home.social

#nginx — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #nginx, aggregated by home.social.

fetched live
  1. Уязвим не nginx, а две строки вашего конфига. Разбираю CVE-2026-42945 на живом стенде

    Критическая дыра в nginx: 9.2 по CVSS, восемнадцать лет в коде, нашёл её ИИ-агент за шесть часов. В новостях к этому прилагают 5.7 миллиона уязвимых серверов, а сканы реальных конфигов находят ноль из 1465 и один из 35633. Поднял стенд, чтобы понять, кто прав. Заодно выяснилось, что граница проходит не там, где её рисуют: трейлинговый знак вопроса безопасен, промежуточный rewrite гасит флаг, а именованный захват спасает не всегда.

    habr.com/ru/articles/1070120/

    #nginx #уязвимости #DevSecOps #CVE

  2. Уязвим не nginx, а две строки вашего конфига. Разбираю CVE-2026-42945 на живом стенде

    Критическая дыра в nginx: 9.2 по CVSS, восемнадцать лет в коде, нашёл её ИИ-агент за шесть часов. В новостях к этому прилагают 5.7 миллиона уязвимых серверов, а сканы реальных конфигов находят ноль из 1465 и один из 35633. Поднял стенд, чтобы понять, кто прав. Заодно выяснилось, что граница проходит не там, где её рисуют: трейлинговый знак вопроса безопасен, промежуточный rewrite гасит флаг, а именованный захват спасает не всегда.

    habr.com/ru/articles/1070120/

    #nginx #уязвимости #DevSecOps #CVE

  3. Уязвим не nginx, а две строки вашего конфига. Разбираю CVE-2026-42945 на живом стенде

    Критическая дыра в nginx: 9.2 по CVSS, восемнадцать лет в коде, нашёл её ИИ-агент за шесть часов. В новостях к этому прилагают 5.7 миллиона уязвимых серверов, а сканы реальных конфигов находят ноль из 1465 и один из 35633. Поднял стенд, чтобы понять, кто прав. Заодно выяснилось, что граница проходит не там, где её рисуют: трейлинговый знак вопроса безопасен, промежуточный rewrite гасит флаг, а именованный захват спасает не всегда.

    habr.com/ru/articles/1070120/

    #nginx #уязвимости #DevSecOps #CVE

  4. How to Install #PinePods on #AlmaLinux #VPS
    This article provides a guide demonstrating how to install PinePods on AlmaLinux VPS using #Docker Compose, PostgreSQL, Valkey, and a host-level #Nginx ...
    Continued 👉 #opensource #selfhosted #letsencrypt #selfhosting #reverseproxy #podcasthosting

    How to Install PinePods on Alm...

  5. How to Install #PinePods on #AlmaLinux #VPS
    This article provides a guide demonstrating how to install PinePods on AlmaLinux VPS using #Docker Compose, PostgreSQL, Valkey, and a host-level #Nginx ...
    Continued 👉 #opensource #selfhosted #letsencrypt #selfhosting #reverseproxy #podcasthosting

    How to Install PinePods on Alm...

  6. How to Setup a Reverse #Proxy with HTTPS Using #Nginx and #Certbot (5 Minute Quick-Start Guide)

    This article outlines how to setup a reverse proxy with HTTPS using Nginx and Certbot.
    What is a Reverse Proxy?
    A reverse proxy is a server ...
    Continued 👉 #proxyserver #letsencrypt #reverseproxy

    How to Setup a Reverse Proxy w...

  7. After the OpenSMTPD article, I am now working on an article to uncover the things that #httpd on #OpenBSD has to offer. Yes, it does not have all the features of #nginx, but still it can do a lot.

    Want to know when the article is available? Follow the RSS feed on bsd-audit.com/ or follow me here.

    If you are using httpd a lot, then a question for you: what are the tips that those new to OpenBSD and httpd should know? Why httpd and not nginx?

  8. After the OpenSMTPD article, I am now working on an article to uncover the things that #httpd on #OpenBSD has to offer. Yes, it does not have all the features of #nginx, but still it can do a lot.

