cookie不同于session,一个存于客户端,一个存于服务端。

环境nginx 1.8.0

centos6.X

sticky:1.2.5   wget https://bitbucket.org/nginx-goodies/nginx-sticky-module-ng/get/master.tar.gz

cookie负载均衡相比iphash来比其中一个特点比较明显:内网nat用户的均衡。而iphash无法做到。

yum install openssl openssl-devel

先停止nginx服务。在给nginx添加模块。

将同版本的nginx包从新解压一份出来。当然同事也讲下载的sticky模块也解压并从命名成nginx-sticky-module

tar -zxf master.tar.gz

mv nginx-goodies-nginx-sticky-module-ng-c78b7dd79d0d nginx-sticky-module

killall nginx

(如果想查看sticky的版本,可以在changelog.txt里查看和改动)

添加模块:

我原来nginx的安装路径是:/usr/local/nginx  (添加模块时,之前的配置和模块也需要加上)因为这些都需要写到nginx这个二进制文件中。

查看之前安装了什么模块使用 /usr/local/nginx/sbin/nginx -V (大写的V哦。和我名字一样)

将之前的待上进行编译

./configure --user=www --group=www --prefix=/usr/local/nginx --with-http_stub_status_module --with-http_ssl_module --add-module=/root/nginx-sticky-module

因为我之前就2个模块。

然后我们make就好。   make install就不需要了,那是重新安装。

我们编译完成之后,在当前目录下会有一个objs,里面有nginx文件,就是我们make生成的二进制文件,然后将这个文件拷贝到/usr/local/nginx/sbin  (之前的nginx最好备份一下,以免发生错误好恢复)

至此 nginx 添加模块成功。 我们直接在nginx配置文件中引用就好。如下图

当然你也可以设置sticky的一些参数,比如sticky的缓存时间,作用于之类的。这里详细查看可以查询sticky解压包里的readme如下

========================================我粘贴出来========================================(英语大侠有福了)

balancing system won't be fair.

Using a cookie to track the upstream server makes each browser unique.

When the sticky module can't apply, it switchs back to the classic Round Robin Upstream or returns a "Bad Gateway" (depending on the no_fallback flag).

Sticky module can't apply when cookies are not supported by the browser

> Sticky module is based on a "best effort" algorithm. Its aim is not to handle # Nginx Sticky Module

# Nginx Sticky Module

modified and extended version; see Changelog.txt

# Description

A nginx module to add a sticky cookie to be always forwarded to the same upstream server.

When dealing with several backend servers, it's sometimes useful that one client (browser) is always served by the same backend server (for session persistance for example).

Using a persistance by IP (with the ip_hash upstream module) is maybe not a good idea because there could be situations where a lot of different browsers are coming with the same IP address (behind proxies)and the load balancing system won't be fair.

Using a cookie to track the upstream server makes each browser unique.

When the sticky module can't apply, it switchs back to the classic Round Robin Upstream or returns a "Bad Gateway" (depending on the no_fallback flag).

Sticky module can't apply when cookies are not supported by the browser

> Sticky module is based on a "best effort" algorithm. Its aim is not to handle > security somehow. It's been made to ensure that normal users are always > redirected to the same  backend server: that's all!

# Installation

You'll need to re-compile Nginx from source to include this module. Modify your compile of Nginx by adding the following directive (modified to suit your path of course):

./configure ... --add-module=/absolute/path/to/nginx-sticky-module-ng     make     make install

# Usage

upstream {       sticky;       server 127.0.0.1:9000;       server 127.0.0.1:9001;       server 127.0.0.1:9002;     }

sticky [name=route] [domain=.foo.bar] [path=/] [expires=1h]            [hash=index|md5|sha1] [no_fallback] [secure] [httponly];

- name:    the name of the cookies used to track the persistant upstream srv;   default: route

- domain:  the domain in which the cookie will be valid   default: nothing. Let the browser handle this.

