1. 多域名多证书配置的核心价值
在Web服务部署中,经常需要在一台服务器上承载多个独立域名的服务。传统方案是为每个域名单独部署服务器,但这会造成资源浪费和管理成本上升。Nginx的Server Block功能允许我们通过单一服务实例实现多域名的独立配置,每个域名可以拥有独立的SSL证书和内容策略。
我管理过多个电商项目的服务器架构,其中有个典型案例需要同时运行主站、管理后台和API服务三个独立域名。通过Nginx的多域名配置,不仅节省了60%的服务器成本,还简化了证书更新和配置管理工作。这种方案特别适合中小型项目初期部署,以及需要隔离测试/生产环境的企业场景。
需要模型API调用? 免费领10W Token,多模型网关一键接入 Claude、DeepSeek 等主流模型。
2. 基础环境准备与安装
2.1 系统环境要求
推荐使用Ubuntu 20.04 LTS或CentOS 8作为基础系统。关键组件包括:
- Nginx 1.18+(支持TLS 1.3)
- OpenSSL 1.1.1+
- 至少2个已解析到服务器IP的域名
安装Nginx的核心命令:
bash复制# Ubuntu/Debian
sudo apt update
sudo apt install nginx -y
# CentOS/RHEL
sudo yum install epel-release
sudo yum install nginx -y
2.2 证书申请最佳实践
建议使用Let's Encrypt的certbot工具自动化证书管理:
bash复制sudo apt install certbot python3-certbot-nginx -y
certbot --nginx -d example.com -d www.example.com
证书存放路径通常为:
- /etc/letsencrypt/live/example.com/fullchain.pem
- /etc/letsencrypt/live/example.com/privkey.pem
重要提示:生产环境务必设置证书自动续期
bash复制sudo crontab -e
# 添加以下内容
0 12 * * * /usr/bin/certbot renew --quiet
3. 多服务配置实战
3.1 基础配置结构
Nginx的主配置文件位于/etc/nginx/nginx.conf,我们主要通过包含conf.d目录下的独立配置文件来管理多域名:
code复制/etc/nginx/
├── nginx.conf
├── conf.d/
│ ├── example.com.conf
│ ├── api.example.com.conf
│ └── admin.example.com.conf
└── snippets/
└── ssl-params.conf
典型配置文件示例(/etc/nginx/conf.d/example.com.conf):
nginx复制server {
listen 80;
server_name example.com www.example.com;
return 301 https://$server_name$request_uri;
}
server {
listen 443 ssl http2;
server_name example.com www.example.com;
ssl_certificate /etc/letsencrypt/live/example.com/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/example.com/privkey.pem;
include snippets/ssl-params.conf;
root /var/www/example.com;
index index.html;
location / {
try_files $uri $uri/ =404;
}
}
3.2 高级配置技巧
3.2.1 负载均衡配置
nginx复制upstream backend {
server 127.0.0.1:8000;
server 127.0.0.1:8001;
keepalive 32;
}
server {
location /api/ {
proxy_pass http://backend;
proxy_http_version 1.1;
proxy_set_header Connection "";
}
}
3.2.2 静态资源优化
nginx复制location ~* \.(jpg|jpeg|png|gif|ico|css|js)$ {
expires 365d;
add_header Cache-Control "public, no-transform";
access_log off;
}
4. 性能调优与安全加固
4.1 SSL参数优化
创建/etc/nginx/snippets/ssl-params.conf:
nginx复制ssl_protocols TLSv1.2 TLSv1.3;
ssl_prefer_server_ciphers on;
ssl_ciphers "EECDH+AESGCM:EDH+AESGCM:AES256+EECDH:AES256+EDH";
ssl_ecdh_curve secp384r1;
ssl_session_cache shared:SSL:10m;
ssl_session_tickets off;
ssl_stapling on;
ssl_stapling_verify on;
resolver 8.8.8.8 8.8.4.4 valid=300s;
resolver_timeout 5s;
add_header Strict-Transport-Security "max-age=63072000; includeSubDomains; preload";
add_header X-Frame-Options DENY;
add_header X-Content-Type-Options nosniff;
add_header X-XSS-Protection "1; mode=block";
4.2 连接数优化
在/etc/nginx/nginx.conf的events块中添加:
nginx复制events {
worker_connections 4096;
multi_accept on;
use epoll;
}
http块中添加:
nginx复制http {
keepalive_timeout 30;
keepalive_requests 1000;
sendfile on;
tcp_nopush on;
tcp_nodelay on;
}
5. 常见问题排查指南
5.1 证书加载失败
检查步骤:
- 确认证书路径权限:
bash复制sudo chmod 755 /etc/letsencrypt/{live,archive}
- 检查Nginx错误日志:
bash复制sudo tail -f /var/log/nginx/error.log
- 测试配置语法:
bash复制sudo nginx -t
5.2 413 Request Entity Too Large
在http或server块中添加:
nginx复制client_max_body_size 100M;
5.3 502 Bad Gateway
可能原因及解决方案:
- 后端服务未运行:
bash复制sudo systemctl status your-backend-service
- 防火墙阻止:
bash复制sudo ufw allow 8000/tcp
- 代理设置错误:
nginx复制proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
6. 监控与维护
6.1 状态监控配置
启用Nginx status模块:
nginx复制server {
location /nginx_status {
stub_status on;
access_log off;
allow 127.0.0.1;
deny all;
}
}
监控指标示例:
- Active connections
- Requests per second
- Connection states (reading/writing/waiting)
6.2 日志分析技巧
使用goaccess进行实时分析:
bash复制sudo apt install goaccess
goaccess /var/log/nginx/access.log --log-format=COMBINED
关键日志字段分析:
- $remote_addr 客户端IP
- $time_local 访问时间
- $request 请求内容
- $status 响应状态码
- $body_bytes_sent 发送字节数
- $http_referer 来源页面
- $http_user_agent 客户端设备信息
7. 高级应用场景
7.1 灰度发布配置
基于Cookie的流量分割:
nginx复制split_clients "${remote_addr}${http_user_agent}" $variant {
10% "v2";
* "v1";
}
server {
location / {
if ($variant = "v2") {
proxy_pass http://new_version;
}
proxy_pass http://current_version;
}
}
7.2 地理限制访问
使用GeoIP模块:
nginx复制geo $allowed_country {
default no;
CN yes;
US yes;
JP yes;
}
server {
if ($allowed_country = no) {
return 403;
}
}
安装GeoIP数据库:
bash复制sudo apt install libmaxminddb-dev
sudo nginx -V # 确认包含--with-http_geoip_module
8. 配置版本控制方案
建议采用Git管理Nginx配置:
bash复制cd /etc/nginx
sudo git init
sudo git add .
sudo git commit -m "Initial nginx config"
创建部署脚本deploy.sh:
bash复制#!/bin/bash
sudo nginx -t && sudo systemctl reload nginx
git add .
git commit -m "$(date +'%Y-%m-%d %H:%M') config update"
git push origin master
关键提示:每次修改配置后必须测试语法
bash复制sudo nginx -t && sudo systemctl reload nginx
