Nginx Web Server+Nodejs Https proxy +Antmedia Https proxy

— ์•„๋ž˜๋Š” nginx๋ฅผ ์›น์„œ๋ฒ„๋กœ ์‚ฌ์šฉํ•˜๊ณ  nodejs https ํ”„๋ก์‹œ Andmedia server ์˜ httpsํ”„๋ก์‹œํ•˜๋Š” ์„ค์ •์ž…๋‹ˆ๋‹ค.
Below is the configuration for using nginx as a web server and nodejs https proxy Andmedia server’s https proxy.

https://host.domain.com/nodejs/ โ†’ Node.js ์„œ๋ฒ„ (/nodejs/)๋ฅผ ํ†ตํ•ด ์ ‘์†ํ–ˆ์Šต๋‹ˆ๋‹ค. / You are accessing the Node.js server (/nodejs/).

https://host.domain.com/nodejs/login โ†’ Node.js ์„œ๋ฒ„ (/nodejs/login)๋ฅผ ํ†ตํ•ด ์ ‘์†ํ–ˆ์Šต๋‹ˆ๋‹ค. / You connected via the Node.js server (/nodejs/login).

https://host.domain.com/web/ โ†’ ์ •์  ํŒŒ์ผ(index.html) / Static file(index.html)

https://host.domain.com/LiveApp/ โ†’ Ant Media Server

-Nginx์˜ ๋ฃจํŠธ ๋””๋ ‰ํ† ๋ฆฌ ์ฒ˜๋ฆฌ๊ฐ€ Nodejs๋ณด๋‹ค ๋จผ์ € ์‹คํ–‰๋˜๋ฏ€๋กœ ์„ค์ •์ด ์ค‘๋ณต๋˜๋ฉด nodejs ‘/’ ๋Š”์‹คํ–‰์ด ์•ˆ๋ฉ๋‹ˆ๋‹ค.
Since Nginx’s root directory processing is executed before Nodejs, if the settings are duplicated, nodejs ‘/’ will not be executed.

-nodejs๊ตฌ์„ฑ์‹œ /nodejs/์ฒ˜๋Ÿผ ๋ผ์šฐํ„ฐ์— ์ ‘๋‘์–ด๋ฅผ ๋‹ค ๋ถ™์—ฌ์„œ ๊ตฌ์„ฑํ•˜๋Š” ๊ฒƒ์„ ์ถ”์ฒœํ•ฉ๋‹ˆ๋‹ค.(๋ฃจํŠธ๋กœ ์‹คํ–‰์‹œ nginx์ฒ˜๋ฆฌ๊ฐ€ ์šฐ์„ ์ด๋ฏ€๋กœ ์‹คํ–‰ ๋˜์ง€ ์•Š์„ ์ˆ˜ ์žˆ์Œ)
When configuring nodejs, it is recommended to configure it by adding a prefix to the router, such as /nodejs/. (When running as root, nginx processing takes priority, so it may not run.)

-์š”์ฒญ ์ฒ˜๋ฆฌ ์„ค๋ช… / Request Processing Description

์š”์ฒญ ๊ฒฝ๋กœ
request path
์ฒ˜๋ฆฌ์ฃผ์ฒด
Processing entity
์„ค๋ช…
explanation
/Nginx์ •์  ํŒŒ์ผ /var/www/html/index.html ์ œ๊ณต
Static file /var/www/html/index.html
/nodejs/Node.jsNginx๊ฐ€ ํ”„๋ก์‹œ๋กœ ์ „๋‹ฌ
Nginx proxying
/LiveApp/Ant MediaNginx๊ฐ€ ํ”„๋ก์‹œ๋กœ ์ „๋‹ฌ
Nginx proxying
๊ธฐํƒ€ etcNginxtry_files๋กœ ์ •์  ํŒŒ์ผ ํ™•์ธ ํ›„ ์—†์œผ๋ฉด 404
Check static files with try_files and output 404

— Nginx location /nodejs/ + proxy_pass http://localhost:3000/nodejs/;
Nginx๋Š” ์š”์ฒญ ๊ฒฝ๋กœ์—์„œ location /nodejs/ ์ดํ›„์˜ ๊ฒฝ๋กœ(์ฆ‰, /admin)๋ฅผ ์ž˜๋ผ์„œ proxy_pass ๋’ค์— ๋ถ™์ž…๋‹ˆ๋‹ค.
Nginx will cut off the path after location /nodejs/ ( /admin ) from the request path and append it after proxy_pass.
ํ•˜์ง€๋งŒ proxy_pass์— ์Šฌ๋ž˜์‹œ๋กœ ๋๋‚˜๋Š” ๊ฒฝ๋กœ๊ฐ€ ์žˆ์œผ๋ฉด, ์ž˜๋ฆฐ ๊ฒฝ๋กœ๋ฅผ ๊ทธ๋Œ€๋กœ ๋ถ™์—ฌ์„œ ์ „๋‹ฌํ•ฉ๋‹ˆ๋‹ค.
However, if proxy_pass contains a path that ends with a slash, the truncated path is passed as is

