The Definitive Guide to Architecture, Configuration, and Production Operations
Introduction: The NGINX Story and Architecture Promise
- The Igor Sysoev Problem: Why NGINX Was Created
- Event-Driven Architecture: The Core Innovation
- What NGINX Is Today: Beyond the Web Server
- Open Source vs NGINX Plus: The Edition Landscape
- How to Use This Book
Chapter 1: Installation and Environment Setup
- Packaging Ecosystems: Official Repositories vs Package Managers
- Building from Source: Control and Customization
- Containerized NGINX: Official Images and Variants
- Directory Structure and Binaries
- Default Configuration Anatomy
Chapter 2: Configuration Syntax, Directives, and Contexts
- The Configuration Grammar: Blocks, Directives, and Parameters
- Directive Contexts: Where Directives Belong
- Configuration Inheritance and Precedence
- Variables: Built-in, Custom, and Computed
- Include Mechanism and Configuration Organization
- Configuration Testing and Validation
Chapter 3: Worker Processes and Connection Handling
- The Master-Worker Process Model
- Worker Process Count and CPU Affinity
- The Event Loop: Epoll, Kqueue, and Event Ports
- Connection Lifecycle States
- Keepalive Connections and Tuning
- File Descriptor Limits and System Configuration
Chapter 4: Web Serving and Virtual Hosts
- Server Blocks and Virtual Hosts
- The Location Directive: NGINX’s Routing Engine
- Serving Static Content Efficiently
- Error Pages and Response Handling
- Request Limits and Resource Protection
- Compression: gzip, Brotli, and zstd
Chapter 5: Reverse Proxying and Upstream Configuration
- The Reverse Proxy Model: Why and How
- Upstream Groups: Structure and Directives
- Load Balancing Algorithms
- Health Checks: Passive and Active
- Proxy Buffering and Connection Management
- Timeouts and Retries
Chapter 6: Load Balancing Patterns and Advanced Traffic Management
- Production Load Balancing Topologies
- Traffic Splitting and Canary Deployments
- Session Persistence Strategies
- Geographic and Data Center Routing
- Rate Limiting and Request Throttling
- Connection Limits and Resource Protection
Chapter 7: Caching Architecture and Implementation
- Caching Fundamentals: When and Why to Cache
- Proxy Cache Configuration
- Cache Keys and Granularity
- Cache Bypass, Stale Serving, and Upstream Interaction
- Cache Purging and Management
- Memory vs Disk Caching Tradeoffs
Chapter 8: TLS, SSL, and Transport Security
- TLS Termination: Architecture and Rationale
- Certificate Configuration and Management
- Protocol Versions and Cipher Suites
- Session Resumption and Performance
- OCSP Stapling and Certificate Validation
- Advanced TLS: HSTS, MTLS, and Security Headers
Chapter 9: HTTP/2, HTTP/3, and QUIC
- HTTP/2: Multiplexing and Performance
- HTTP/2 Configuration and Tuning
- HTTP/3 and QUIC: The Next Generation
- Protocol Negotiation and Fallback
Chapter 10: Authentication, Authorization, and Access Control
- Basic and Digest Authentication
- IP-Based Access Control
- OAuth and OpenID Connect Integration Patterns
- External Authentication via Subrequests
- JWT Validation and API Security
- Role-Based Access Control Patterns
Chapter 11: Request Rewriting, Redirects, and URL Manipulation
- The Rewrite Directive: Syntax and Behavior
- Internal Redirects vs Client Redirects
- The Return Directive: Simpler Alternatives
- Argument Manipulation and Query String Control
- Migrating from Apache .htaccess Rules
- SEO-Friendly Redirects and Canonicalization
Chapter 12: Application Integration: FastCGI, uWSGI, SCGI, and gRPC
- FastCGI: PHP and Beyond
- uWSGI Protocol: Python and Ruby Applications
- SCGI: A Simpler Alternative
- gRPC Proxying: Modern Microservices
- Application Protocol Selection Guidance
Chapter 13: WebSocket and Long-Lived Connection Proxying
- WebSocket Protocol and Upgrade Mechanism
- Configuring WebSocket Proxying
- Long-Polling and Server-Sent Events
- Scaling WebSocket Connections
- Security Considerations for Persistent Connections
Chapter 14: Logging, Monitoring, and Observability
- Access and Error Log Configuration
- Custom Log Formats
- The stub_status Module and Basic Metrics
- NGINX Plus API and Advanced Monitoring
- Integration with Observability Stacks
- Debug Logging and Troubleshooting
Chapter 15: Stream Proxying, Mail Proxy, and TCP/UDP Handling
- The Stream Module: TCP/UDP Load Balancing
- TLS Termination for TCP Streams
- UDP Proxying and DNS Load Balancing
- The Mail Module: SMTP, IMAP, and POP3 Proxying
- Database Connection Proxying Patterns
Chapter 16: Performance Tuning and Kernel Optimization
- Worker Process and Event Loop Tuning
- Buffer Sizing Strategy
- Kernel Parameter Optimization
- Filesystem and I/O Optimization
- Connection and Timeout Tuning
- Load Testing Methodology
Chapter 17: Security Hardening and Defense in Depth
- Configuration Hardening Checklist
- Mitigating Common Web Attacks
- Security Headers Configuration
- Vulnerability Management and Patching
- Securing the NGINX Process Itself
- WAF Integration and Request Filtering
Chapter 18: Containerized Deployments and Kubernetes Ingress
- Docker Deployment Patterns
- Kubernetes Ingress Fundamentals
- NGINX Ingress Controller Configuration
- Advanced Kubernetes Patterns
- Service Mesh Integration
- GitOps and Declarative Management
Chapter 19: High Availability, Automation, and Production Operations
- High Availability Architectures
- Zero-Downtime Configuration Changes
- Dynamic Reconfiguration (NGINX Plus)
- Configuration Management and Automation
- CI/CD Integration for NGINX Configurations
- Operational Runbooks and Troubleshooting Flows
Chapter 20: Troubleshooting, Debugging, and Common Pitfalls
- Reading and Interpreting Error Logs
- Connection and Timeout Troubleshooting
- Upstream and Backend Issues
- TLS and SSL Troubleshooting
- Performance Degradation Diagnosis
- Common Configuration Pitfalls and Anti-Patterns
Chapter 21: NGINX Ecosystem Comparison and Technology Selection
- NGINX vs Apache: Architecture and Philosophy
- NGINX vs HAProxy: The Load Balancer Debate
- NGINX vs Envoy: Cloud-Native and Service Mesh
- NGINX vs Caddy and Traefik: Modern Alternatives
- Technology Selection Framework
Chapter 22: Migration Strategies and Modernization Patterns
- Migrating from Apache to NGINX
- Upgrading NGINX Versions Safely
- Modernizing Legacy NGINX Configurations
- Evolving from Open Source to NGINX Plus
- Decommissioning and Replacement Patterns
Conclusion: The NGINX Mastery Journey
References
- RFCs and Standards
- Official NGINX Documentation
- F5 NGINX Documentation
- NGINX Community Blog Articles
- Third-Party Resources and Tools
- Historical and Background Sources
- Performance and Comparison Sources