    Want to know when the article is available? Follow the RSS feed on bsd-audit.com/ or follow me here.

    If you are using httpd a lot, then a question for you: what are the tips that those new to OpenBSD and httpd should know? Why httpd and not nginx?

  9. After the OpenSMTPD article, I am now working on an article to uncover the things that #httpd on #OpenBSD has to offer. Yes, it does not have all the features of #nginx, but still it can do a lot.

    Want to know when the article is available? Follow the RSS feed on bsd-audit.com/ or follow me here.

    If you are using httpd a lot, then a question for you: what are the tips that those new to OpenBSD and httpd should know? Why httpd and not nginx?

  10. After the OpenSMTPD article, I am now working on an article to uncover the things that #httpd on #OpenBSD has to offer. Yes, it does not have all the features of #nginx, but still it can do a lot.

    Want to know when the article is available? Follow the RSS feed on bsd-audit.com/ or follow me here.

    If you are using httpd a lot, then a question for you: what are the tips that those new to OpenBSD and httpd should know? Why httpd and not nginx?

  11. After the OpenSMTPD article, I am now working on an article to uncover the things that #httpd on #OpenBSD has to offer. Yes, it does not have all the features of #nginx, but still it can do a lot.

    Want to know when the article is available? Follow the RSS feed on bsd-audit.com/ or follow me here.

    If you are using httpd a lot, then a question for you: what are the tips that those new to OpenBSD and httpd should know? Why httpd and not nginx?

  12. Install #Plausible CE on #AlmaLinux #VPS

    This article provides a guide to install Plausible CE on AlmaLinux VPS using #Docker Compose, then puts it behind #Nginx with HTTPS from Let’s Encrypt.
    What is Plausible CE?
    Plausible CE ...
    Continued 👉 #opensource #selfhosted #letsencrypt #selfhosting

    Install Plausible CE on AlmaLi...

  13. Install #Plausible CE on #AlmaLinux #VPS

    This article provides a guide to install Plausible CE on AlmaLinux VPS using #Docker Compose, then puts it behind #Nginx with HTTPS from Let’s Encrypt.
    What is Plausible CE?
    Plausible CE ...
    Continued 👉 #opensource #selfhosted #letsencrypt #selfhosting

    Install Plausible CE on AlmaLi...

  14. 🚀 Deploy #Odoo on Rocky Linux #VPS

    This guide walks through the steps to deploy Odoo on Rocky Linux VPS using PostgreSQL, #Python virtual environment, #Nginx reverse proxy, and systemd. This setup is ...
    Continued 👉 #postgresql #rockylinux #selfhosted #opensource #selfhosting #letsencrypt

    🚀 Deploy Odoo on Rocky Linux V...

  15. 🚀 Deploy #Odoo on Rocky Linux #VPS

    This guide walks through the steps to deploy Odoo on Rocky Linux VPS using PostgreSQL, #Python virtual environment, #Nginx reverse proxy, and systemd. This setup is ...
    Continued 👉 #postgresql #rockylinux #selfhosted #opensource #selfhosting #letsencrypt

    🚀 Deploy Odoo on Rocky Linux V...

  16. How to Install #PinePods on #AlmaLinux #VPS
    This article provides a guide demonstrating how to install PinePods on AlmaLinux VPS using #Docker Compose, PostgreSQL, Valkey, and a host-level #Nginx reverse proxy with Let’s Encrypt SSL.

    What is PinePods?
    PinePods is a self-hosted, open-source #podcast management system. In simple terms, it lets you run your own private podcast ...
    Continued 👉 blog.radwebhosting.com/install #letsencrypt #reverseproxy #selfhosting #opensource #selfhosted #podcasthosting

  17. How to Install #PinePods on #AlmaLinux #VPS
    This article provides a guide demonstrating how to install PinePods on AlmaLinux VPS using #Docker Compose, PostgreSQL, Valkey, and a host-level #Nginx reverse proxy with Let’s Encrypt SSL.

