mirror of
https://github.com/rancher/rancher-docs.git
synced 2026-09-29 14:38:50 +00:00
Make NGINX L7 config generic
This commit is contained in:
committed by
Denise
parent
096084816f
commit
7e7233363d
@@ -138,46 +138,59 @@ Rancher will respond `200` to health checks on the `/healthz` endpoint.
|
|||||||
|
|
||||||
#### Example NGINX config
|
#### Example NGINX config
|
||||||
|
|
||||||
|
This NGINX configuration is tested on NGINX 1.14.
|
||||||
|
|
||||||
|
>**Note:** This NGINX configuration is only an example and may not suit your environment. For complete documentation, see [NGINX Load Balancing - HTTP Load Balancing](https://docs.nginx.com/nginx/admin-guide/load-balancer/http-load-balancer/).
|
||||||
|
|
||||||
* Replace `IP_NODE1`, `IP_NODE2` and `IP_NODE3` with the IP addresses of the nodes in your cluster.
|
* Replace `IP_NODE1`, `IP_NODE2` and `IP_NODE3` with the IP addresses of the nodes in your cluster.
|
||||||
* Replace both occurences of `FQDN` to the DNS name for Rancher.
|
* Replace both occurences of `FQDN` to the DNS name for Rancher.
|
||||||
* Replace `/certs/fullchain.pem` and `/certs/privkey.pem` to the location of the server certificate and the server certificate key respectively.
|
* Replace `/certs/fullchain.pem` and `/certs/privkey.pem` to the location of the server certificate and the server certificate key respectively.
|
||||||
|
|
||||||
```
|
```
|
||||||
upstream rancher {
|
worker_processes 4;
|
||||||
server IP_NODE_1:80;
|
worker_rlimit_nofile 40000;
|
||||||
server IP_NODE_2:80;
|
|
||||||
server IP_NODE_3:80;
|
events {
|
||||||
|
worker_connections 8192;
|
||||||
}
|
}
|
||||||
|
|
||||||
map $http_upgrade $connection_upgrade {
|
http {
|
||||||
default Upgrade;
|
upstream rancher {
|
||||||
'' close;
|
server IP_NODE_1:80;
|
||||||
}
|
server IP_NODE_2:80;
|
||||||
|
server IP_NODE_3:80;
|
||||||
|
}
|
||||||
|
|
||||||
server {
|
map $http_upgrade $connection_upgrade {
|
||||||
listen 443 ssl http2;
|
default Upgrade;
|
||||||
server_name FQDN;
|
'' close;
|
||||||
ssl_certificate /certs/fullchain.pem;
|
}
|
||||||
ssl_certificate_key /certs/privkey.pem;
|
|
||||||
|
|
||||||
location / {
|
server {
|
||||||
proxy_set_header Host $host;
|
listen 443 ssl http2;
|
||||||
proxy_set_header X-Forwarded-Proto $scheme;
|
server_name FQDN;
|
||||||
proxy_set_header X-Forwarded-Port $server_port;
|
ssl_certificate /certs/fullchain.pem;
|
||||||
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
ssl_certificate_key /certs/privkey.pem;
|
||||||
proxy_pass http://rancher;
|
|
||||||
proxy_http_version 1.1;
|
|
||||||
proxy_set_header Upgrade $http_upgrade;
|
|
||||||
proxy_set_header Connection $connection_upgrade;
|
|
||||||
# This allows the ability for the execute shell window to remain open for up to 15 minutes. Without this parameter, the default is 1 minute and will automatically close.
|
|
||||||
proxy_read_timeout 900s;
|
|
||||||
proxy_buffering off;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
server {
|
location / {
|
||||||
listen 80;
|
proxy_set_header Host $host;
|
||||||
server_name FQDN;
|
proxy_set_header X-Forwarded-Proto $scheme;
|
||||||
return 301 https://$server_name$request_uri;
|
proxy_set_header X-Forwarded-Port $server_port;
|
||||||
|
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
||||||
|
proxy_pass http://rancher;
|
||||||
|
proxy_http_version 1.1;
|
||||||
|
proxy_set_header Upgrade $http_upgrade;
|
||||||
|
proxy_set_header Connection $connection_upgrade;
|
||||||
|
# This allows the ability for the execute shell window to remain open for up to 15 minutes. Without this parameter, the default is 1 minute and will automatically close.
