Nginx日常记录
- [2025-10-20] nginx的代理配置
server { listen 80; location / { proxy_pass http://localhost:3000; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; } }
- [2025-10-20] tls配置
server { listen 443 ssl; server_name your_domain.com; ssl_certificate /path/to/your_certificate.pem; ssl_certificate_key /path/to/your_private.pem; ssl_session_cache shared:SSL:1m; ssl_session_timeout 10m; ssl_ciphers HIGH:!aNULL:!MD5; ssl_prefer_server_ciphers on; location / { root /path/to/your/web/files; index index.html index.htm; } }
顺便贴一个生成密钥对的脚本
openssl ecparam -genkey -name prime256v1 -out key.pem && \ openssl req -new -key key.pem -out cert.csr && \ openssl x509 -req -days 365 -in cert.csr -signkey key.pem -out cert.pem