공공부하자개발 · 영어 학습 노트
리눅스
웹 서버Tomcat · Nginx 설치와 설정0/8 완료
  • 01Tomcat 설치
  • 02Tomcat server.xml 설정
  • 03Tomcat 인스턴스와 JVM 옵션
  • 04Tomcat 보안과 운영 점검
  • 05nginx 설치
  • 06nginx 리버스 프록시
  • 07nginx HTTPS
  • 08nginx 로드밸런싱과 운영
사이트 소개개인정보처리방침연락처
© 2026 공부하자
홈 › 웹 서버 › 05 / 8

nginx 설치

섹션 7진행 0 / 8
1왜 배우는가2핵심 원리3코드 예제4응용 변형 예제5자주 하는 실수 (Tip)6연습 문제7정리‹ 이전다음 ›

3. 코드 예제

예제 1: RPM 반입과 오프라인 설치 — 01_nginx_install.sh 발췌

bash
for f in "nginx-$NGINX_VER-1.el9.ngx.x86_64.rpm" \
         "pcre2-10.42-1.el9.x86_64.rpm" \
         "openssl-libs-3.2.2-1.el9.x86_64.rpm"; do
  printf '%s placeholder rpm\n' "$f" > "$DIST/$f"
done
(cd "$DIST" && sha256sum -- *.rpm > SHA256SUMS)
(cd "$DIST" && sha256sum -c SHA256SUMS --quiet) \
  && echo "  sha256 일치, 설치를 진행합니다"
run dnf localinstall -y "$DIST"/*.rpm
run systemctl enable nginx
text
== 1. RPM 반입과 오프라인 설치 ==
  인터넷 PC 가 게시한 값과 비교할 체크섬:
916348d20a6c1013b7f144f6457591c895d7c1f6e96c6ce26ca97c257aac7b6b *nginx-1.26.2-1.el9.ngx.x86_64.rpm
9d5a48d91907e44032f4cc6857a6b658d8d9fad38ce5f506f26af72a849728c2 *openssl-libs-3.2.2-1.el9.x86_64.rpm
41fb1069e516931601e824c7b6bd0d76965253cd8aa2bd1f5aa2a8fb7ef662cc *pcre2-10.42-1.el9.x86_64.rpm
  sha256 일치, 설치를 진행합니다
  [dry] dnf localinstall -y WORK/dist/nginx-1.26.2-1.el9.ngx.x86_64.rpm WORK/dist/openssl-libs-3.2.2-1.el9.x86_64.rpm WORK/dist/pcre2-10.42-1.el9.x86_64.rpm
  [dry] systemctl enable nginx
  RPM 은 nginx 계정과 systemd 유닛을 함께 설치합니다

체크섬 파일(SHA256SUMS)로 세 개 RPM 을 한 번에 검증한 뒤에만 dnf localinstall 로 넘어갑니다. RPM 은 이 한 번의 설치로 계정과 유닛까지 함께 준비됩니다.

예제 2: 소스 빌드 configure·make install — 01_nginx_install.sh 발췌

bash
CONF_OPTS="--prefix=$BASE/nginx --sbin-path=$BASE/nginx/sbin/nginx"
CONF_OPTS="$CONF_OPTS --conf-path=$BASE/nginx/conf/nginx.conf"
CONF_OPTS="$CONF_OPTS --pid-path=$BASE/nginx/run/nginx.pid"
CONF_OPTS="$CONF_OPTS --with-http_ssl_module --with-http_realip_module"
CONF_OPTS="$CONF_OPTS --with-stream --with-http_v2_module"
run bash -c "cd $BUILD && ./configure $CONF_OPTS"
run bash -c "cd $BUILD && make -j\$(nproc)"
run bash -c "cd $BUILD && make install"
text
== 2. 소스 빌드 의존성과 configure 옵션 ==
  [dry] dnf install -y gcc make pcre2-devel zlib-devel openssl-devel
  configure 옵션:
    --prefix=/app/nginx
    --sbin-path=/app/nginx/sbin/nginx
    --conf-path=/app/nginx/conf/nginx.conf
    --pid-path=/app/nginx/run/nginx.pid
    --with-http_ssl_module
    --with-http_realip_module
    --with-stream
    --with-http_v2_module
== 3. 소스 빌드 make·make install ==
  configure 스크립트 문법 확인: 이상 없음
  [dry] bash -c cd WORK/build/nginx-1.26.2 && ./configure --prefix=/app/nginx --sbin-path=/app/nginx/sbin/nginx --conf-path=/app/nginx/conf/nginx.conf --pid-path=/app/nginx/run/nginx.pid --with-http_ssl_module --with-http_realip_module --with-stream --with-http_v2_module
  [dry] bash -c cd WORK/build/nginx-1.26.2 && make -j$(nproc)
  [dry] bash -c cd WORK/build/nginx-1.26.2 && make install
  make install 이 끝나면 $BASE/nginx 아래 sbin·conf·logs 가 생깁니다

--prefix 로 지정한 경로가 이후 --sbin-path·--conf-path·--pid-path 기본값의 뿌리가 됩니다. 옵션을 명시하면 나중에 폴더 구조를 읽을 때 헷갈리지 않습니다.

