AI guide
【One-Line Pitch】
A hands-on recipe collection for engineers who already understand modern web architecture and now need to configure NGINX (open source or Plus) for real application-delivery problems—load balancing, security, caching, cloud/container deployment, and operations. Best for practitioners who want working configurations and the reasoning behind them, not a from-zero tutorial.
【Book Arc】
- **Opening (~0%–13%)**: Installation and fundamentals—setting up NGINX on Debian/Ubuntu and RedHat/CentOS, installing NGINX Plus, verifying the install, and learning the key files, directories, and commands. Solves the "get it running and know where things live" problem.
- **Early (~13%–33%)**: Core delivery mechanics—HTTP/TCP/UDP load balancing, session persistence, health checks, traffic management (A/B testing, GeoIP, rate/connection/bandwidth limits), large-scale caching, and programmability/automation (Plus API, key-value store, njs, Chef/Ansible/Consul).
- **Middle (~33%–53%)**: Security and modern protocols—authentication (basic auth, subrequests, JWT, OpenID Connect), access control and TLS, HTTP/2 and gRPC, plus media streaming (MP4/FLV, HLS/HDS).
- **Late (~53%–67%)**: Deployment environments—cloud (AWS, Azure, Google Compute Engine), containers and microservices (API gateway, Docker images, Kubernetes Ingress, service mesh/mTLS), high-availability patterns, and monitoring.
- **Ending (~67%–100%)**: Operations and tooling—logging and request tracing, performance tuning, NGINX Instance Manager and Controller, and practical ops tips like includes and config debugging.
【Key Takeaways】
- **This is a cookbook, not a linear textbook** (Early): each section is framed as problem → solution → explanation, so it works best as a reference you jump into by task.
- **Load balancing spans HTTP, TCP, and UDP** (Early): the `upstream` pattern recurs across the `http` and `stream` contexts, with algorithms like round-robin, least connections, and Plus-only least-time.
- **Session persistence is a first-class concern** (Early): NGINX Plus offers sticky cookie, sticky learn, and sticky routing for stateful applications where requests must return to the same server.
- **Health checks split into passive (open source) and active (Plus)** (Early): passive checks watch live traffic, while active checks probe upstreams proactively to avoid client-facing failures.
- **NGINX is often the first security boundary** (Middle): the book treats authentication, TLS, access control, and WAF/DDoS protection as core delivery concerns, not add-ons.
- **Caching and traffic management are tunable levers** (Early): cache zones, locking, hash keys, bypass, and slicing, alongside rate, connection, and bandwidth limits.
- **Cloud, containers, and service mesh are covered as deployment targets** (Late): AWS/Azure/GCP patterns, Docker images, Kubernetes Ingress, and mTLS mesh setups.
- **Operations close the loop** (Ending): logging, tracing, performance tuning, and management tooling (Instance Manager, Controller) round out the lifecycle.
【Reading Tips】
- Use the table of contents as your entry point: jump straight to the chapter matching your current task rather than reading cover to cover.
- Deep-read the load balancing, security, and caching chapters—these are the highest-leverage for production delivery work.
- Skim the installation and cloud-provider chapters if you already have a working environment; return when migrating platforms.
- Watch for the recurring "NGINX Plus only" annotations—many advanced features (active health checks, least-time, JWT, sticky sessions) are not in the open source edition.
- Treat the config snippets as starting points and always validate with `nginx -t` before reloading.
【Coverage Limits】
This guide is synthesized from stratified excerpts covering the front matter, table of contents, and early-to-mid chapters; later chapters on Instance Manager, Controller, and detailed ops tips are only visible at the heading level, so their specific content is not summarized here.
Passage locations
Page 4
Kim Cofer 英文版校对:JM Olejarz O'Reilly 徽标是 O'Reilly Media, Inc. 的注册商标。《NGINX 完全指南》、封面图片和相关商业包 装是 O'Reilly Media, Inc. 的商标。 本书所述均为作者的个人观点,不代表出版商的立场。虽然出版商和作者已经做出了...
View in text
Excerpt 2
....................................................... 181 ix前言 前言 《NGINX 完全指南》旨在通过一些简单易懂的例子解析应用交付中真实存在的问题。 本书内容丰富全面,探讨了 NGINX 的大部分主要特性,可帮助您学习如何使用这些 功能。 本书涉...
View in text
Page 17
GINX Plus 仓库进行身份验证。 详解 NGINX 会及时更新这个仓库安装指南和 NGINX Plus 安装说明。这些说明因您的操作 系统和版本而略有不同,但都有一个共同点:您必须从 NGINX 门户获取证书和密钥并 提供给您的系统,以便对 NGINX Plus 仓库进行身份验证。 1.4 验证安装 问题...
View in text
Page 25
06 weight=5; server read2.example.com:3306; server 10.10.12.34:3306 backup; } server { listen 3306; proxy_pass mysql_read; } } 此示例中的 server 代码块指示 NGINX 侦听 TC...
View in text