- path:    the path in which the cookie will be valid   default: /

- expires: the validity duration of the cookie   default: nothing. It's a session cookie.   restriction: must be a duration greater than one second

- hash:    the hash mechanism to encode upstream server. It cant' be used with hmac.   default: md5

- md5|sha1: well known hash     - index:    it's not hashed, an in-memory index is used instead, it's quicker and the overhead is shorter     Warning: the matching against upstream servers list     is inconsistent. So, at reload, if upstreams servers     has changed, index values are not guaranted to     correspond to the same server as before!     USE IT WITH CAUTION and only if you need to!

- hmac:    the HMAC hash mechanism to encode upstream server     It's like the hash mechanism but it uses hmac_key     to secure the hashing. It can't be used with hash.     md5|sha1: well known hash     default: none. see hash.

- hmac_key: the key to use with hmac. It's mandatory when hmac is set            default: nothing.

- no_fallback: when this flag is set, nginx will return a 502 (Bad Gateway or               Proxy Error) if a request comes with a cookie and the               corresponding backend is unavailable.

- secure    enable secure cookies; transferred only via https - httponly  enable cookies not to be leaked via js # Detail Mechanism

- see docs/sticky.{vsd,pdf}

# Issues and Warnings:

- when using different upstream-configs with stickyness that use the same domain but   refer to different location - configs it might be wise to set a different path / route -   option on each of this upstream-configs like described here:   https://bitbucket.org/nginx-goodies/nginx-sticky-module-ng/issue/7/leaving-cookie-path-empty-in-module

- sticky module does not work with the "backup" option of the "server" configuration item. - sticky module might work with the nginx_http_upstream_check_module (up from version 1.2.3) - sticky module may require to configure nginx with SSL support (when using "secure" option)

# Contributing

- please send/suggest patches as diffs - tickets and issues here: https://bitbucket.org/nginx-goodies/nginx-sticky-session-ng

# Downloads

# TODO

see Todo.md

# Authors & Credits

- Jerome Loyet, initial module - Markus Linnala, httponly/secure-cookies-patch - Peter Bowey, Nginx 1.5.8 API-Change - Michael Chernyak for Max-Age-Patch - anybody who suggested a patch, created an issue on bitbucket or helped improving this module

# Copyright & License

This module is licenced under the BSD license.

Copyright (C) 2010 Jerome Loyet (jerome at loyet dot net)     Copyright (C) 2014 Markus Manzke (goodman at nginx-goodies dot com)

Redistribution and use in source and binary forms, with or without     modification, are permitted provided that the following conditions     are met:

1. Redistributions of source code must retain the above copyright     notice, this list of conditions and the following disclaimer.

2. Redistributions in binary form must reproduce the above copyright     notice, this list of conditions and the following disclaimer in the     documentation and/or other materials provided with the distribution.

THIS SOFTWARE IS PROVIDED BY AUTHOR AND CONTRIBUTORS ``AS IS'' AND     ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE     IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE     ARE DISCLAIMED.  IN NO EVENT SHALL AUTHOR OR CONTRIBUTORS BE LIABLE     FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL     DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS     OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)     HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT     LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY     OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF     SUCH DAMAGE.

nginx添加sticky模块-cookie保持会话的更多相关文章

  1. nginx添加sticky cookie 分流模块

    需要下载nginx源码和sticky,在nginx配置文件中添加sticky模块,然后重新编译nginx. #准备安装基础环境:yum install gcc openssl-devel pcre-d ...

  2. nginx添加 nginx_heath模块

    原因?为什么会使用nginx_heath 这个模块,主要是如nginx+tomcat部署的时,tomcat挂了之后nginx->upstream 轮询是可以踢掉挂掉的tomcat服务的,如果部署 ...

  3. yum安装的Nginx添加第三方模块支持tcp

    需求:生产有个接口是通过socket通信.nginx1.9开始支持tcp层的转发,通过stream实现的,而socket也是基于tcp通信. 实现方法:Centos7.2下yum直接安装的nginx, ...

