AWS · मराठी आवृत्ती
7.10 Combination 5: CentOS Stream 9 + Nginx
AL2023 सारखा config, पण SELinux labels आणि firewalld तपासू:
sudo yum install -y nginx
sudo service nginx start
sudo systemctl enable nginx
sudo tee /etc/nginx/conf.d/mysite.conf > /dev/null <<'EOF'
server {
listen 80;
listen [::]:80;
server_name YOUR_SERVER_NAME;
root /var/www/mysite;
index index.html;
location / {
try_files $uri $uri/ =404;
}
error_page 404 /404.html;
}
EOF
sudo sed -i "s/YOUR_SERVER_NAME/$(curl -s https://checkip.amazonaws.com)/" /etc/nginx/conf.d/mysite.conf
# SELinux: give the files the web-content label
sudo restorecon -Rv /var/www/mysite
ls -Z /var/www/mysite # should show httpd_sys_content_t
# firewalld: only if it is active
if systemctl is-active --quiet firewalld; then
sudo firewall-cmd --permanent --add-service=http --add-service=https
sudo firewall-cmd --reload
fi
sudo nginx -t && sudo service nginx reload
curl -s http://localhost -H "Host: $(curl -s https://checkip.amazonaws.com)" | head -5
Custom folder चा SELinux context
/var/www खाली distribution policy मध्ये web labels अपेक्षित असतात; restorecon आणि ls -Z ने खात्री करा. /data/site सारख्या custom path साठी permanent mapping द्या:
sudo semanage fcontext -a -t httpd_sys_content_t "/data/site(/.*)?"
sudo restorecon -Rv /data/sitesemanage साठी policycoreutils-python-utils package लागू शकतो. Rule आधी असेल तर -a ऐवजी योग्य modify operation वापरा. Home path मध्ये parent traverse/SELinux policy वेगळा अडथळा असू शकतो; dedicated web root सोयीचा.
Lab
ls -Z /var/www/mysite मध्ये labels, getenforce मध्ये Enforcing आणि browser मध्ये site तपासा.