Various fixes that prevented production deployment

This commit is contained in:
Christoph Haas 2018-08-07 18:36:53 +02:00
parent 591845a25d
commit 459e86e25a
8 changed files with 134 additions and 279 deletions

View file

@ -24,10 +24,6 @@ proxy_cache_path /var/cache/nginx levels=1:2 keys_zone=my_cache:10m max_size=10g
log_format proxy '[$time_local] Cache: $upstream_cache_status $upstream_addr $upstream_response_time $status $bytes_sent $remote_addr $request_uri "$http_referer" "$http_user_agent" $scheme';
# Performance
passenger_max_pool_size 8;
passenger_max_request_queue_size 200;
limit_req_zone $binary_remote_addr zone=one:20m rate=5r/s;
# Frontend caching and static asset delivery
@ -37,7 +33,7 @@ server {
ssl_certificate /etc/letsencrypt/live/screenshots.debian.net/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/screenshots.debian.net/privkey.pem;
root /opt/debshots/public;
#root /opt/debshots/public;
server_name _;
access_log /var/log/nginx/cache-access.log proxy;
@ -62,7 +58,7 @@ server {
location /json/ {
try_files /maintenance.html @backend;
proxy_cache my_cache;
proxy_pass http://127.0.0.1:8888/;
proxy_pass http://127.0.0.1:3000/;
proxy_cache_lock on;
proxy_cache_use_stale updating;
add_header X-Coffee front-json;
@ -74,12 +70,17 @@ server {
location @backend {
proxy_cache my_cache;
proxy_pass http://127.0.0.1:8888;
proxy_set_header x_debian_sso_dn $ssl_client_s_dn;
proxy_pass http://127.0.0.1:3000;
# Avoid cache stampede - rather update once and deliver stale content
proxy_cache_lock on;
proxy_cache_use_stale updating;
add_header X-Coffee front-rails;
# Use sendfile mechanism to deliver files directly
proxy_set_header X-Sendfile-Type X-Accel-Redirect;
proxy_set_header X-Accel-Mapping /opt/debshots/public/=/__send_file_accel/;
}
location /assets/ {
@ -105,49 +106,46 @@ server {
}
# Backend rails application
server {
listen 127.0.0.1:8888;
# server {
# listen 127.0.0.1:3000;
root /opt/debshots/public;
# root /opt/debshots/public;
server_name _;
access_log /var/log/nginx/rails-access.log;
# server_name _;
# access_log /var/log/nginx/rails-access.log;
passenger_enabled on;
passenger_ruby /opt/debshots/.rbenv/versions/2.4.1/bin/ruby;
# # Send thumbnails using X-Sendfile / X-Accel-Redirect
# # The correct thumbnail is computed by the Rails application so it cannot be served directly.
# location /thumbnail/ {
# expires 1h;
# proxy_cache_valid 404 15m;
# add_header X-Coffee back-thumbnail;
# limit_req zone=one burst=30;
# }
# # Send public assets using X-Sendfile / X-Accel-Redirect (e.g. public/images/dummy/...)
# location /public/ {
# expires 1h;
# add_header X-Coffee back-public;
# Send thumbnails using X-Sendfile / X-Accel-Redirect
# The correct thumbnail is computed by the Rails application so it cannot be served directly.
location /thumbnail/ {
expires 1h;
proxy_cache_valid 404 15m;
add_header X-Coffee back-thumbnail;
limit_req zone=one burst=30;
}
# # passenger_set_header X-Sendfile-Type X-Accel-Redirect;
# # passenger_env_var HTTP_X_ACCEL_MAPPING /opt/debshots/public/=/__send_file_accel/;
# # passenger_pass_header X-Accel-Redirect;
# }
# Send public assets using X-Sendfile / X-Accel-Redirect (e.g. public/images/dummy/...)
location /public/ {
expires 1h;
add_header X-Coffee back-public;
# # Deliver static files directly from Nginx. See https://mattbrictson.com/accelerated-rails-downloads
# location /__send_file_accel/ {
# internal;
# alias /opt/debshots/public/;
# add_header X-Coffee back-accel;
# expires 1d;
# more_clear_headers 'Set-Cookie';
# }
passenger_set_header X-Sendfile-Type X-Accel-Redirect;
passenger_env_var HTTP_X_ACCEL_MAPPING /opt/debshots/public/=/__send_file_accel/;
passenger_pass_header X-Accel-Redirect;
}
location /__send_file_accel/ {
internal;
alias /opt/debshots/public/;
add_header X-Coffee back-accel;
expires 1d;
more_clear_headers 'Set-Cookie';
}
location /secretstatus {
stub_status;
access_log off;
allow all;
add_header X-Coffee back-status;
}
}
# location /secretstatus {
# stub_status;
# access_log off;
# allow all;
# add_header X-Coffee back-status;
# }
# }