    What is PinePods?
    PinePods is a self-hosted, open-source #podcast management system. In simple terms, it lets you run your own private podcast ...
    Continued 👉 blog.radwebhosting.com/install #letsencrypt #reverseproxy #selfhosting #opensource #selfhosted #podcasthosting

  18. How to Install #PinePods on #AlmaLinux #VPS
    This article provides a guide demonstrating how to install PinePods on AlmaLinux VPS using #Docker Compose, PostgreSQL, Valkey, and a host-level #Nginx reverse proxy with Let’s Encrypt SSL.

    What is PinePods?
    PinePods is a self-hosted, open-source #podcast management system. In simple terms, it lets you run your own private podcast ...
    Continued 👉 blog.radwebhosting.com/install #letsencrypt #reverseproxy #selfhosting #opensource #selfhosted #podcasthosting

  19. How to Install #PinePods on #AlmaLinux #VPS
    This article provides a guide demonstrating how to install PinePods on AlmaLinux VPS using #Docker Compose, PostgreSQL, Valkey, and a host-level #Nginx reverse proxy with Let’s Encrypt SSL.

    What is PinePods?
    PinePods is a self-hosted, open-source #podcast management system. In simple terms, it lets you run your own private podcast ...
    Continued 👉 blog.radwebhosting.com/install #letsencrypt #reverseproxy #selfhosting #opensource #selfhosted #podcasthosting

  20. How to Setup a Reverse #Proxy with HTTPS Using #Nginx and #Certbot (5 Minute Quick-Start Guide)

    This article outlines how to setup a reverse proxy with HTTPS using Nginx and Certbot.
    What is a Reverse Proxy?
    A reverse proxy is a server that sits between client devices and a backend server, forwarding client requests to the backend server and returning the server's response to the clients. Unlike a forward proxy, ...
    Continued 👉 blog.radwebhosting.com/setup-a #letsencrypt #reverseproxy #proxyserver

  21. How to Setup a Reverse #Proxy with HTTPS Using #Nginx and #Certbot (5 Minute Quick-Start Guide)

    This article outlines how to setup a reverse proxy with HTTPS using Nginx and Certbot.
    What is a Reverse Proxy?
    A reverse proxy is a server that sits between client devices and a backend server, forwarding client requests to the backend server and returning the server's response to the clients. Unlike a forward proxy, ...
    Continued 👉 blog.radwebhosting.com/setup-a #letsencrypt #reverseproxy #proxyserver

  22. How to Setup a Reverse #Proxy with HTTPS Using #Nginx and #Certbot (5 Minute Quick-Start Guide)

    This article outlines how to setup a reverse proxy with HTTPS using Nginx and Certbot.
    What is a Reverse Proxy?
    A reverse proxy is a server that sits between client devices and a backend server, forwarding client requests to the backend server and returning the server's response to the clients. Unlike a forward proxy, ...
    Continued 👉 blog.radwebhosting.com/setup-a #letsencrypt #reverseproxy #proxyserver

  23. How to Setup a Reverse #Proxy with HTTPS Using #Nginx and #Certbot (5 Minute Quick-Start Guide)

    This article outlines how to setup a reverse proxy with HTTPS using Nginx and Certbot.
    What is a Reverse Proxy?
    A reverse proxy is a server that sits between client devices and a backend server, forwarding client requests to the backend server and returning the server's response to the clients. Unlike a forward proxy, ...
    Continued 👉 blog.radwebhosting.com/setup-a #letsencrypt #reverseproxy #proxyserver

  24. 🚀 How to Deploy #TinyCP on #Ubuntu #VPS
    This article provides a guide demonstrating how to deploy TinyCP on Ubuntu VPS.

    What is TinyCP?
    TinyCP is a lightweight web hosting control panel designed to manage Linux servers through a simple web interface. It provides core hosting features without the heavy resource usage of traditional panels.
    READ ALSO: Top 12 Best VPS Control Panels

    🧠 ...
    Continued 👉 blog.radwebhosting.com/deploy- #letsencrypt #nginx #phpfpm #selfhosted #controlpanel #selfhosting

  25. 🚀 How to Deploy #TinyCP on #Ubuntu #VPS
    This article provides a guide demonstrating how to deploy TinyCP on Ubuntu VPS.

