Nginx / Apache Web 服务器
本文介绍在 Ubuntu 26.04 上安装和配置两大主流 Web 服务器:Nginx 和 Apache。
Nginx
安装 Nginx
sudo apt update
sudo apt install nginx -y
# 启动并设置开机自启
sudo systemctl enable --now nginx
# 查看状态
sudo systemctl status nginx
# 查看版本
nginx -v防火墙配置
# 允许 HTTP 和 HTTPS
sudo ufw allow 'Nginx Full'
# 或分别允许
sudo ufw allow 80/tcp
sudo ufw allow 443/tcp目录结构
/etc/nginx/
├── nginx.conf # 主配置文件
├── sites-available/ # 可用站点配置
├── sites-enabled/ # 已启用站点(符号链接)
├── conf.d/ # 额外配置片段
├── snippets/ # 可复用的配置片段
└── modules-enabled/ # 已启用模块
/var/www/ # 网站根目录
/var/log/nginx/ # 日志目录虚拟主机配置
# 创建网站目录
sudo mkdir -p /var/www/example.com/html
sudo chown -R www-data:www-data /var/www/example.com
echo "<h1>Welcome to example.com</h1>" | sudo tee /var/www/example.com/html/index.html
# 创建虚拟主机配置
sudo tee /etc/nginx/sites-available/example.com << 'EOF'
server {
listen 80;
listen [::]:80;
server_name example.com www.example.com;
root /var/www/example.com/html;
index index.html index.htm;
# 日志
access_log /var/log/nginx/example.com.access.log;
error_log /var/log/nginx/example.com.error.log;
location / {
try_files $uri $uri/ =404;
}
# 静态资源缓存
location ~* \.(jpg|jpeg|png|gif|ico|css|js|woff2)$ {
expires 30d;
add_header Cache-Control "public, immutable";
}
# 禁止访问隐藏文件
location ~ /\. {
deny all;
}
}
EOF
# 启用站点
sudo ln -s /etc/nginx/sites-available/example.com /etc/nginx/sites-enabled/
# 移除默认站点(可选)
sudo rm /etc/nginx/sites-enabled/default
# 测试配置
sudo nginx -t
# 重新加载
sudo systemctl reload nginx反向代理配置
sudo tee /etc/nginx/sites-available/app-proxy << 'EOF'
server {
listen 80;
server_name app.example.com;
location / {
proxy_pass http://127.0.0.1:3000;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
# WebSocket 支持
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "upgrade";
}
}
EOF
sudo ln -s /etc/nginx/sites-available/app-proxy /etc/nginx/sites-enabled/
sudo nginx -t && sudo systemctl reload nginxNginx 性能优化
# /etc/nginx/nginx.conf 关键配置
sudo tee /etc/nginx/conf.d/performance.conf << 'EOF'
# Gzip 压缩
gzip on;
gzip_vary on;
gzip_proxied any;
gzip_comp_level 5;
gzip_min_length 256;
gzip_types
text/plain
text/css
text/xml
text/javascript
application/json
application/javascript
application/xml
application/rss+xml
image/svg+xml;
# 文件缓存
open_file_cache max=1000 inactive=20s;
open_file_cache_valid 30s;
open_file_cache_min_uses 2;
# 连接优化
keepalive_timeout 65;
keepalive_requests 100;
EOF
sudo nginx -t && sudo systemctl reload nginxApache
安装 Apache
sudo apt update
sudo apt install apache2 -y
# 启动并设置开机自启
sudo systemctl enable --now apache2
# 查看状态
sudo systemctl status apache2
# 查看版本
apache2 -v防火墙配置
sudo ufw allow 'Apache Full'目录结构
/etc/apache2/
├── apache2.conf # 主配置文件
├── ports.conf # 监听端口
├── sites-available/ # 可用站点配置
├── sites-enabled/ # 已启用站点
├── mods-available/ # 可用模块
├── mods-enabled/ # 已启用模块
└── conf-available/ # 额外配置
/var/www/ # 网站根目录
/var/log/apache2/ # 日志目录常用模块管理
# 启用模块
sudo a2enmod rewrite # URL 重写
sudo a2enmod ssl # SSL/TLS
sudo a2enmod headers # HTTP 头控制
sudo a2enmod proxy # 反向代理
sudo a2enmod proxy_http # HTTP 代理
sudo a2enmod proxy_wstunnel # WebSocket 代理
# 禁用模块
sudo a2dismod autoindex
# 重启生效
sudo systemctl restart apache2虚拟主机配置
# 创建网站目录
sudo mkdir -p /var/www/example.com/html
sudo chown -R www-data:www-data /var/www/example.com
echo "<h1>Welcome to example.com</h1>" | sudo tee /var/www/example.com/html/index.html
# 创建虚拟主机配置
sudo tee /etc/apache2/sites-available/example.com.conf << 'EOF'
<VirtualHost *:80>
ServerName example.com
ServerAlias www.example.com
ServerAdmin admin@example.com
DocumentRoot /var/www/example.com/html
<Directory /var/www/example.com/html>
