dev.conf 13 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325
  1. # ============================================================
  2. # 开发环境(deve):deve.ailien.shop
  3. #
  4. # 仓库: docs/devops/dev/middleware/nginx/dev.conf
  5. # 宿主机: /docker/middleware/nginx/conf.d/dev.conf
  6. # 下载备份同级: E:\temp\nginx\conf.d\dev.conf(与 test.conf 同级)
  7. #
  8. # 加载关系(见上一级 nginx.conf):
  9. # include /docker/middleware/nginx/*.conf;
  10. # 常见 compose 将宿主机 conf.d 挂载为容器内 /docker/middleware/nginx/,
  11. # 则本文件在容器内路径为 /docker/middleware/nginx/dev.conf,与 test.conf 一并被 include。
  12. #
  13. # 本文件勿重复定义(已在 test.conf 的 http 上下文):
  14. # limit_req_zone payment_prepay
  15. # map $http_upgrade $connection_upgrade
  16. # map $http_origin $cors_origin
  17. # upstream gateway / store / dining / upl_ai_upload / test_ai_service
  18. #
  19. # 静态资源: Jenkins 部署到宿主机 /deve/html → 容器内 /deve/html(须 nginx 挂载)
  20. # 上传目录: 宿主机 /deve/data/uploads → 容器内 /deve/data/uploads(可选挂载)
  21. #
  22. # Java dev 宿主机端口: gateway 28000, store 28004, second 28005, dining 28014
  23. # gateway 与 nginx 同在 app-network 时用容器名;store/dining 与 test.conf 一致走宿主机端口。
  24. # ============================================================
  25. upstream dev_gateway {
  26. server gateway-dev:8000;
  27. keepalive 32;
  28. }
  29. upstream dev_store {
  30. server 120.26.186.130:28004;
  31. keepalive 8;
  32. }
  33. upstream dev_dining {
  34. server 120.26.186.130:28014;
  35. keepalive 8;
  36. }
  37. # --------------- deve.ailien.shop HTTP → HTTPS ---------------
  38. server {
  39. listen 80;
  40. server_name deve.ailien.shop;
  41. access_log /var/log/nginx/deve.ailien.shop.80.access.log main;
  42. error_log /var/log/nginx/deve.ailien.shop.80.error.log warn;
  43. location / {
  44. return 308 https://$host$request_uri;
  45. }
  46. }
  47. # --------------- deve.ailien.shop (443) ---------------
  48. server {
  49. listen 443 ssl;
  50. http2 on;
  51. server_name deve.ailien.shop;
  52. # 与 test.conf 一致,使用 ailien.shop 证书(需证书覆盖 deve.ailien.shop 或 *.ailien.shop)
  53. ssl_certificate /etc/nginx/ssl/ailien.shop.pem;
  54. ssl_certificate_key /etc/nginx/ssl/ailien.shop.key;
  55. ssl_session_timeout 1d;
  56. ssl_protocols TLSv1.2 TLSv1.3;
  57. ssl_ciphers ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384;
  58. client_max_body_size 100m;
  59. access_log /var/log/nginx/deve.ailien.shop.access.log main;
  60. error_log /var/log/nginx/deve.ailien.shop.error.log warn;
  61. # Docker 内置 DNS(gateway-dev 容器 IP 变更时重新解析)
  62. resolver 127.0.0.11 valid=10s ipv6=off;
  63. resolver_timeout 5s;
  64. # 商户端 PC:https://deve.ailien.shop/group_web_merchant/
  65. location /group_web_merchant/ {
  66. root /deve/html;
  67. index index.html;
  68. try_files $uri $uri/ @dev_merchant_spa;
  69. }
  70. location @dev_merchant_spa {
  71. root /deve/html;
  72. try_files /group_web_merchant/index.html =404;
  73. }
  74. location = /group_web_merchant {
  75. return 301 $scheme://$host/group_web_merchant/;
  76. }
  77. # 运营中台:https://deve.ailien.shop/group_web/
  78. location /group_web/ {
  79. root /deve/html;
  80. index index.html;
  81. try_files $uri $uri/ @dev_group_spa;
  82. }
  83. location @dev_group_spa {
  84. root /deve/html;
  85. try_files /group_web/index.html =404;
  86. }
  87. location = /group_web {
  88. return 301 $scheme://$host/group_web/;
  89. }
  90. # 律师 Web:https://deve.ailien.shop/group_lawyer_web/
  91. location /group_lawyer_web/ {
  92. root /deve/html;
  93. index index.html;
  94. try_files $uri $uri/ @dev_lawyer_spa;
  95. }
  96. location @dev_lawyer_spa {
  97. root /deve/html;
  98. try_files /group_lawyer_web/index.html =404;
  99. }
  100. location = /group_lawyer_web {
  101. return 301 $scheme://$host/group_lawyer_web/;
  102. }
  103. # AI WebSocket(复用 test.conf 中的 test_ai_service)
  104. location /ai/ws {
  105. proxy_pass http://test_ai_service;
  106. proxy_http_version 1.1;
  107. proxy_set_header Upgrade $http_upgrade;
  108. proxy_set_header Connection $connection_upgrade;
  109. proxy_set_header Host $host;
  110. proxy_set_header X-Real-IP $remote_addr;
