Skip to Content
文档服务器Nginx / Apache

Nginx / Apache Web 服务器

本文介绍在 Ubuntu 26.04 上安装和配置两大主流 Web 服务器:Nginx 和 Apache。

Nginx

安装 Nginx

sudo apt update sudo apt install nginx -y # 启动并设置开机自启 sudo systemctl enable --now nginx # 查看状态 sudo systemctl status nginx # 查看版本 nginx -v

防火墙配置

# 允许 HTTP 和 HTTPS sudo ufw allow 'Nginx Full' # 或分别允许 sudo ufw allow 80/tcp sudo ufw allow 443/tcp

目录结构

/etc/nginx/ ├── nginx.conf # 主配置文件 ├── sites-available/ # 可用站点配置 ├── sites-enabled/ # 已启用站点(符号链接) ├── conf.d/ # 额外配置片段 ├── snippets/ # 可复用的配置片段 └── modules-enabled/ # 已启用模块 /var/www/ # 网站根目录 /var/log/nginx/ # 日志目录

虚拟主机配置

# 创建网站目录 sudo mkdir -p /var/www/example.com/html sudo chown -R www-data:www-data /var/www/example.com echo "<h1>Welcome to example.com</h1>" | sudo tee /var/www/example.com/html/index.html # 创建虚拟主机配置 sudo tee /etc/nginx/sites-available/example.com << 'EOF' server { listen 80; listen [::]:80; server_name example.com www.example.com; root /var/www/example.com/html; index index.html index.htm; # 日志 access_log /var/log/nginx/example.com.access.log; error_log /var/log/nginx/example.com.error.log; location / { try_files $uri $uri/ =404; } # 静态资源缓存 location ~* \.(jpg|jpeg|png|gif|ico|css|js|woff2)$ { expires 30d; add_header Cache-Control "public, immutable"; } # 禁止访问隐藏文件 location ~ /\. { deny all; } } EOF # 启用站点 sudo ln -s /etc/nginx/sites-available/example.com /etc/nginx/sites-enabled/ # 移除默认站点(可选) sudo rm /etc/nginx/sites-enabled/default # 测试配置 sudo nginx -t # 重新加载 sudo systemctl reload nginx

反向代理配置

sudo tee /etc/nginx/sites-available/app-proxy << 'EOF' server { listen 80; server_name app.example.com; location / { proxy_pass http://127.0.0.1:3000; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; # WebSocket 支持 proxy_http_version 1.1; proxy_set_header Upgrade $http_upgrade; proxy_set_header Connection "upgrade"; } } EOF sudo ln -s /etc/nginx/sites-available/app-proxy /etc/nginx/sites-enabled/ sudo nginx -t && sudo systemctl reload nginx

Nginx 性能优化

# /etc/nginx/nginx.conf 关键配置 sudo tee /etc/nginx/conf.d/performance.conf << 'EOF' # Gzip 压缩 gzip on; gzip_vary on; gzip_proxied any; gzip_comp_level 5; gzip_min_length 256; gzip_types text/plain text/css text/xml text/javascript application/json application/javascript application/xml application/rss+xml image/svg+xml; # 文件缓存 open_file_cache max=1000 inactive=20s; open_file_cache_valid 30s; open_file_cache_min_uses 2; # 连接优化 keepalive_timeout 65; keepalive_requests 100; EOF sudo nginx -t && sudo systemctl reload nginx

Apache

安装 Apache

sudo apt update sudo apt install apache2 -y # 启动并设置开机自启 sudo systemctl enable --now apache2 # 查看状态 sudo systemctl status apache2 # 查看版本 apache2 -v

防火墙配置

sudo ufw allow 'Apache Full'

目录结构

/etc/apache2/ ├── apache2.conf # 主配置文件 ├── ports.conf # 监听端口 ├── sites-available/ # 可用站点配置 ├── sites-enabled/ # 已启用站点 ├── mods-available/ # 可用模块 ├── mods-enabled/ # 已启用模块 └── conf-available/ # 额外配置 /var/www/ # 网站根目录 /var/log/apache2/ # 日志目录

常用模块管理

# 启用模块 sudo a2enmod rewrite # URL 重写 sudo a2enmod ssl # SSL/TLS sudo a2enmod headers # HTTP 头控制 sudo a2enmod proxy # 反向代理 sudo a2enmod proxy_http # HTTP 代理 sudo a2enmod proxy_wstunnel # WebSocket 代理 # 禁用模块 sudo a2dismod autoindex # 重启生效 sudo systemctl restart apache2