    What is TinyCP?
    TinyCP is a lightweight web hosting control panel designed to manage Linux servers through a simple web interface. It provides core hosting features without the heavy resource usage of traditional panels.
    READ ALSO: Top 12 Best VPS Control Panels

    🧠 ...
    Continued 👉 blog.radwebhosting.com/deploy- #letsencrypt #nginx #phpfpm #selfhosted #controlpanel #selfhosting

  26. 🚀 How to Deploy #TinyCP on #Ubuntu #VPS
    This article provides a guide demonstrating how to deploy TinyCP on Ubuntu VPS.

    What is TinyCP?
    TinyCP is a lightweight web hosting control panel designed to manage Linux servers through a simple web interface. It provides core hosting features without the heavy resource usage of traditional panels.
    READ ALSO: Top 12 Best VPS Control Panels

    🧠 ...
    Continued 👉 blog.radwebhosting.com/deploy- #letsencrypt #nginx #phpfpm #selfhosted #controlpanel #selfhosting

  27. 🚀 How to Deploy #TinyCP on #Ubuntu #VPS
    This article provides a guide demonstrating how to deploy TinyCP on Ubuntu VPS.

    What is TinyCP?
    TinyCP is a lightweight web hosting control panel designed to manage Linux servers through a simple web interface. It provides core hosting features without the heavy resource usage of traditional panels.
    READ ALSO: Top 12 Best VPS Control Panels

    🧠 ...
    Continued 👉 blog.radwebhosting.com/deploy- #letsencrypt #nginx #phpfpm #selfhosted #controlpanel #selfhosting

  28. How to Deploy #gVisor on #Ubuntu #VPS

    This article provides a guide demonstrating how to deploy gVisor on Ubuntu VPS.
    Introduction
    gVisor is an open-source application kernel developed by Google that provides an additional security layer between containerized applications and the Linux kernel. Unlike traditional containers that share the host kernel directly, gVisor intercepts system calls through a user-space kernel (runsc), significantly ...
    Continued 👉 blog.radwebhosting.com/deploy- #nginx

  29. How to Deploy #gVisor on #Ubuntu #VPS

    This article provides a guide demonstrating how to deploy gVisor on Ubuntu VPS.
    Introduction
    gVisor is an open-source application kernel developed by Google that provides an additional security layer between containerized applications and the Linux kernel. Unlike traditional containers that share the host kernel directly, gVisor intercepts system calls through a user-space kernel (runsc), significantly ...
    Continued 👉 blog.radwebhosting.com/deploy- #nginx

  30. How to Deploy #gVisor on #Ubuntu #VPS

    This article provides a guide demonstrating how to deploy gVisor on Ubuntu VPS.
    Introduction
    gVisor is an open-source application kernel developed by Google that provides an additional security layer between containerized applications and the Linux kernel. Unlike traditional containers that share the host kernel directly, gVisor intercepts system calls through a user-space kernel (runsc), significantly ...
    Continued 👉 blog.radwebhosting.com/deploy- #nginx

  31. How to Deploy #gVisor on #Ubuntu #VPS

    This article provides a guide demonstrating how to deploy gVisor on Ubuntu VPS.
    Introduction
    gVisor is an open-source application kernel developed by Google that provides an additional security layer between containerized ...
    Continued 👉 #nginx

    How to Deploy gVisor on Ubuntu...

  32. Neuer Quick-Tipp im Blog:

    Startet die Backend-VM hinter dem nginx-Reverse-Proxy neu, sehen Besucher nur einen nackten 502.

    Mit error_page und einer benannten Location gibt's stattdessen eine saubere Wartungsseite – inklusive der Timeout-Falle, die sonst 60 Sekunden Ladebalken produziert.