  111. proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
  112. proxy_set_header X-Forwarded-Proto $scheme;
  113. proxy_connect_timeout 60s;
  114. proxy_send_timeout 3600s;
  115. proxy_read_timeout 3600s;
  116. }
  117. # AI 接口(复用 test.conf 中的 test_ai_service)
  118. location /ai/ {
  119. if ($request_method = 'OPTIONS') {
  120. add_header 'Access-Control-Allow-Origin' $cors_origin;
  121. add_header 'Access-Control-Allow-Methods' 'GET, POST, PUT, DELETE, PATCH, OPTIONS';
  122. add_header 'Access-Control-Allow-Headers' '*';
  123. add_header 'Access-Control-Allow-Credentials' 'true';
  124. add_header 'Access-Control-Max-Age' 3600;
  125. add_header 'Content-Length' 0;
  126. return 204;
  127. }
  128. add_header 'Access-Control-Allow-Origin' $cors_origin always;
  129. add_header 'Access-Control-Allow-Credentials' 'true' always;
  130. proxy_pass http://test_ai_service;
  131. proxy_http_version 1.1;
  132. proxy_set_header Host $host;
  133. proxy_set_header X-Real-IP $remote_addr;
  134. proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
  135. proxy_set_header X-Forwarded-Proto $scheme;
  136. proxy_connect_timeout 60s;
  137. proxy_send_timeout 60s;
  138. proxy_read_timeout 60s;
  139. }
  140. # WebSocket 直连 store-dev:/alienStore/socket/ → /socket/
  141. location /alienStore/socket/ {
  142. rewrite ^/alienStore/socket/(.*)$ /socket/$1 break;
  143. proxy_pass http://dev_store;
  144. proxy_http_version 1.1;
  145. proxy_set_header Upgrade $http_upgrade;
  146. proxy_set_header Connection $connection_upgrade;
  147. proxy_set_header Host $host;
  148. proxy_set_header X-Real-IP $remote_addr;
  149. proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
  150. proxy_set_header X-Forwarded-Proto $scheme;
  151. proxy_connect_timeout 60s;
  152. proxy_send_timeout 3600s;
  153. proxy_read_timeout 3600s;
  154. }
  155. # 点餐 SSE:直连 dining-dev
  156. location /alienDining/store/order/sse/ {
  157. rewrite ^/alienDining/(.*)$ /$1 break;
  158. proxy_pass http://dev_dining;
  159. proxy_http_version 1.1;
  160. proxy_set_header Host $host;
  161. proxy_set_header X-Real-IP $remote_addr;
  162. proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
  163. proxy_set_header X-Forwarded-Proto $scheme;
  164. proxy_connect_timeout 60s;
  165. proxy_send_timeout 86400s;
  166. proxy_read_timeout 86400s;
  167. proxy_buffering off;
  168. }
  169. # 支付预下单限流(zone 在 test.conf 定义)
  170. location ~* payment/prePay {
  171. limit_req zone=payment_prepay burst=1 nodelay;
  172. limit_req_status 429;
  173. add_header X-Payment-Limit "applied" always;
  174. rewrite ^/api/(.*)$ /$1 break;
  175. proxy_pass http://dev_gateway;
  176. proxy_http_version 1.1;
  177. proxy_set_header Host $host;
  178. proxy_set_header X-Real-IP $remote_addr;
  179. proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
  180. proxy_set_header X-Forwarded-Proto $scheme;
  181. proxy_set_header Upgrade $http_upgrade;
  182. proxy_set_header Connection $connection_upgrade;
  183. proxy_connect_timeout 60s;
  184. proxy_send_timeout 3600s;
  185. proxy_read_timeout 3600s;
  186. if ($request_method = 'OPTIONS') {
  187. add_header 'Access-Control-Allow-Origin' $cors_origin;
  188. add_header 'Access-Control-Allow-Methods' 'GET, POST, PUT, DELETE, PATCH, OPTIONS';
  189. add_header 'Access-Control-Allow-Headers' '*';
  190. add_header 'Access-Control-Allow-Credentials' 'true';
  191. add_header 'Access-Control-Max-Age' 3600;
  192. add_header 'Content-Length' 0;
  193. return 204;
  194. }
  195. proxy_hide_header Access-Control-Allow-Origin;
  196. proxy_hide_header Access-Control-Allow-Credentials;
  197. proxy_hide_header Access-Control-Allow-Methods;
  198. proxy_hide_header Access-Control-Allow-Headers;
  199. proxy_hide_header Access-Control-Expose-Headers;
  200. proxy_hide_header Access-Control-Max-Age;
  201. add_header 'Access-Control-Allow-Origin' $cors_origin always;
  202. add_header 'Access-Control-Allow-Credentials' 'true' always;
  203. }
  204. # /api/ → gateway-dev(去掉 /api 前缀)
  205. location /api/ {