虚拟主机配置

# 创建网站目录 sudo mkdir -p /var/www/example.com/html sudo chown -R www-data:www-data /var/www/example.com echo "<h1>Welcome to example.com</h1>" | sudo tee /var/www/example.com/html/index.html # 创建虚拟主机配置 sudo tee /etc/apache2/sites-available/example.com.conf << 'EOF' <VirtualHost *:80> ServerName example.com ServerAlias www.example.com ServerAdmin admin@example.com DocumentRoot /var/www/example.com/html <Directory /var/www/example.com/html> Options -Indexes +FollowSymLinks AllowOverride All Require all granted </Directory> # 日志 ErrorLog ${APACHE_LOG_DIR}/example.com-error.log CustomLog ${APACHE_LOG_DIR}/example.com-access.log combined </VirtualHost> EOF # 启用站点 sudo a2ensite example.com.conf # 禁用默认站点(可选) sudo a2dissite 000-default.conf # 测试配置 sudo apache2ctl configtest # 重新加载 sudo systemctl reload apache2

反向代理配置

sudo a2enmod proxy proxy_http sudo tee /etc/apache2/sites-available/app-proxy.conf << 'EOF' <VirtualHost *:80> ServerName app.example.com ProxyPreserveHost On ProxyPass / http://127.0.0.1:3000/ ProxyPassReverse / http://127.0.0.1:3000/ # WebSocket 代理 RewriteEngine On RewriteCond %{HTTP:Upgrade} websocket [NC] RewriteCond %{HTTP:Connection} upgrade [NC] RewriteRule ^/?(.*) ws://127.0.0.1:3000/$1 [P,L] ErrorLog ${APACHE_LOG_DIR}/app-proxy-error.log CustomLog ${APACHE_LOG_DIR}/app-proxy-access.log combined </VirtualHost> EOF sudo a2ensite app-proxy.conf sudo apache2ctl configtest && sudo systemctl reload apache2

SSL 证书配置

使用 Let’s Encrypt(Certbot)

# 安装 Certbot sudo apt install certbot -y # Nginx 插件 sudo apt install python3-certbot-nginx -y # Apache 插件 sudo apt install python3-certbot-apache -y

Nginx SSL 配置

# 自动获取并配置证书 sudo certbot --nginx -d example.com -d www.example.com # 测试自动续期 sudo certbot renew --dry-run # 查看证书信息 sudo certbot certificates

Certbot 会自动将 Nginx 配置修改为:

server { listen 443 ssl; listen [::]:443 ssl; http2 on; server_name example.com www.example.com; ssl_certificate /etc/letsencrypt/live/example.com/fullchain.pem; ssl_certificate_key /etc/letsencrypt/live/example.com/privkey.pem; include /etc/letsencrypt/options-ssl-nginx.conf; ssl_dhparam /etc/letsencrypt/ssl-dhparams.pem; # ... 其他配置 } # HTTP 跳转 HTTPS server { listen 80; server_name example.com www.example.com; return 301 https://$host$request_uri; }

Apache SSL 配置

# 启用 SSL 模块 sudo a2enmod ssl # 自动获取并配置证书 sudo certbot --apache -d example.com -d www.example.com

手动 SSL 配置(Nginx)

sudo tee /etc/nginx/snippets/ssl-params.conf << 'EOF' ssl_protocols TLSv1.2 TLSv1.3; ssl_ciphers ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384; ssl_prefer_server_ciphers off; ssl_session_timeout 1d; ssl_session_cache shared:SSL:10m; ssl_session_tickets off; # HSTS add_header Strict-Transport-Security "max-age=63072000; includeSubDomains; preload" always; # OCSP Stapling ssl_stapling on; ssl_stapling_verify on; resolver 223.5.5.5 8.8.8.8 valid=300s; EOF

自动续期

# Certbot 安装时已自动配置 systemd timer sudo systemctl status certbot.timer # 手动续期 sudo certbot renew # 查看续期计划 sudo systemctl list-timers | grep certbot

Nginx vs Apache 选型建议

场景推荐原因
高并发静态文件Nginx事件驱动,内存占用低
.htaccess 需求Apache原生支持目录级配置
反向代理 / 负载均衡Nginx配置简洁,性能优秀
PHP(PHP-FPM)均可两者都支持 FastCGI,26.04 推荐方案
微服务网关Nginx更适合 API 网关场景
Warning

Ubuntu 26.04 的 Apache 2.4.66 service 默认启用 MemoryDenyWriteExecute=yes,会导致 libapache2-mod-php 崩溃。官方推荐改用 PHP-FPM(mod_proxy_fcgi + php-fpm),不再使用嵌入式 mod_php。

常用管理命令

# Nginx sudo nginx -t # 测试配置 sudo systemctl reload nginx # 平滑重载 sudo systemctl restart nginx # 重启 sudo tail -f /var/log/nginx/access.log # 查看访问日志 # Apache sudo apache2ctl configtest # 测试配置 sudo systemctl reload apache2 # 平滑重载 sudo systemctl restart apache2 # 重启 sudo a2ensite site.conf # 启用站点 sudo a2dissite site.conf # 禁用站点 sudo a2enmod module # 启用模块 sudo a2dismod module # 禁用模块 sudo tail -f /var/log/apache2/access.log # 查看访问日志

相关文章

Last updated on