예제 3: nginx.conf 골격과 검증 — 01_nginx_install.sh 발췌

bash
cat > "$NCONF/nginx.conf" <<EOF
user nginx;
worker_processes auto;
error_log $BASE/nginx/logs/error.log warn;
pid $BASE/nginx/run/nginx.pid;

events {
    worker_connections 1024;
}

http {
    include       mime.types;
    default_type  application/octet-stream;
    sendfile      on;
    keepalive_timeout  65;
    include $BASE/nginx/conf/conf.d/*.conf;
}
EOF
awk 'BEGIN{o=0;c=0}
{o+=gsub(/{/,"{"); c+=gsub(/}/,"}")}
END{ if (o==c) printf "  중괄호 짝 검사 통과: 여는 %d 닫는 %d\n", o, c }' \
  "$NCONF/nginx.conf"
run "$BASE/nginx/sbin/nginx" -t -c "$NCONF/nginx.conf"
text
== 5. 폴더 구조와 nginx.conf 골격 ==
  생성된 폴더:
WORK/app/nginx
WORK/app/nginx/conf
WORK/app/nginx/html
WORK/app/nginx/logs
WORK/app/nginx/run
WORK/app/nginx/sbin
== 6. 설정 검증 ==
  중괄호 짝 검사 통과: 여는 2 닫는 2
  [dry] /app/nginx/sbin/nginx -t -c WORK/app/nginx/conf/nginx.conf

conf.d 는 conf 폴더 안에 있어 최상위 목록에는 보이지 않습니다. 중괄호 짝 검사를 실제 파일에 대해 먼저 하고, nginx -t 로 다시 한 번 확인하는 이중 점검입니다.

예제 4: systemd 유닛과 방화벽·SELinux — 01_nginx_install.sh 발췌

bash
cat > "$UNIT" <<EOF
[Service]
Type=forking
PIDFile=$BASE/nginx/run/nginx.pid
ExecStartPre=$BASE/nginx/sbin/nginx -t
ExecStart=$BASE/nginx/sbin/nginx
ExecReload=/bin/kill -s HUP \$MAINPID
ExecStop=/bin/kill -s QUIT \$MAINPID
EOF
run firewall-cmd --permanent --add-service=http
run firewall-cmd --permanent --add-service=https
run firewall-cmd --reload
run setsebool -P httpd_can_network_connect 1
text
== 7. systemd 유닛 작성과 확인 ==
  nginx.service 필수 키 확인: 이상 없음
  [dry] systemctl daemon-reload
  RPM 설치는 유닛을 이미 포함해 이 단계가 필요 없습니다
== 8. 방화벽과 SELinux ==
  [dry] firewall-cmd --permanent --add-service=http
  [dry] firewall-cmd --permanent --add-service=https
  [dry] firewall-cmd --reload
  [dry] setsebool -P httpd_can_network_connect 1

ExecStartPre 가 nginx -t 를 먼저 돌리므로 문법이 깨진 설정으로는 애초에 기동이 안 됩니다. 방화벽과 SELinux 는 둘 다 열어야 하며, 하나만 열면 여전히 접근이 막힙니다.

예제 직접 실행

아래 폴더의 셸 스크립트를 RHEL 또는 Git Bash 에서 실행합니다. 리눅스 전용 명령은 DRY_RUN=1 을 붙이면 실행하지 않고 명령만 출력합니다.

cd web-src/05_nginx_install
ls *.sh
DRY_RUN=1 bash <스크립트>.sh
코드 예제
  • 예제 1: RPM 반입과 오프라인 설치 — 01_nginx_install.sh 발췌
  • 예제 2: 소스 빌드 configure·make install — 01_nginx_install.sh 발췌
  • 예제 3: nginx.conf 골격과 검증 — 01_nginx_install.sh 발췌
  • 예제 4: systemd 유닛과 방화벽·SELinux — 01_nginx_install.sh 발췌
이전 섹션2 핵심 원리3 / 7다음 섹션4 응용 변형 예제