์š”์ฒญ: https://host.damain.com/nodejs/admin
location: /nodejs/
proxy_pass: http://localhost:3000/nodejs/

โ†’ ์ „๋‹ฌ: http://localhost:3000/nodejs/admin

Node.js๋Š” ๊ทธ๋ƒฅ ์ •์ƒ์ ์ธ /nodejs/admin ๊ฒฝ๋กœ๋ฅผ ๋ฐ›๊ฒŒ ๋ฉ๋‹ˆ๋‹ค.

Nginx(/etc/nginx/sites-available/default) ์„ค์ •

— ๊ทธ๋Ÿฐ๋ฐ ๋งŒ์•ฝ proxy_pass๊ฐ€ ์Šฌ๋ž˜์‹œ ์—†์ด ๋๋‚œ๋‹ค๋ฉด?
But what if proxy_pass ends without a slash?

proxy_pass http://localhost:3000/nodejs;   # ์Šฌ๋ž˜์‹œ ์—†์Œ / no slash

์ด๋Ÿด ๊ฒฝ์šฐ Nginx๋Š” ์š”์ฒญ ๊ฒฝ๋กœ ์ „์ฒด๋ฅผ proxy_pass์˜ ๋’ค์— ๋ถ™์ด์ง€ ์•Š๊ณ , ๊ทธ๋ƒฅ ๋ฎ์–ด์”Œ์›๋‹ˆ๋‹ค.
In this case, Nginx will not append the entire request path to proxy_pass, but will simply overwrite it.

https://โ€ฆ/nodejs/admin โ†’ http://localhost:3000/nodejsadmin

— ๊ฒฐ๋ก ์€ nginx์—์„œ ๊ฒฝ๋กœ ์„ค์ •์„ ์˜ฌ๋ฐ”๋กœ ํ•˜๋ฉด ํ”„๋ก์‹œ๋œ ๊ฒฐ๊ณผ๊ฐ’(http://localhost:3000/nodejs/admin)์„ ๊ฐ€์ง€๊ณ  nodejs์—์„œ ๊ฒฐ๊ณผ๊ฐ’์„ ์ฒ˜๋ฆฌํ•ฉ๋‹ˆ๋‹ค.
The bottom line is that if you set the path correctly in nginx, the proxied result (http://localhost:3000/nodejs/admin) will be used to process the result in nodejs.

-๋งˆ์ง€๋ง‰์œผ๋กœ ์ •๋ฆฌํ•˜์ž๋ฉด…
Finally, to summarize

1.nginx์˜ ์„ค์ •์ด nodejs๋ณด๋‹ค ์šฐ์„ ์ˆœ์œ„๊ฐ€ ๋†’๋‹ค. ๊ทธ๋Ÿฌ๋ฏ€๋กœnodejs๋ฅผ ๋ฃจํŠธ(/)๋ผ์šฐํ„ฐ๋ฅผ ์‚ฌ์šฉํ•˜๋ฉด ์˜ค๋ฅ˜๊ฐ€ ๋ฐœ์ƒ ํ•  ์ˆ˜ ์žˆ๋‹ค.
2.nginx ์„ค์ •์˜ proxy_pass http://localhost:3000/nodejs/;์—์„œ ๋งˆ์ง€๋ง‰ / ๊ฐ€ ์ค‘์š”ํ•˜๋‹ค.
3.nginx์„ค์ •์ด ์˜ฌ๋ฐ”๋ฅด๋‹ค๋ฉด nodejs๋Š” nginx๋ฅผ ๋ชจ๋ฅด๋‹ˆ ํ”„๋ก์‹œ ์ฒ˜๋ฆฌ๋œ ๋ถ€๋ถ„์˜ ๋ผ์šฐํ„ฐ ๋ถ€๋ถ„๋งŒ ์ฒ˜๋ฆฌํ•œ๋‹ค.