    👉 just-stuff.blog/nginx-reverse-

    #nginx #ReverseProxy #Linux #Homelab #SelfHosted

  33. Neuer Quick-Tipp im Blog:

    Startet die Backend-VM hinter dem nginx-Reverse-Proxy neu, sehen Besucher nur einen nackten 502.

    Mit error_page und einer benannten Location gibt's stattdessen eine saubere Wartungsseite – inklusive der Timeout-Falle, die sonst 60 Sekunden Ladebalken produziert.

    👉 just-stuff.blog/nginx-reverse-

    #nginx #ReverseProxy #Linux #Homelab #SelfHosted

  34. Neuer Quick-Tipp im Blog:

    Startet die Backend-VM hinter dem nginx-Reverse-Proxy neu, sehen Besucher nur einen nackten 502.

    Mit error_page und einer benannten Location gibt's stattdessen eine saubere Wartungsseite – inklusive der Timeout-Falle, die sonst 60 Sekunden Ladebalken produziert.

    👉 just-stuff.blog/nginx-reverse-

    #nginx #ReverseProxy #Linux #Homelab #SelfHosted

  35. Neuer Quick-Tipp im Blog:

    Startet die Backend-VM hinter dem nginx-Reverse-Proxy neu, sehen Besucher nur einen nackten 502.

    Mit error_page und einer benannten Location gibt's stattdessen eine saubere Wartungsseite – inklusive der Timeout-Falle, die sonst 60 Sekunden Ladebalken produziert.

    👉 just-stuff.blog/nginx-reverse-

    #nginx #ReverseProxy #Linux #Homelab #SelfHosted

  36. Neuer Quick-Tipp im Blog:

    Startet die Backend-VM hinter dem nginx-Reverse-Proxy neu, sehen Besucher nur einen nackten 502.

    Mit error_page und einer benannten Location gibt's stattdessen eine saubere Wartungsseite – inklusive der Timeout-Falle, die sonst 60 Sekunden Ladebalken produziert.

    👉 just-stuff.blog/nginx-reverse-

    #nginx #ReverseProxy #Linux #Homelab #SelfHosted

  37. 🚀 How to Deploy Open edX on #Ubuntu #VPS (1 Hour Quick-Start Guide)

    This article provides a start-to-finish, production-ready guide demonstrating how to deploy Open edX on Ubuntu VPS. This follows the official Tutor-based deployment, which is the recommended, supported, and upgrade-safe method.
    Overview
    Open edX is a large, microservice-based ...
    Continued 👉 blog.radwebhosting.com/deploy- #nginx #opensource #learningmanagementsystem #letsencrypt #django #education #elearning #openedx #mongodb

  38. 🚀 How to Deploy Open edX on #Ubuntu #VPS (1 Hour Quick-Start Guide)

    This article provides a start-to-finish, production-ready guide demonstrating how to deploy Open edX on Ubuntu VPS. This follows the official Tutor-based deployment, which is the recommended, supported, and upgrade-safe method.
    Overview
    Open edX is a large, microservice-based ...
    Continued 👉 blog.radwebhosting.com/deploy- #nginx #opensource #learningmanagementsystem #letsencrypt #django #education #elearning #openedx #mongodb

  39. 🚀 How to Deploy Open edX on #Ubuntu #VPS (1 Hour Quick-Start Guide)

    This article provides a start-to-finish, production-ready guide demonstrating how to deploy Open edX on Ubuntu VPS. This follows the official Tutor-based deployment, which is the recommended, supported, and upgrade-safe method.
    Overview
    Open edX is a large, microservice-based ...
    Continued 👉 blog.radwebhosting.com/deploy- #nginx #opensource #learningmanagementsystem #letsencrypt #django #education #elearning #openedx #mongodb

  40. 🚀 How to Deploy #TinyCP on #Ubuntu #VPS
    This article provides a guide demonstrating how to deploy TinyCP on Ubuntu VPS.

