Welcome! Log In Create A New Profile

Advanced

Re: nginx as SSL terminating server

W. Andrew Loe III
July 28, 2010 06:10PM
Quite simply: no.

You cannot stop the first nginx from buffering requests. You can (and
should!) stop it from buffering responses with the proxy_buffering
directive:

proxy_buffering off;

I have a similar setup (minus the haproxy layer,
passenger_global_queue is good enough) and would also like to do this.
I've tried messing with the proxy buffer sizes but it doesn't seem to
make any significant difference with large uploads and opens up DoS
opportunities.

On Tue, Jul 27, 2010 at 12:11 PM, joshua <nginx-forum@nginx.us> wrote:
> We have the following setup:
>
> firewall --> single nginx instance (SSL termination) --> haproxy -->
> multiple nginx/unicorn instances (via unix socket)
>
> Is it recommendable to turn request buffering off at the first nginx?
> Ideally things like uploads would be buffered at the final nginx
> instances. The first one is only there to terminate SSL and pass
> requests on to haproxy.
>
> Thanks,
> Joshua Sierles
>
> Posted at Nginx Forum: http://forum.nginx.org/read.php?2,113599,113599#msg-113599
>
>
> _______________________________________________
> nginx mailing list
> nginx@nginx.org
> http://nginx.org/mailman/listinfo/nginx
>

_______________________________________________
nginx mailing list
nginx@nginx.org
http://nginx.org/mailman/listinfo/nginx
Subject Author Posted

nginx as SSL terminating server

joshua July 27, 2010 03:11PM

Re: nginx as SSL terminating server

W. Andrew Loe III July 28, 2010 06:10PM



Sorry, only registered users may post in this forum.

Click here to login

Online Users

Guests: 149
Record Number of Users: 8 on April 13, 2023
Record Number of Guests: 421 on December 02, 2018
Powered by nginx      Powered by FreeBSD      PHP Powered      Powered by MariaDB      ipv6 ready