for f in "nginx-$NGINX_VER-1.el9.ngx.x86_64.rpm" \
"pcre2-10.42-1.el9.x86_64.rpm" \
"openssl-libs-3.2.2-1.el9.x86_64.rpm"; do
printf '%s placeholder rpm\n' "$f" > "$DIST/$f"
done
(cd "$DIST" && sha256sum -- *.rpm > SHA256SUMS)
(cd "$DIST" && sha256sum -c SHA256SUMS --quiet) \
&& echo " sha256 일치, 설치를 진행합니다"
run dnf localinstall -y "$DIST"/*.rpm
run systemctl enable nginx== 1. RPM 반입과 오프라인 설치 ==
인터넷 PC 가 게시한 값과 비교할 체크섬:
916348d20a6c1013b7f144f6457591c895d7c1f6e96c6ce26ca97c257aac7b6b *nginx-1.26.2-1.el9.ngx.x86_64.rpm
9d5a48d91907e44032f4cc6857a6b658d8d9fad38ce5f506f26af72a849728c2 *openssl-libs-3.2.2-1.el9.x86_64.rpm
41fb1069e516931601e824c7b6bd0d76965253cd8aa2bd1f5aa2a8fb7ef662cc *pcre2-10.42-1.el9.x86_64.rpm
sha256 일치, 설치를 진행합니다
[dry] dnf localinstall -y WORK/dist/nginx-1.26.2-1.el9.ngx.x86_64.rpm WORK/dist/openssl-libs-3.2.2-1.el9.x86_64.rpm WORK/dist/pcre2-10.42-1.el9.x86_64.rpm
[dry] systemctl enable nginx
RPM 은 nginx 계정과 systemd 유닛을 함께 설치합니다체크섬 파일(SHA256SUMS)로 세 개 RPM 을 한 번에 검증한 뒤에만 dnf localinstall 로 넘어갑니다. RPM 은 이 한 번의 설치로 계정과 유닛까지 함께 준비됩니다.
CONF_OPTS="--prefix=$BASE/nginx --sbin-path=$BASE/nginx/sbin/nginx"
CONF_OPTS="$CONF_OPTS --conf-path=$BASE/nginx/conf/nginx.conf"
CONF_OPTS="$CONF_OPTS --pid-path=$BASE/nginx/run/nginx.pid"
CONF_OPTS="$CONF_OPTS --with-http_ssl_module --with-http_realip_module"
CONF_OPTS="$CONF_OPTS --with-stream --with-http_v2_module"
run bash -c "cd $BUILD && ./configure $CONF_OPTS"
run bash -c "cd $BUILD && make -j\$(nproc)"
run bash -c "cd $BUILD && make install"== 2. 소스 빌드 의존성과 configure 옵션 ==
[dry] dnf install -y gcc make pcre2-devel zlib-devel openssl-devel
configure 옵션:
--prefix=/app/nginx
--sbin-path=/app/nginx/sbin/nginx
--conf-path=/app/nginx/conf/nginx.conf
--pid-path=/app/nginx/run/nginx.pid
--with-http_ssl_module
--with-http_realip_module
--with-stream
--with-http_v2_module
== 3. 소스 빌드 make·make install ==
configure 스크립트 문법 확인: 이상 없음
[dry] bash -c cd WORK/build/nginx-1.26.2 && ./configure --prefix=/app/nginx --sbin-path=/app/nginx/sbin/nginx --conf-path=/app/nginx/conf/nginx.conf --pid-path=/app/nginx/run/nginx.pid --with-http_ssl_module --with-http_realip_module --with-stream --with-http_v2_module
[dry] bash -c cd WORK/build/nginx-1.26.2 && make -j$(nproc)
[dry] bash -c cd WORK/build/nginx-1.26.2 && make install
make install 이 끝나면 $BASE/nginx 아래 sbin·conf·logs 가 생깁니다--prefix 로 지정한 경로가 이후 --sbin-path·--conf-path·--pid-path 기본값의 뿌리가 됩니다. 옵션을 명시하면 나중에 폴더 구조를 읽을 때 헷갈리지 않습니다.
cat > "$NCONF/nginx.conf" <<EOF
user nginx;
worker_processes auto;
error_log $BASE/nginx/logs/error.log warn;
pid $BASE/nginx/run/nginx.pid;
events {
worker_connections 1024;
}
http {
include mime.types;
default_type application/octet-stream;
sendfile on;
keepalive_timeout 65;
include $BASE/nginx/conf/conf.d/*.conf;
}
EOF
awk 'BEGIN{o=0;c=0}
{o+=gsub(/{/,"{"); c+=gsub(/}/,"}")}
END{ if (o==c) printf " 중괄호 짝 검사 통과: 여는 %d 닫는 %d\n", o, c }' \
"$NCONF/nginx.conf"
run "$BASE/nginx/sbin/nginx" -t -c "$NCONF/nginx.conf"== 5. 폴더 구조와 nginx.conf 골격 ==
생성된 폴더:
WORK/app/nginx
WORK/app/nginx/conf
WORK/app/nginx/html
WORK/app/nginx/logs
WORK/app/nginx/run
WORK/app/nginx/sbin
== 6. 설정 검증 ==
중괄호 짝 검사 통과: 여는 2 닫는 2
[dry] /app/nginx/sbin/nginx -t -c WORK/app/nginx/conf/nginx.confconf.d 는 conf 폴더 안에 있어 최상위 목록에는 보이지 않습니다. 중괄호 짝 검사를 실제 파일에 대해 먼저 하고, nginx -t 로 다시 한 번 확인하는 이중 점검입니다.
cat > "$UNIT" <<EOF
[Service]
Type=forking
PIDFile=$BASE/nginx/run/nginx.pid
ExecStartPre=$BASE/nginx/sbin/nginx -t
ExecStart=$BASE/nginx/sbin/nginx
ExecReload=/bin/kill -s HUP \$MAINPID
ExecStop=/bin/kill -s QUIT \$MAINPID
EOF
run firewall-cmd --permanent --add-service=http
run firewall-cmd --permanent --add-service=https
run firewall-cmd --reload
run setsebool -P httpd_can_network_connect 1== 7. systemd 유닛 작성과 확인 ==
nginx.service 필수 키 확인: 이상 없음
[dry] systemctl daemon-reload
RPM 설치는 유닛을 이미 포함해 이 단계가 필요 없습니다
== 8. 방화벽과 SELinux ==
[dry] firewall-cmd --permanent --add-service=http
[dry] firewall-cmd --permanent --add-service=https
[dry] firewall-cmd --reload
[dry] setsebool -P httpd_can_network_connect 1ExecStartPre 가 nginx -t 를 먼저 돌리므로 문법이 깨진 설정으로는 애초에 기동이 안 됩니다. 방화벽과 SELinux 는 둘 다 열어야 하며, 하나만 열면 여전히 접근이 막힙니다.