    What is TinyCP?
    TinyCP is a lightweight web hosting control panel designed to manage Linux ...
    Continued 👉 #letsencrypt #selfhosting #nginx #phpfpm #controlpanel #selfhosted

    🚀 How to Deploy TinyCP on Ubun...

  41. 🚀 How to Deploy #TinyCP on #Ubuntu #VPS
    This article provides a guide demonstrating how to deploy TinyCP on Ubuntu VPS.

    What is TinyCP?
    TinyCP is a lightweight web hosting control panel designed to manage Linux ...
    Continued 👉 #letsencrypt #selfhosting #nginx #phpfpm #controlpanel #selfhosted

    🚀 How to Deploy TinyCP on Ubun...

  42. Liebe #Mastodon und #Fedi #Admins, ich bräuchte etwas Unterstützung beim Umzug meiner Instanz in mein Homelab. Herausforderung ist aktuell die öffentliche Erreichbarkeit über IPv6 im Zusammenspiel mit Docker. Vorher war ich IPv4 only. Die IPv6 route ich über einen #nginx an den Mastodon-Container weiter. Erreichbarkeit funktioniert. Ich bekomme aber nicht mehr von allen Instanzen (wie z.B. mastodon.social) Updates gepusht. Andere (wie z.B. chaos.social) funktionieren einwandfrei. Jemand Ideen?

  43. Liebe #Mastodon und #Fedi #Admins, ich bräuchte etwas Unterstützung beim Umzug meiner Instanz in mein Homelab. Herausforderung ist aktuell die öffentliche Erreichbarkeit über IPv6 im Zusammenspiel mit Docker. Vorher war ich IPv4 only. Die IPv6 route ich über einen #nginx an den Mastodon-Container weiter. Erreichbarkeit funktioniert. Ich bekomme aber nicht mehr von allen Instanzen (wie z.B. mastodon.social) Updates gepusht. Andere (wie z.B. chaos.social) funktionieren einwandfrei. Jemand Ideen?

  44. Liebe #Mastodon und #Fedi #Admins, ich bräuchte etwas Unterstützung beim Umzug meiner Instanz in mein Homelab. Herausforderung ist aktuell die öffentliche Erreichbarkeit über IPv6 im Zusammenspiel mit Docker. Vorher war ich IPv4 only. Die IPv6 route ich über einen #nginx an den Mastodon-Container weiter. Erreichbarkeit funktioniert. Ich bekomme aber nicht mehr von allen Instanzen (wie z.B. mastodon.social) Updates gepusht. Andere (wie z.B. chaos.social) funktionieren einwandfrei. Jemand Ideen?

  45. nginx -s reload может не применить конфиг

    Пока идёт бинарный апгрейд nginx, systemctl reload nginx не применяет конфиг так, как вы думаете: в лучшем случае к половине процессов сервера, в худшем — вообще никуда. Код возврата ноль в обоих случаях, в error.log пусто. Что именно у вас — решает одна строчка в юните: -s reload бьёт по pid-файлу, а он после USR2 принадлежит новому мастеру; kill -s HUP $MAINPID бьёт по старому, а тот конфиг вообще не перечитывает, и это описано в документации nginx — в разделе про обновление исполняемого файла, куда по другому поводу не заходят. Это первая из пяти проверок. Я взял пять ходовых утверждений про reload в nginx, померил каждое на стенде — и получил результаты по обе стороны: три подтвердились, два развалились. Развалившиеся оказались интереснее. Не работают ровно те страшилки, что про слушающий сокет: listen ... reuseport бесшовность не ломает (inode’ы сокетов до и после reload одни и те же — их держит мастер, а не воркер), паузы в accept при reload не существует вовсе (msleep(100) стоит ПЕРЕД QUIT), а значит и арифметика про переполнение backlog на reload — про нагрузку, а не про reload. Зато подтвердилось то, о чём почти не пишут. keepalive_min_timeout оставляет уходящего воркера в живых, и тот обслуживает запросы, которых в момент reload ещё не существовало — по старому конфигу. А ngx_close_idle_connections не различает направление соединения, поэтому каждый reload сбрасывает пул keepalive к бэкендам — и с 1.29.7 это касается всех, у кого есть блок upstream : пул там включён по умолчанию, 32 соединения на воркер. Правило из первой части — «соединение, открытое до reload, нового конфига не увидит» — приходится переформулировать: держится старого конфига не соединение, а процесс. В конце — Traefik, у которого reload’а нет вовсе, и который умеет не применить конфиг своим способом: кольцевой буфер на одно сообщение и двухсекундный дроссель. nginx release-1.31.3, traefik v3.7.10, все опыты в репозитории, запуск одной командой.