2.์„ค์ • ๋ฐ ์†Œ์Šค์ฝ”๋“œ

— Nginx(/etc/nginx/sites-available/default) Setting

server {
    listen 443 ssl;
    server_name host.domain.com;

    ssl_certificate /etc/letsencrypt/live/media.freelifemakers.org/fullchain.pem;
    ssl_certificate_key /etc/letsencrypt/live/media.freelifemakers.org/privkey.pem;
    include /etc/letsencrypt/options-ssl-nginx.conf;
    ssl_dhparam /etc/letsencrypt/ssl-dhparams.pem;

    # ์ •์  ์›น ํŒŒ์ผ / static web files (/web/)
    location /web/ {
        alias /var/www/html/web/;
        index index.html;
        try_files $uri $uri/ =404;
    }

    # Ant Media Server ์—ฐ๋™ / antmedia server integration (/LiveApp/)
    location /LiveApp/ {
        proxy_pass http://localhost:5080/LiveApp/;
        proxy_http_version 1.1;
        proxy_set_header Upgrade $http_upgrade;
        proxy_set_header Connection "upgrade";
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;
    }

    # Node.js ์•ฑ ํ”„๋ก์‹œ / Node.js app proxy  (/nodejs/)
    location /nodejs/ {
        proxy_pass http://localhost:3000/nodejs/;  # <=== ์ค‘์š”: /nodejs/๋กœ ํ”„๋ก์‹œ
        proxy_http_version 1.1;
        proxy_set_header Upgrade $http_upgrade;
        proxy_set_header Connection "upgrade";
        proxy_set_header Host $host;
        proxy_cache_bypass $http_upgrade;
    }

    # ๋ฃจํŠธ ์ •์  ํŒŒ์ผ / root static file
    location / {
        root /var/www/html/;
        index index.html;
        try_files $uri $uri/ =404;
    }
}

# HTTP ์ ‘๊ทผ ์‹œ HTTPS๋กœ ๋ฆฌ๋””๋ ‰์…˜ / 
Redirect to HTTPS when accessing HTTP
server {
    listen 80;
    server_name host.domain.com;
    return 301 https://$host$request_uri;
}

Nodejs test code

const express = require('express');
const app = express();
const port = 3000;

// ๋ฃจํŠธ ๊ฒฝ๋กœ (ํ”„๋ก์‹œ๋ฅผ ํ†ตํ•ด ์ง์ ‘ ์ ‘๊ทผํ•˜๋Š” ๊ฒฝ์šฐ ์‚ฌ์šฉ ์•ˆ๋จ)
app.get("/", (req, res) => {
  res.send("Node.js ์„œ๋ฒ„ (/)๋ฅผ ํ†ตํ•ด ์ ‘์†ํ–ˆ์Šต๋‹ˆ๋‹ค.");
});

// ํ”„๋ก์‹œ๋œ ๊ฒฝ๋กœ
app.get("/nodejs/", (req, res) => {
  res.send("Node.js ์„œ๋ฒ„ (/nodejs/)๋ฅผ ํ†ตํ•ด ์ ‘์†ํ–ˆ์Šต๋‹ˆ๋‹ค.");
});

app.get("/nodejs/admin", (req, res) => {
  res.send("Node.js ์„œ๋ฒ„ (/nodejs/admin)๋ฅผ ํ†ตํ•ด ์ ‘์†ํ–ˆ์Šต๋‹ˆ๋‹ค.");
});

app.get("/nodejs/video", (req, res) => {
  res.send("Node.js ์„œ๋ฒ„ (/nodejs/video)๋ฅผ ํ†ตํ•ด ์ ‘์†ํ–ˆ์Šต๋‹ˆ๋‹ค.");
});

app.get("/nodejs/login", (req, res) => {
  res.send("Node.js ์„œ๋ฒ„ (/nodejs/login)๋ฅผ ํ†ตํ•ด ์ ‘์†ํ–ˆ์Šต๋‹ˆ๋‹ค.");
});

// ํ™•์ธ์šฉ
app.get("/liveapp", (req, res) => {
  res.send("Ant Media Server (/liveapp)์œผ๋กœ ์ง์ ‘ ์ ‘์†ํ–ˆ์Šต๋‹ˆ๋‹ค. (Nginx ํ”„๋ก์‹œ ์„ค์ • ํ™•์ธ์šฉ)");
});

app.listen(port, () => {
  console.log(`Node.js ์„œ๋ฒ„๊ฐ€ http://localhost:${port} ์—์„œ ์‹คํ–‰ ์ค‘์ž…๋‹ˆ๋‹ค.`);
});

Leave a Reply