templates/openresty.nginx.conf.erb'),
notify => Exec["reload-nginx"],
require => Exec["openrestysetup"],
}
exec { 'reload-nginx':
command => "/data/openresty/nginx/sbin/nginx -s reload",
refreshonly => true,
}
file {nginx_conf: ensure => directory, recurse => true, purge => false, source => "puppet:///soft/openresty/hostname/nginx/conf.d",
notify => Exec["reload-nginx"],
require => Exec["openrestysetup"],
}
file { nginx_logrote: ensure => file, mode => 755,owner => root,group => root, source => "puppet:///soft/openresty/hostname/nginx/nginx_logrote.sh",
}
cron {"nginx_logrote_cron":
command => "/bin/bash $nginx_logrote > /dev/null 2>&1",
user => root,minute => '0',hour => '0',
}
}

vi /etc/puppet/manifests/nodes/huangat-test.pp
node 'huangat-test' {
include linuxnginx::nginx1102
}
node 'api2' {
include linuxnginx::openresty1136
}

目录
相关文章
|
25天前
|
应用服务中间件 Linux nginx
【Azure App Service】基于Linux创建的App Service是否可以主动升级内置的Nginx版本呢?
基于Linux创建的App Service是否可以主动升级内置的Nginx版本呢?Web App Linux 默认使用的 Nginx 版本是由平台预定义的,无法更改这个版本。
134 77
|
5天前
|
缓存 Ubuntu Linux
Linux中yum、rpm、apt-get、wget的区别,yum、rpm、apt-get常用命令,CentOS、Ubuntu中安装wget
通过本文,我们详细了解了 `yum`、`rpm`、`apt-get`和 `wget`的区别、常用命令以及在CentOS和Ubuntu中安装 `wget`的方法。`yum`和 `apt-get`是高层次的包管理器,分别用于RPM系和Debian系发行版,能够自动解决依赖问题;而 `rpm`是低层次的包管理工具,适合处理单个包;`wget`则是一个功能强大的下载工具,适用于各种下载任务。在实际使用中,根据系统类型和任务需求选择合适的工具,可以大大提高工作效率和系统管理的便利性。
54 25
|
21天前
|
Ubuntu Java Linux
Linux 安装 Qualcomm ® SnapdragonTM Profiler
通过本文的详细介绍,您应该已经成功在 Linux 系统上安装并配置了 Qualcomm® Snapdragon™ Profiler,并能够连接 Android 设备进行性能分析。Snapdragon Profiler 提供了丰富的工具和功能,可以帮助开发者深入了解应用程序的性能瓶颈,从而进行优化。希望本文能对您有所帮助,让您在开发过程中更高效地使用 Snapdragon Profiler 进行性能分析和优化。
56 10
|
22天前
|
Linux
Linux安装svn并启动
Linux安装svn并启动
55 10
|
1月前
|
前端开发 应用服务中间件 nginx
docker安装nginx,前端项目运行
通过上述步骤,你可以轻松地在Docker中部署Nginx并运行前端项目。这种方法不仅简化了部署流程,还确保了环境的一致性,提高了开发和运维的效率。确保按步骤操作,并根据项目的具体需求进行相应的配置调整。
148 25
|
1月前
|
Oracle 关系型数据库 Linux
linux8安装oracle 11g遇到的问题记录
Oracle 11g在Linux 8上安装时会遇到link编译环节的问题。官方建议忽略安装中的链接错误,安装完成后应用DBPSU 11.2.0.4.240716补丁及一次性补丁33991024,再重新编译二进制文件,并配置监听器和数据库。但因11g已退出服务期,这些补丁需付费获取。网上信息显示22年1月的PSU补丁也可解决问题,找到该补丁后按常规方式打补丁即可。如有需求或疑问可咨询我。
83 20
|
1月前
|
弹性计算 运维 Ubuntu
os-copilot在Alibaba Cloud Linux镜像下的安装与功能测试
我顺利使用了OS Copilot的 -t -f 功能,我的疑惑是在换行的时候就直接进行提问了,每次只能写一个问题,没法连续换行更有逻辑的输入问题。 我认为 -t 管道 功能有用 ,能解决环境问题的连续性操作。 我认为 -f 管道 功能有用 ,可以单独创建可连续性提问的task问题。 我认为 | 对文件直接理解在新的服务器理解有很大的帮助。 此外,我还有建议 可以在非 co 的环境下也能进行连续性的提问。
79 7
|
2月前
|
Linux Python
Linux 安装python3.7.6
本教程介绍在Linux系统上安装Python 3.7.6的步骤。首先使用`yum`安装依赖环境,包括zlib、openssl等开发库。接着通过`wget`下载Python 3.7.6源码包并解压。创建目标文件夹`/usr/local/python3`后,进入解压目录执行配置、编译和安装命令。最后设置软链接,使`python3`和`pip3`命令生效。
|
2月前
|
Ubuntu Linux
Linux 各发行版安装 ping 命令指南
如何在不同 Linux 发行版(Ubuntu/Debian、CentOS/RHEL/Fedora、Arch Linux、openSUSE、Alpine Linux)上安装 `ping` 命令,详细列出各发行版的安装步骤和验证方法,帮助系统管理员和网络工程师快速排查网络问题。
244 20
|
2月前
|
负载均衡 Ubuntu 应用服务中间件
nginx修改网站默认根目录及发布(linux、centos、ubuntu)openEuler软件源repo站点
通过合理配置 Nginx,我们可以高效地管理和发布软件源,为用户提供稳定可靠的服务。
217 13

热门文章

最新文章