    habr.com/ru/articles/1068364/

    #nginx #reload #nginx_s_reload #systemd #бинарный_апгрейд #keepalive #upstream #reuseport #backlog #traefik

  46. nginx -s reload может не применить конфиг

    Пока идёт бинарный апгрейд nginx, systemctl reload nginx не применяет конфиг так, как вы думаете: в лучшем случае к половине процессов сервера, в худшем — вообще никуда. Код возврата ноль в обоих случаях, в error.log пусто. Что именно у вас — решает одна строчка в юните: -s reload бьёт по pid-файлу, а он после USR2 принадлежит новому мастеру; kill -s HUP $MAINPID бьёт по старому, а тот конфиг вообще не перечитывает, и это описано в документации nginx — в разделе про обновление исполняемого файла, куда по другому поводу не заходят. Это первая из пяти проверок. Я взял пять ходовых утверждений про reload в nginx, померил каждое на стенде — и получил результаты по обе стороны: три подтвердились, два развалились. Развалившиеся оказались интереснее. Не работают ровно те страшилки, что про слушающий сокет: listen ... reuseport бесшовность не ломает (inode’ы сокетов до и после reload одни и те же — их держит мастер, а не воркер), паузы в accept при reload не существует вовсе (msleep(100) стоит ПЕРЕД QUIT), а значит и арифметика про переполнение backlog на reload — про нагрузку, а не про reload. Зато подтвердилось то, о чём почти не пишут. keepalive_min_timeout оставляет уходящего воркера в живых, и тот обслуживает запросы, которых в момент reload ещё не существовало — по старому конфигу. А ngx_close_idle_connections не различает направление соединения, поэтому каждый reload сбрасывает пул keepalive к бэкендам — и с 1.29.7 это касается всех, у кого есть блок upstream : пул там включён по умолчанию, 32 соединения на воркер. Правило из первой части — «соединение, открытое до reload, нового конфига не увидит» — приходится переформулировать: держится старого конфига не соединение, а процесс. В конце — Traefik, у которого reload’а нет вовсе, и который умеет не применить конфиг своим способом: кольцевой буфер на одно сообщение и двухсекундный дроссель. nginx release-1.31.3, traefik v3.7.10, все опыты в репозитории, запуск одной командой.

    habr.com/ru/articles/1068364/

    #nginx #reload #nginx_s_reload #systemd #бинарный_апгрейд #keepalive #upstream #reuseport #backlog #traefik

