Compare commits

...
9 Commits
Author SHA1 Message Date
yurymuski 26130d1da8 typo fix 2023-09-04 01:10:35 +04:00
yurymuski 23f424b839 add --with-debug 2023-09-04 01:03:07 +04:00
yurymuski c55df02f0d readme upd 2023-09-04 00:41:54 +04:00
yurymuski 2655f98dee change debiam to ubuntu 2023-09-04 00:32:11 +04:00
yurymuski 3cde573afd upd CI, and readme 2023-09-03 23:00:59 +04:00
yurymuski 3bdbdb0e55 try fix ci 2023-09-03 02:51:13 +04:00
yurymuski 48b184cd32 fix compile err 2023-09-03 02:27:38 +04:00
yurymuski de3337a5bc try nginx version change 2023-09-03 02:23:33 +04:00
yurymuski 9e070a1318 version bump 2023-09-03 02:15:48 +04:00
4 changed files with 57 additions and 14 deletions
+38
View File
@@ -0,0 +1,38 @@
name: ci
on:
push:
branches:
- master
paths-ignore:
- '**/README.md'
tags:
- '*'
jobs:
build-and-push:
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v3
- name: Inject slug/short variables
uses: rlespinasse/github-slug-action@v4.x
- name: Login to Docker Hub
uses: docker/login-action@v2
with:
username: ${{ secrets.DOCKERHUB_USERNAME }}
password: ${{ secrets.DOCKERHUB_TOKEN }}
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v2
- name: Build and push
uses: docker/build-push-action@v4
with:
push: true
tags: |
${{ secrets.DOCKERHUB_USERNAME }}/${{ env.GITHUB_REPOSITORY_NAME_PART }}:${{ env.GITHUB_REF_SLUG }}
${{ secrets.DOCKERHUB_USERNAME }}/${{ env.GITHUB_REPOSITORY_NAME_PART }}:latest
+10 -5
View File
@@ -3,21 +3,22 @@ FROM ubuntu:20.04 AS builder
LABEL maintainer="Yury Muski <muski.yury@gmail.com>"
ENV NGINX_PATH /etc/nginx
ENV NGINX_VERSION 1.19.6
ENV NGINX_VERSION 1.16.1
ENV QUICHE_VERSION 0.9.0
ENV QUICHE_VERSION 0.18.0
WORKDIR /opt
RUN apt-get update && \
DEBIAN_FRONTEND=noninteractive apt-get install -y libpcre3 libpcre3-dev zlib1g-dev zlib1g golang-go build-essential git curl cmake;
DEBIAN_FRONTEND=noninteractive apt-get install -y libpcre3 libpcre3-dev zlib1g-dev zlib1g golang-go build-essential libbrotli-dev git curl cmake;
RUN curl -O https://nginx.org/download/nginx-$NGINX_VERSION.tar.gz && \
tar xvzf nginx-$NGINX_VERSION.tar.gz && \
git clone --branch $QUICHE_VERSION --recursive https://github.com/cloudflare/quiche && \
cd /opt/quiche && git submodule update --init && cd /opt/ && \
git clone --recursive https://github.com/google/ngx_brotli.git && \
cd nginx-$NGINX_VERSION && \
patch -p01 < ../quiche/extras/nginx/nginx-1.16.patch && \
patch -p01 < ../quiche/nginx/nginx-1.16.patch && \
curl https://sh.rustup.rs -sSf | sh -s -- -y -q && \
export PATH="$HOME/.cargo/bin:$PATH" && \
./configure \
@@ -60,9 +61,10 @@ RUN curl -O https://nginx.org/download/nginx-$NGINX_VERSION.tar.gz && \
--with-stream_realip_module \
--with-stream_ssl_module \
--with-stream_ssl_preread_module \
--with-debug \
--add-module=/opt/ngx_brotli \
--with-http_v3_module \
--with-openssl=/opt/quiche/deps/boringssl \
--with-openssl=/opt/quiche/quiche/deps/boringssl \
--build="quiche-$(git --git-dir=../quiche/.git rev-parse --short HEAD)" \
--with-quiche=/opt/quiche &&\
make && \
@@ -70,6 +72,9 @@ RUN curl -O https://nginx.org/download/nginx-$NGINX_VERSION.tar.gz && \
FROM ubuntu:20.04
RUN apt-get update && \
DEBIAN_FRONTEND=noninteractive apt-get install -y libpcre3 libbrotli1
COPY --from=builder /usr/sbin/nginx /usr/sbin/
COPY --from=builder /etc/nginx/ /etc/nginx/
+7 -7
View File
@@ -3,12 +3,10 @@ Nginx compiled with *BoringSSL* and *quiche* for *HTTP3* support, *Brotli* suppo
## version
nginx version: nginx/1.19.6 (quiche-ad9d933)
quiche 0.9.0
nginx version: nginx/1.16.1 (quiche-28ef289f)
quiche 0.18.0
Based on ubuntu:20.04, size 109MB
Link for [quiche + nginx manual](https://github.com/cloudflare/quiche/tree/master/extras/nginx)
Link for [quiche + nginx manual](https://github.com/cloudflare/quiche/tree/master/nginx)
### usage
- get certs from certbot in /etc/letsencrypt/
@@ -25,9 +23,11 @@ docker run -it --rm --name certbot \
- create nginx.conf like in example
`docker run --name nginx -d -p 80:80 -p 443:443/tcp -p 443:443/udp -v ${PWD}/temp/letsencrypt/:/opt/nginx/certs/ -v ${PWD}/nginx.conf:/etc/nginx/nginx.conf ymuski/nginx-quic`
```sh
# NOTE: --privileged needed for setsockopt(SO_TXTIME) access
docker run --name nginx --privileged -d -p 80:80 -p 443:443/tcp -p 443:443/udp -v ${PWD}/temp/letsencrypt/:/opt/nginx/certs/ -v ${PWD}/nginx.conf:/etc/nginx/nginx.conf ymuski/nginx-http3
```
`docker run --name nginx -d -p 80:80 -p 443:443/tcp -p 443:443/udp -v /etc/letsencrypt/:/opt/nginx/certs/ -v /opt/nginx/conf/example.nginx.conf:/etc/nginx/nginx.conf ymuski/nginx-quic`
### Checking
+2 -2
View File
@@ -51,7 +51,7 @@ http {
}
# Add Alt-Svc header to negotiate HTTP/3.
add_header alt-svc 'h3-27=":443"; ma=86400, h3-28=":443"; ma=86400, h3-29=":443"; ma=86400, h3=":443"; ma=86400';
add_header alt-svc 'h3=":443"; ma=86400';
location / {
root html;
@@ -62,7 +62,7 @@ http {
return 200 "http3 on $hostname";
add_header Content-Type text/plain;
# Add Alt-Svc header to negotiate HTTP/3.
add_header alt-svc 'h3-27=":443"; ma=86400, h3-28=":443"; ma=86400, h3-29=":443"; ma=86400, h3=":443"; ma=86400';
add_header alt-svc 'h3=":443"; ma=86400';
}
}