Ravindra Bagale · Cyber Securityसर्व coursesया course चे lessonsशोधाEnglish

Cyber Security · मराठी आवृत्ती

Nginx server block कसा वाचायचा?

रवींद्र बागले यांच्या course वर आधारित · सहज मराठीत explanation

या page मध्ये

Nginx मध्ये साधी directive name value; अशी असते; block name { ... } असा. Semicolon आणि braces नीट ठेवणं महत्त्वाचं.

main context  (user, worker_processes, error_log)
 ├── events { worker_connections ... }
 └── http {  (mime types, logging, gzip, include conf.d/*.conf)
        └── server {            ← one per website (a "server block")
               listen ...; server_name ...; root ...;
               └── location /path { ... }   ← rules for part of the URL
            }
     }

Main context मध्ये global settings, events मध्ये connection-related settings आणि http मध्ये HTTP configuration. त्यात server blocks आणि त्यात URL paths साठी location blocks येतात.

पूर्ण example

# /etc/nginx/conf.d/mysite.conf   (Ubuntu: /etc/nginx/sites-available/mysite)
server {
    listen 80;                          # IPv4 port
    listen [::]:80;                     # IPv6 port
    server_name example.com www.example.com;   # which Host names this block answers

    root  /var/www/mysite;              # document root: URL "/" maps here
    index index.html index.htm;         # file served for a folder request

    location / {
        try_files $uri $uri/ =404;      # file? folder? otherwise 404
    }

    location /images/ {
        expires 7d;                     # let browsers cache images for 7 days
    }

    error_page 404 /404.html;           # custom error page (file inside root)
    autoindex off;                      # never list folder contents

    access_log /var/log/nginx/mysite_access.log;
    error_log  /var/log/nginx/mysite_error.log;
}

या block मध्ये IPv4/IPv6 port 80, example.com/www.example.com hostnames, /var/www/mysite root आणि index files दिल्या आहेत. try_files $uri $uri/ =404 आधी file, मग directory तपासतो; नाही मिळाल्यास 404. Images साठी सात दिवसांची cache expiry, custom 404 page, directory listing बंद आणि वेगळी logs आहेत.

Directive काय काम करतं? Example
listen Listen port/IP; default_server ने त्या endpoint साठी fallback listen 80 default_​server;
server_name Host शी जुळवायची नावं; _ placeholder, स्वतः catch-all नाही server_​name example.​com www.​example.​com;
root URL path जोडायचा root folder root /​var/​www/​mysite;
index Directory URL साठी तपासायच्या files index index.​html index.​php;
location URL path match करणारे rules location /​api/ { ... }
try_files क्रमाने files तपासा; मग fallback try_​files $uri $uri/ /​index.​html; (SPA)
return लगेच redirect किंवा status द्या return 301 https://$host$request_​uri;
error_page स्वतःचा error page error_​page 404 /​404.​html;
client_​max_​body_​size Request body size limit; config/context तपासा client_​max_​body_​size 20M;
server_tokens Headers/error pages मधले Nginx version details कमी/दाखवा server_tokens off;

return थेट status/redirect देतो. client_max_body_size request body size मर्यादित करतो; example 20M. server_tokens off काही version details लपवतो, पण Nginx ची ओळख किंवा सर्व fingerprinting नाहीसं करत नाही. server_name _ हा साधा placeholder आहे; default होण्याचं कारण default_server असतं, underscore जादुई catch-all नाही.

Syntax error वाचूया

Directive शेवटी ; आणि block साठी matching } हवा. sudo nginx -t file आणि line सांगतो. Report झालेली line आणि तिच्या आधीची line दोन्ही पाहा; error नेहमी आधीच्याच line वर असतो असं नाही.

कोणता server block निवडला जातो?

  1. Connection च्या listen IP/port साठीचे blocks पाहिले जातात.
  2. Hostname match नुसार योग्य server_name निवडतात. Exact, wildcard आणि regex names यांचे नियम आहेत; या simple example मध्ये exact names महत्त्वाची आहेत.
  3. Match नसेल तर त्या listen endpoint चा default_server, नसेल तर पहिला loaded block वापरतात.

म्हणून “नवीन config केला तरी welcome page येतो” असं झाल्यास browser कोणता Host पाठवतोय आणि default block कोणता आहे ते तपासा.

Practice

Amazon Linux वर /etc/nginx/nginx.conf किंवा Ubuntu वर /etc/nginx/sites-available/default वाचा. listen, server_name, root, index आणि प्रत्येक location ओळखा.