  47. nginx -s reload может не применить конфиг

    Пока идёт бинарный апгрейд nginx, systemctl reload nginx не применяет конфиг так, как вы думаете: в лучшем случае к половине процессов сервера, в худшем — вообще никуда. Код возврата ноль в обоих случаях, в error.log пусто. Что именно у вас — решает одна строчка в юните: -s reload бьёт по pid-файлу, а он после USR2 принадлежит новому мастеру; kill -s HUP $MAINPID бьёт по старому, а тот конфиг вообще не перечитывает, и это описано в документации nginx — в разделе про обновление исполняемого файла, куда по другому поводу не заходят. Это первая из пяти проверок. Я взял пять ходовых утверждений про reload в nginx, померил каждое на стенде — и получил результаты по обе стороны: три подтвердились, два развалились. Развалившиеся оказались интереснее. Не работают ровно те страшилки, что про слушающий сокет: listen ... reuseport бесшовность не ломает (inode’ы сокетов до и после reload одни и те же — их держит мастер, а не воркер), паузы в accept при reload не существует вовсе (msleep(100) стоит ПЕРЕД QUIT), а значит и арифметика про переполнение backlog на reload — про нагрузку, а не про reload. Зато подтвердилось то, о чём почти не пишут. keepalive_min_timeout оставляет уходящего воркера в живых, и тот обслуживает запросы, которых в момент reload ещё не существовало — по старому конфигу. А ngx_close_idle_connections не различает направление соединения, поэтому каждый reload сбрасывает пул keepalive к бэкендам — и с 1.29.7 это касается всех, у кого есть блок upstream : пул там включён по умолчанию, 32 соединения на воркер. Правило из первой части — «соединение, открытое до reload, нового конфига не увидит» — приходится переформулировать: держится старого конфига не соединение, а процесс. В конце — Traefik, у которого reload’а нет вовсе, и который умеет не применить конфиг своим способом: кольцевой буфер на одно сообщение и двухсекундный дроссель. nginx release-1.31.3, traefik v3.7.10, все опыты в репозитории, запуск одной командой.

    habr.com/ru/articles/1068364/

    #nginx #reload #nginx_s_reload #systemd #бинарный_апгрейд #keepalive #upstream #reuseport #backlog #traefik

  48. Install #Plausible CE on #AlmaLinux #VPS

    This article provides a guide to install Plausible CE on AlmaLinux VPS using #Docker Compose, then puts it behind #Nginx with HTTPS from Let’s Encrypt.
    What is Plausible CE?
    Plausible CE stands for Plausible Community Edition.

    It is the free, self-hosted version of Plausible Analytics, a privacy-focused alternative to Google Analytics. Instead of sending your ...
    Continued 👉 blog.radwebhosting.com/install #letsencrypt #selfhosted #opensource #selfhosting

  49. Install #Plausible CE on #AlmaLinux #VPS

    This article provides a guide to install Plausible CE on AlmaLinux VPS using #Docker Compose, then puts it behind #Nginx with HTTPS from Let’s Encrypt.
    What is Plausible CE?
    Plausible CE stands for Plausible Community Edition.

    It is the free, self-hosted version of Plausible Analytics, a privacy-focused alternative to Google Analytics. Instead of sending your ...
    Continued 👉 blog.radwebhosting.com/install #letsencrypt #selfhosted #opensource #selfhosting

  50. Install #Plausible CE on #AlmaLinux #VPS

    This article provides a guide to install Plausible CE on AlmaLinux VPS using #Docker Compose, then puts it behind #Nginx with HTTPS from Let’s Encrypt.
    What is Plausible CE?
    Plausible CE stands for Plausible Community Edition.

    It is the free, self-hosted version of Plausible Analytics, a privacy-focused alternative to Google Analytics. Instead of sending your ...
    Continued 👉 blog.radwebhosting.com/install #letsencrypt #selfhosted #opensource #selfhosting

  51. So gestern Nacht noch einen Fehler beim Proxy und Remote IP Rate Limit Thema für social.anoxinon.de gelöst. Wenn ihr da die letzten Tage noch hineingerannt seid, sollte es jetzt verschwunden sein. Gerne aber mal Rückmeldung geben,

    #Anoxinon #Mastodon #Nginx #NPMPLus

  52. So gestern Nacht noch einen Fehler beim Proxy und Remote IP Rate Limit Thema für social.anoxinon.de gelöst. Wenn ihr da die letzten Tage noch hineingerannt seid, sollte es jetzt verschwunden sein. Gerne aber mal Rückmeldung geben,

    #Anoxinon #Mastodon #Nginx #NPMPLus

  53. So gestern Nacht noch einen Fehler beim Proxy und Remote IP Rate Limit Thema für social.anoxinon.de gelöst. Wenn ihr da die letzten Tage noch hineingerannt seid, sollte es jetzt verschwunden sein. Gerne aber mal Rückmeldung geben,

    #Anoxinon #Mastodon #Nginx #NPMPLus