# 7.10 Combination 5: CentOS Stream 9 + Nginx

Source: https://ravindrabagale.com/mr/aws/ch07-static-website-hosting-3-oses-2-web-servers/7-10-combination-5-centos-stream-9-nginx.html
Language: mr (Marathi with English technical terms)

AL2023 सारखा config, पण SELinux labels आणि firewalld तपासू:

sudo yum install -y nginx
sudo service nginx start
sudo systemctl enable nginx

sudo tee /etc/nginx/conf.d/mysite.conf > /dev/null <<'EOF'
server {
    listen 80;
    listen [::]:80;
    server_name YOUR_SERVER_NAME;
    root /var/www/mysite;
    index index.html;
    location / {
        try_files $uri $uri/ =404;
    }
    error_page 404 /404.html;
}
EOF
sudo sed -i "s/YOUR_SERVER_NAME/$(curl -s https://checkip.amazonaws.com)/" /etc/nginx/conf.d/mysite.conf

# SELinux: give the files the web-content label
sudo restorecon -Rv /var/www/mysite
ls -Z /var/www/mysite            # should show httpd_sys_content_t

# firewalld: only if it is active
if systemctl is-active --quiet firewalld; then
  sudo firewall-cmd --permanent --add-service=http --add-service=https
  sudo firewall-cmd --reload
fi

sudo nginx -t && sudo service nginx reload
curl -s http://localhost -H "Host: $(curl -s https://checkip.amazonaws.com)" | head -5

Custom folder चा SELinux context

/var/www खाली distribution policy मध्ये web labels अपेक्षित असतात; restorecon आणि ls -Z ने खात्री करा. /data/site सारख्या custom path साठी permanent mapping द्या:

sudo semanage fcontext -a -t httpd_sys_content_t "/data/site(/.*)?"
sudo restorecon -Rv /data/site

semanage साठी policycoreutils-python-utils package लागू शकतो. Rule आधी असेल तर -a ऐवजी योग्य modify operation वापरा. Home path मध्ये parent traverse/SELinux policy वेगळा अडथळा असू शकतो; dedicated web root सोयीचा.

Lab

ls -Z /var/www/mysite मध्ये labels, getenforce मध्ये Enforcing आणि browser मध्ये site तपासा.

रवींद्र बागले यांची tip

403 आला की SELinux बंद न करता label आणि denial logs पाहा. mv नंतर जुन्या labels साठी restorecon उपयोगी.
