Files
EpicNext-Cms/deployment/proxy/nginx.conf
T
openhands e3c010f383 fix(proxy): raise nginx worker rlimit above worker_connections
nginx inherited systemd's soft LimitNOFILE of 1024, so every start logged
"2048 worker_connections exceed open file resource limit: 1024" and the
worker_connections value could not actually be reached.

Set worker_rlimit_nofile to 65536. Bounded from above by a systemd drop-in
at /etc/systemd/system/nginx.service.d/override.conf (LimitNOFILE=65536),
since the master's hard limit caps what workers may request.
2026-10-01 17:11:04 +02:00

60 lines
2.2 KiB
Nginx Configuration File

# Canonical nginx config for the EpicNabbo CMS edge.
# Source of truth: repository deployment/proxy/nginx-cms.conf (the site block)
# and this file. Installed/synced by scripts/nginx-sync.sh so it cannot be
# lost again while nginx keeps running on an in-memory copy.
#
# Traffic path: Cloudflare -> Traefik (:443) -> nginx (:9443) -> CMS (:3002),
# with direct Cloudflare-origin and game-client (ws.epicnabbo.nl) connections
# also terminating on :9443.
# nginx is the last layer that can still rewrite Cache-Control, so it owns the
# headers it adds explicitly; everything proxied to the CMS is passed through
# untouched unless this file says otherwise.
user www-data;
worker_processes auto;
# Raise the file-descriptor rlimit for the workers. Must stay <= the master's
# RLIMIT_NOFILE *hard* limit, otherwise nginx refuses to start with
# "setrlimit(RLIMIT_NOFILE) failed". Bounded from above by the systemd drop-in
# /etc/systemd/system/nginx.service.d/override.conf (LimitNOFILE=65536).
worker_rlimit_nofile 65536;
pid /run/nginx.pid;
error_log /var/log/nginx/error.log warn;
events {
worker_connections 2048;
use epoll;
}
http {
include /etc/nginx/mime.types;
default_type application/octet-stream;
# Compression is done once, at the edge (Traefik / Cloudflare). Enabling
# gzip here too would double-compress proxied responses and fight Vary.
gzip off;
sendfile on;
tcp_nopush on;
server_tokens off;
keepalive_timeout 30s;
client_max_body_size 64m;
client_body_buffer_size 16k;
client_header_buffer_size 1k;
large_client_header_buffers 4 8k;
# Blue/green cutover: ci-deploy.sh writes the active upstream here, and
# `proxy_pass http://cms_app` below follows it via graceful nginx -s reload.
upstream cms_app {
include /etc/nginx/snippets/cms_upstream_servers.conf;
}
# Cache policy maps and server blocks live in the site file so they are
# synced together and can never drift apart.
include /etc/nginx/sites-enabled/*.conf;
# Trusted edge / real-IP handling (regenerated by scripts/cf-ips-sync.sh
# from the live Cloudflare ranges; installed via scripts/nginx-sync.sh).
include /etc/nginx/conf.d/cloudflare-ips.conf;
}