|
||||||
|
proxy_read_timeout 900s;
|
||||||
|
proxy_buffering off;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
server {
|
||||||
|
listen 80;
|
||||||
|
server_name FQDN;
|
||||||
|
return 301 https://$server_name$request_uri;
|
||||||
|
}
|
||||||
}
|
}
|
||||||
```
|
```
|
||||||
|
|||||||
+45
-32
@@ -96,45 +96,58 @@ The load balancer or proxy has to be configured to support the following:
|
|||||||
|
|
||||||
### Example Nginx configuration
|
### Example Nginx configuration
|
||||||
|
|
||||||
This layer 7 Nginx configuration is tested on Nginx version 1.13 (mainline) and 1.14 (stable).
|
This NGINX configuration is tested on NGINX 1.14.
|
||||||
|
|
||||||
>**Note:** This Nginx configuration is only an example and may not suit your environment. For complete documentation, see [NGINX Load Balancing - TCP and UDP Load Balancer](https://docs.nginx.com/nginx/admin-guide/load-balancer/tcp-udp-load-balancer/).
|
>**Note:** This Nginx configuration is only an example and may not suit your environment. For complete documentation, see [NGINX Load Balancing - HTTP Load Balancing](https://docs.nginx.com/nginx/admin-guide/load-balancer/http-load-balancer/).
|
||||||
|
|
||||||
|
* Replace `rancher-server` with the IP address or hostname of the node running the Rancher container.
|
||||||
|
* Replace both occurences of `FQDN` to the DNS name for Rancher.
|
||||||
|
* Replace `/certs/fullchain.pem` and `/certs/privkey.pem` to the location of the server certificate and the server certificate key respectively.
|
||||||
|
|
||||||
```
|
```
|
||||||
upstream rancher {
|
worker_processes 4;
|
||||||
server rancher-server:80;
|
worker_rlimit_nofile 40000;
|
||||||
|
|
||||||
|
events {
|
||||||
|
worker_connections 8192;
|
||||||
}
|
}
|
||||||
|
|
||||||
map $http_upgrade $connection_upgrade {
|
http {
|
||||||
default Upgrade;
|
upstream rancher {
|
||||||
'' close;
|
server rancher-server:80;
|
||||||
}
|
|
||||||
|
|
||||||
server {
|
|
||||||
listen 443 ssl http2;
|
|
||||||
server_name rancher.yourdomain.com;
|
|
||||||
ssl_certificate /etc/your_certificate_directory/fullchain.pem;
|
|
||||||
ssl_certificate_key /etc/your_certificate_directory/privkey.pem;
|
|
||||||
|
|
||||||
location / {
|
|
||||||
proxy_set_header Host $host;
|
|
||||||
proxy_set_header X-Forwarded-Proto $scheme;
|
|
||||||
proxy_set_header X-Forwarded-Port $server_port;
|
|
||||||
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
|
||||||
proxy_pass http://rancher;
|
|
||||||
proxy_http_version 1.1;
|
|
||||||
proxy_set_header Upgrade $http_upgrade;
|
|
||||||
proxy_set_header Connection $connection_upgrade;
|
|
||||||
# This allows the ability for the execute shell window to remain open for up to 15 minutes. Without this parameter, the default is 1 minute and will automatically close.
|
|
||||||
proxy_read_timeout 900s;
|
|
||||||
proxy_buffering off;
|
|
||||||
}
|
}
|
||||||
}
|
|
||||||
|
|
||||||
server {
|
map $http_upgrade $connection_upgrade {
|
||||||
listen 80;
|
default Upgrade;
|
||||||
server_name rancher.yourdomain.com;
|
'' close;
|
||||||
return 301 https://$server_name$request_uri;
|
}
|
||||||
|
|
||||||
|
server {
|
||||||
|
listen 443 ssl http2;
|
||||||
|
server_name FQDN;
|
||||||
|
ssl_certificate /certs/fullchain.pem;
|
||||||
|
ssl_certificate_key /certs/privkey.pem;
|
||||||
|
|
||||||
|
location / {
|
||||||
|
proxy_set_header Host $host;
|
||||||
|
proxy_set_header X-Forwarded-Proto $scheme;
|
||||||
|
proxy_set_header X-Forwarded-Port $server_port;
|
||||||
|
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
||||||
|
proxy_pass http://rancher;
|
||||||
|
proxy_http_version 1.1;
|
||||||
|
proxy_set_header Upgrade $http_upgrade;
|
||||||
|
proxy_set_header Connection $connection_upgrade;
|
||||||
|
# This allows the ability for the execute shell window to remain open for up to 15 minutes. Without this parameter, the default is 1 minute and will automatically close.
|
||||||
|
proxy_read_timeout 900s;
|
||||||
|
proxy_buffering off;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
server {
|
||||||
|
listen 80;
|
||||||
|
server_name FQDN;
|
||||||
|
return 301 https://$server_name$request_uri;
|
||||||
|
}
|
||||||
}
|
}
|
||||||
```
|
```
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user