SlideShare uma empresa Scribd logo
1 de 45
Baixar para ler offline
NGINX SCRIPTING
EXTENDING NGINX FUNCTIONALITIES WITH LUA
          Tony Fabeen / @tonyfabeen / SlimStacks
WHO AM I
NGINX ("ENGINE-X")
High performance HTTP, POP/IMAP and reverse proxy server.
Started in 2002 by Igor Sysoev, public in 2004.
Entirely written in C.
Hosts nearly 12.18% of active sites across all domains.
Nginx.com in 2011.
MASTER WORKER MODEL
$p ax|ge nix
        s u rp gn

ro 339..nix mse poes/p/gn/bnnix
 ot 12 . gn: atr rcs otnixsi/gn

ww 330..nix wre poes
 w 13 . gn: okr rcs
MASTER PROCESS
reading and validating configuration
creating, binding and closing sockets
starting, terminating and maintaining the configured number of w r e
                                                                okr
processes
re-opening log files
compiling embedded Perl scripts
WORKER PROCESS
Do all important stuff
Handle connection from clients
Reverse Proxy and Filtering functionalities
REQUEST PROCESSING
REQUEST PHASES
SERVER REWRITE PHASE
request URI transformation on virtual server level
FIND CONFIG PHASE
configuration location lookup
REWRITE PHASE
request URI transformation on location level
ACCESS PHASE
access restrictions check phase
TRY FILES PHASE
try_files directive processing phase
CONTENT PHASE
content generation phase
LOG PHASE
 logging phase
MODULARITY
Core Module
Functional Modules
CORE MODULE
Event Loop
Module execution control
FUNCTIONAL MODULES
Read from / Write to Network and Storage
Transform Content
Outbound Filtering
Server Side Includes
Upstream Server communication
...etc
LUA ON THE STAGE
A BIT OF LUA
 Created in Brazil
 Portable
 Simple
 Small
 Easy to embed
 Fast
OSS USING LUA
LUA NGINX MODULE
           https://github.com/chaoslawful/lua-nginx-module/
Created by TaoBao.com Engineers
High concurrent and non-blocking request processing
Programs can be written in the plain-old sequential way
Nginx takes care of I/O operations and Lua Nginx Module restore the
context and resume the program logic
LUA NGINX MODULE
         https://github.com/chaoslawful/lua-nginx-module
Introduces directives for running Lua inside Nginx
Exposes the Nginx environment to Lua via an Api
It's fast
Is even faster when compiled with LUA JIT(Just in Time Compiler)
NGINX LUA API
DIRECTIVES
Configuration directives serve as gateways to the Lua API within the
                           nginx.conf file.

     cnetb_u LASRP_TIG
     otn_yla U_CITSRN
     rwieb_u LASRP_TIG
     ert_yla U_CITSRN
     acs_ylaLASRP_TIG
     cesb_u U_CITSRN
     cnetb_u_iePT_OLASRP_IE
     otn_ylafl AHT_U_CITFL
     rwieb_u_iePT_OLASRP_IE
     ert_ylafl AHT_U_CITFL
     acs_ylafl PT_OLASRP_IE
     cesb_u_ie AHT_U_CITFL
      Unless you set l a c d _ a h to o f modules will be loaded once on the first request.
                      u_oecce f ,
NGX PACKAGE
Nginx Environment is exposed via n x
                                  g package
     nxagulag
      g.r.r_r
     nxvrVRAL_AE
      g.a.AIBENM
     nxhae.EDRATIUE
      g.edrHAE_TRBT
     nxcx
      g.t
HELLO WORLD !
  lcto /el-srb-u {
   oain hloue-yla
    dfuttp "etpan;
     eal_ye tx/li"
    cnetb_u '
     otn_yla
      nxsy"el," nxvragnm,""
       g.a(Hlo , g.a.r_ae !)
    ';
  }

  lcto /el-srb-gn {
   oain hloue-ynix
    eh "el,$r_ae!;
     co Hlo agnm "
  }

$cr ht:/oahs/el-srb-u?aeDvnap
  ul tp/lclothloue-ylanm=eISma
 Hlo Dvnap !
  el, eISma
$cr ht:/oahs/el-srb-gn?aeDvnap
  ul tp/lclothloue-ynixnm=eISma
 Hlo Dvnap !
  el, eISma
NGINX VARS
    lcto /csignixag {
     oain aesn-gn-rs
      st$is 3;
      e frt 5
      st$eod6;
      e scn 5

        stb_u $u '
         e_yla sm
          rtr nxvrfrt+nxvrscn
           eun g.a.is  g.a.eod
        ';

        eh "h smi $u"
        co Te u s sm;
    }

$cr ht:/oahs/csignixag
  ul tp/lclotaesn-gn-rs
 Tesmi 9
  h u s 9
NGINX SUBREQUESTS
lcto /u-urqet {
oain lasbeuss
 cnetb_u '
  otn_yla
  lclrsos =nxlcto.atr(/el-srb-gn?ae
   oa epne   g.oaincpue"hloue-ynixnm=
Dvnap"
eISma)
  i rsos.tts> 50te
   f epnesau = 0 hn
     nxei(epnesau)
     g.xtrsos.tts
  ed
   n

      nxsau =rsos.tts
       g.tts  epnesau
      nxsyrsos.oy
       g.a(epnebd)
    ';
}