Options -Indexes +FollowSymLinks
AllowOverride All
Require all granted
</Directory>
# 日志
ErrorLog ${APACHE_LOG_DIR}/example.com-error.log
CustomLog ${APACHE_LOG_DIR}/example.com-access.log combined
</VirtualHost>
EOF
# 启用站点
sudo a2ensite example.com.conf
# 禁用默认站点(可选)
sudo a2dissite 000-default.conf
# 测试配置
sudo apache2ctl configtest
# 重新加载
sudo systemctl reload apache2反向代理配置
sudo a2enmod proxy proxy_http
sudo tee /etc/apache2/sites-available/app-proxy.conf << 'EOF'
<VirtualHost *:80>
ServerName app.example.com
ProxyPreserveHost On
ProxyPass / http://127.0.0.1:3000/
ProxyPassReverse / http://127.0.0.1:3000/
# WebSocket 代理
RewriteEngine On
RewriteCond %{HTTP:Upgrade} websocket [NC]
RewriteCond %{HTTP:Connection} upgrade [NC]
RewriteRule ^/?(.*) ws://127.0.0.1:3000/$1 [P,L]
ErrorLog ${APACHE_LOG_DIR}/app-proxy-error.log
CustomLog ${APACHE_LOG_DIR}/app-proxy-access.log combined
</VirtualHost>
EOF
sudo a2ensite app-proxy.conf
sudo apache2ctl configtest && sudo systemctl reload apache2SSL 证书配置
使用 Let’s Encrypt(Certbot)
# 安装 Certbot
sudo apt install certbot -y
# Nginx 插件
sudo apt install python3-certbot-nginx -y
# Apache 插件
sudo apt install python3-certbot-apache -yNginx SSL 配置
# 自动获取并配置证书
sudo certbot --nginx -d example.com -d www.example.com
# 测试自动续期
sudo certbot renew --dry-run
# 查看证书信息
sudo certbot certificatesCertbot 会自动将 Nginx 配置修改为:
server {
listen 443 ssl;
listen [::]:443 ssl;
http2 on;
server_name example.com www.example.com;
ssl_certificate /etc/letsencrypt/live/example.com/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/example.com/privkey.pem;
include /etc/letsencrypt/options-ssl-nginx.conf;
ssl_dhparam /etc/letsencrypt/ssl-dhparams.pem;
# ... 其他配置
}
# HTTP 跳转 HTTPS
server {
listen 80;
server_name example.com www.example.com;
return 301 https://$host$request_uri;
}Apache SSL 配置
# 启用 SSL 模块
sudo a2enmod ssl
# 自动获取并配置证书
sudo certbot --apache -d example.com -d www.example.com手动 SSL 配置(Nginx)
sudo tee /etc/nginx/snippets/ssl-params.conf << 'EOF'
ssl_protocols TLSv1.2 TLSv1.3;
ssl_ciphers ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384;
ssl_prefer_server_ciphers off;
ssl_session_timeout 1d;
ssl_session_cache shared:SSL:10m;
ssl_session_tickets off;
# HSTS
add_header Strict-Transport-Security "max-age=63072000; includeSubDomains; preload" always;
# OCSP Stapling
ssl_stapling on;
ssl_stapling_verify on;
resolver 223.5.5.5 8.8.8.8 valid=300s;
EOF自动续期
# Certbot 安装时已自动配置 systemd timer
sudo systemctl status certbot.timer
# 手动续期
sudo certbot renew
# 查看续期计划
sudo systemctl list-timers | grep certbotNginx vs Apache 选型建议
| 场景 | 推荐 | 原因 |
|---|---|---|
| 高并发静态文件 | Nginx | 事件驱动,内存占用低 |
| .htaccess 需求 | Apache | 原生支持目录级配置 |
| 反向代理 / 负载均衡 | Nginx | 配置简洁,性能优秀 |
| PHP(PHP-FPM) | 均可 | 两者都支持 FastCGI,26.04 推荐方案 |
| 微服务网关 | Nginx | 更适合 API 网关场景 |
Warning
Ubuntu 26.04 的 Apache 2.4.66 service 默认启用 MemoryDenyWriteExecute=yes,会导致 libapache2-mod-php 崩溃。官方推荐改用 PHP-FPM(mod_proxy_fcgi + php-fpm),不再使用嵌入式 mod_php。
常用管理命令
# Nginx
sudo nginx -t # 测试配置
sudo systemctl reload nginx # 平滑重载
sudo systemctl restart nginx # 重启
sudo tail -f /var/log/nginx/access.log # 查看访问日志
# Apache
sudo apache2ctl configtest # 测试配置
sudo systemctl reload apache2 # 平滑重载
sudo systemctl restart apache2 # 重启
sudo a2ensite site.conf # 启用站点
sudo a2dissite site.conf # 禁用站点
sudo a2enmod module # 启用模块
sudo a2dismod module # 禁用模块
sudo tail -f /var/log/apache2/access.log # 查看访问日志相关文章
- Docker Compose 服务编排 — 使用 Docker Compose 容器化部署 Web 服务
- SSH 基础 — SSH 远程连接与密钥管理,服务器运维的基础技能
- UFW 防火墙 — 为 Web 服务器配置防火墙规则,开放 HTTP/HTTPS 端口
Last updated on