  206. rewrite ^/api/(.*)$ /$1 break;
  207. proxy_pass http://dev_gateway;
  208. proxy_http_version 1.1;
  209. proxy_set_header Host $host;
  210. proxy_set_header X-Real-IP $remote_addr;
  211. proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
  212. proxy_set_header X-Forwarded-Proto $scheme;
  213. proxy_set_header Upgrade $http_upgrade;
  214. proxy_set_header Connection $connection_upgrade;
  215. proxy_connect_timeout 60s;
  216. proxy_send_timeout 3600s;
  217. proxy_read_timeout 3600s;
  218. if ($request_method = 'OPTIONS') {
  219. add_header 'Access-Control-Allow-Origin' $cors_origin;
  220. add_header 'Access-Control-Allow-Methods' 'GET, POST, PUT, DELETE, PATCH, OPTIONS';
  221. add_header 'Access-Control-Allow-Headers' '*';
  222. add_header 'Access-Control-Allow-Credentials' 'true';
  223. add_header 'Access-Control-Max-Age' 3600;
  224. add_header 'Content-Length' 0;
  225. return 204;
  226. }
  227. proxy_hide_header Access-Control-Allow-Origin;
  228. proxy_hide_header Access-Control-Allow-Credentials;
  229. proxy_hide_header Access-Control-Allow-Methods;
  230. proxy_hide_header Access-Control-Allow-Headers;
  231. proxy_hide_header Access-Control-Expose-Headers;
  232. proxy_hide_header Access-Control-Max-Age;
  233. add_header 'Access-Control-Allow-Origin' $cors_origin always;
  234. add_header 'Access-Control-Allow-Credentials' 'true' always;
  235. }
  236. # H5 静态:/deve/html/h5/HBuilderProjects/...
  237. # 对照 test.conf:root 到 html 根,勿写 root .../h5/(会拼成 h5/h5 404)
  238. location ^~ /h5/HBuilderProjects/ {
  239. root /deve/html;
  240. try_files $uri =404;
  241. add_header Cache-Control "public, max-age=300";
  242. }
  243. # 业务上传文件(对照 test 的 /alien_test/data/uploads/)
  244. location ^~ /uploads/ {
  245. alias /deve/data/uploads/;
  246. try_files $uri =404;
  247. add_header Cache-Control "public, max-age=86400";
  248. }
  249. # Tus/上传:复用 test.conf 的 upl_ai_upload → uat.ailien.shop
  250. location = /ai-upload {
  251. return 301 $scheme://$host/ai-upload/;
  252. }
  253. location ^~ /ai-upload/ {
  254. rewrite ^/ai-upload(.*)$ $1 break;
  255. proxy_pass https://upl_ai_upload;
  256. proxy_http_version 1.1;
  257. proxy_set_header Connection "";
  258. proxy_ssl_server_name on;
  259. proxy_ssl_name uat.ailien.shop;
  260. proxy_set_header Host uat.ailien.shop;
  261. proxy_set_header X-Real-IP $remote_addr;
  262. proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
  263. proxy_set_header X-Forwarded-Proto $scheme;
  264. proxy_connect_timeout 60s;
  265. proxy_send_timeout 3600s;
  266. proxy_read_timeout 3600s;
  267. client_max_body_size 0;
  268. proxy_request_buffering off;
  269. }
  270. # 其余请求 → gateway-dev
  271. location / {
  272. if ($request_method = 'OPTIONS') {
  273. add_header 'Access-Control-Allow-Origin' $cors_origin;
  274. add_header 'Access-Control-Allow-Methods' 'GET, POST, PUT, DELETE, PATCH, OPTIONS';
  275. add_header 'Access-Control-Allow-Headers' '*';
  276. add_header 'Access-Control-Allow-Credentials' 'true';
  277. add_header 'Access-Control-Max-Age' 3600;
  278. add_header 'Content-Length' 0;
  279. return 204;
  280. }
  281. proxy_hide_header Access-Control-Allow-Origin;
  282. proxy_hide_header Access-Control-Allow-Credentials;
  283. proxy_hide_header Access-Control-Allow-Methods;
  284. proxy_hide_header Access-Control-Allow-Headers;
  285. proxy_hide_header Access-Control-Expose-Headers;
  286. proxy_hide_header Access-Control-Max-Age;
  287. add_header 'Access-Control-Allow-Origin' $cors_origin always;
  288. add_header 'Access-Control-Allow-Credentials' 'true' always;
  289. proxy_pass http://dev_gateway;
  290. proxy_http_version 1.1;
  291. proxy_set_header Upgrade $http_upgrade;
  292. proxy_set_header Connection $connection_upgrade;
  293. proxy_set_header Host $host;
  294. proxy_set_header X-Real-IP $remote_addr;
  295. proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
  296. proxy_set_header X-Forwarded-Proto $scheme;
  297. proxy_connect_timeout 60s;
  298. proxy_send_timeout 3600s;
  299. proxy_read_timeout 3600s;
  300. }
  301. }