  4. 已安装的nginx添加其他模块

    总体操作就是添加新模块并重新编译源码,然后把编译后的nginx可执行文件覆盖原来的那个即可.1 查看已安装的参数nginx -V拷贝那些巴拉巴拉的参数,后面编译的时候使用 2 下载相同版本号的源码,解 ...

  5. Nginx添加fastdfs-nginx-module模块

    系统:Ubuntu 20.04 Nginx版本:1.18.0 要添加的模块:fastdfs-nginx-module 思路:configure参数下包括Nginx已安装的模块信息,通过编辑config ...

  6. nginx 添加nginx-http-concat模块

    github地址:https://github.com/alibaba/nginx-http-concat/tree/master 简单的描述一下吧,网上说的安装新的模块需要重新编译nginx,具体的 ...

  7. nginx添加第三方模块

    原已经安装好的nginx,现在需要添加一个未被编译安装的模块: nginx -V 可以查看原来编译时都带了哪些参数,看看nginx是哪个版本,去下载一个nginx的源码,解压 原来的参数:--pref ...

  8. nginx添加新模块

    1.下载模块 git clone https://github.com/agentzh/echo-nginx-module 2.放入指定位置 mv echo-nginx-module-master / ...

  9. 编译安装了的nginx 添加http_ssl_module模块

    1.看下编译安装nginx的时候,都编译安装的哪些模块. [root@zabbix ~]# /usr/local/nginx/sbin/nginx -V nginx version: nginx/1. ...

随机推荐

  1. bind的模拟实现

    bind 一句话介绍 bind: bind() 方法会创建一个新函数.当这个新函数被调用时,bind() 的第一个参数将作为它运行时的 this,之后的一序列参数将会在传递的实参前传入作为它的参数.( ...

  2. 无向图边双联通分量 tarjan 模板

    #include <bits/stdc++.h> using namespace std; const int MAXN = 100005; const int MAXM = 500005 ...

  3. [React] Fetch Data with React Suspense

    Let's get started with the simplest version of data fetching with React Suspense. It may feel a litt ...

  4. 验证码破解 | Selenium模拟登陆12306

    12306官网登录的验证码破解比较简单,验证码是常规的点触类型验证码,使用超级鹰识别率比较高. 思路: (1)webdriver打开浏览器: (2)先对整个屏幕截屏,通过标签定位找到验证码图片,并定位 ...

  5. 1.Http讲解

    1.什么是HTTP HTTP(超文本传输协议)是一个简单的请求-响应协议,它通常运行在TCP上. 文本:html,字符串,.... 超文本:图片,音乐,视频,定位,地图... 80端口 HTTPS:安 ...

  6. Linux 和 windows下查看运行命令的位置

    经常遇到要查看某个命令的运行文件在哪儿! 比如说vue cli,经常使用vue命令创建项目,如果你对nodejs的全局包安装目录了解可能一下就找到了, 蛋疼的是不一定每个命令都是nodejs下的,有可 ...

  7. 第09组 Alpha冲刺(3/6)

    队名:观光队 组长博客 作业博客 组员实践情况 王耀鑫 过去两天完成了哪些任务 文字/口头描述 完成服务器连接数据库部分代码 展示GitHub当日代码/文档签入记录 接下来的计划 服务器网络请求,vu ...

  8. linux高性能服务器编程 (五) --Linux网络编程基础api

    第五章 Linux网络编程基础api 1.主机字节序和网络字节序 字节序是指整数在内存中保存的顺序.字节序分为大端字节序.小端字节序. 大端字节序:一个整数的高位字节数据存放在内存的低地址处.低位字节 ...

  9. Redis简介及其安装

    1.Redis NoSQL (Not noly SQL)不仅仅是SQL 属于非关系型数据库:Redis就属于非关系型数据库 传统的Mysql ,oracle ,sql server 等 都是关系型数据 ...

  10. [技术博客] 利用Vagrant+virtualbox在windows下进行linux开发

    目录 加速box安装的方法 root账户登录 换源教程 安装rvm 访问rails server RubyMine连接虚拟机上的解释器 作者:庄廓然 在windows下进行linux开发:利用Vagr ...