$cr ht:/oahs/u-urqet
  ul tp/lclotlasbeuss
 Hlo Dvnap !
  el, eISma
NON BLOCKING I/O SUBREQUESTS
lcto /nltc-nrmn {
 oain aayisiceet
     cnetb_u '
      otn_yla
      lclrsos =nxlcto.atr(/ei"
       oa epne  g.oaincpue"rds,
          {rs={m ="nr,ky=nxvragln})
           ag  cd  ic" e  g.a.r_ik}
      nxsy"nrmne t :,nxvragln)
       g.a(Iceetd o " g.a.r_ik
     ';

}
lcto /ei {
 oain rds

    itra;
     nenl

    stuecp_r $e $r_e;
     e_nsaeui ky agky
    stuecp_r $m $r_m;
     e_nsaeui cd agcd

    rds_ur $m $e;
     ei2qey cd ky
    rds_as1700167;
     ei2ps 2...:39

}


$cr ht:/oahs/nltc-nrmn?ikht:/w.eismacmb
  ul tp/lclotaayisiceetln=tp/wwdvnap.o.r

    Iceetdt :tp/wwdvnap.o.r
     nrmne o ht:/w.eismacmb
FILTERS
HEADER FILTERS
lcto /{
 oain
  poyps ht:/oahs:00
   rx_as tp/lclot88;
  hae_itrb_u 'g.edrSre ="yLtl Sre";
   edrfle_yla nxhae.evr  M ite evr'
}

$cr - - HA ht:/oahs/edrfle
  ul i X ED tp/lclothae-itr
 HT/. 20O
  TP11 0 K
 Dt:Sn 0 Sp21 2:81 GT
  ae u, 9 e 02 11:1 M
 Sre:M Ltl Sre
  evr y ite evr
 CnetTp:tx/tlcastuf8
  otn-ye ethm;hre=t-
 CnetLnt:49
  otn-egh 4
 Cneto:ke-lv
  oncin epaie
 Sau:20O
  tts 0 K
 XFaeOtos smoii
  -rm-pin: aergn
 XXSPoeto:1 md=lc
  -S-rtcin ; oebok
 XCsae ps
  -acd: as
 XRc-ah:ms
  -akCce is
BODY FILTERS
lcto /oyfle {
oain bd-itr
 eh "ycnet;
  co M otn"

    bd_itrb_u '
     oyfle_yla
      nxag1 =srn.sbnxag1,"y,"or)
       g.r[]  tiggu(g.r[] M" Yu"
      nxag2 =tu -stefo ls canbfe
       g.r[]  re -e o r at hi ufr
    ';
}

$cr ht:/oahs/oyfle
  ul tp/lclotbd-itr
 Yu cnet
  or otn
COSOCKETS
Non Blocking, of course
Communicate via TCP or Unix domain sockets
Keepalive mechanism avoid connect/close for each request
COSOCKETS
lcto /ecce-rmla{
oain mmahdfo-u
 cnetb_u '
  otn_yla
  lclsc =nxsce.onc(17001,121
   oa ok  g.oktcnet"2..." 11)
  lclbts er=sc:ed"e fobrrn)
   oa ye, r  oksn(st o a"

     i ntbtste
      f o ye hn
       nxsy"aldt sn. " er
        g.a(fie o ed. n, r)
       rtr
        eun
     ed
      n

     lcldt =sc:eev(
      oa aa   okrcie)
     i ntdt te
      f o aa hn
       nxsy"aldt rciedt."
        g.a(Fie o eev aa.n)
     ed
      n

      nxsy"eut:" dt)
       g.a(Rsl  , aa
    ';

}
SOME LIBRARIES USING PURE COSOCKETS
    https://github.com/agentzh/lua-resty-memcached
    https://github.com/agentzh/lua-resty-redis
    https://github.com/agentzh/lua-resty-mysql
SUMMARY
The Nginx architecture is excellent for highly scalable applications.
Nginx can do a variety of things thanks to module extensions, and one can
resuse those extensions by issuing sub-requests in Lua.
lua-nginx-module makes use of the evented architecture in Nginx,
providing a powerful and performant programming environment.
It's possible to do 100% non-blocking I/O with readable code.
REFERENCES
http://www.aosabook.org/en/nginx.html
http://openresty.org
http://www.evanmiller.org/nginx-modules-guide.html
http://wiki.nginx.org/HttpLuaModule
BOOKS
QUESTIONS

   ?
THANKS
http://www.twitter.com/tonyfabeen

http://www.linkedin.com/in/tonyfabeen

https://github.com/tonyfabeen
Nginx Scripting - Extending Nginx Functionalities with Lua

Mais conteúdo relacionado

Mais procurados

Using Node.js to Build Great Streaming Services - HTML5 Dev Conf
Using Node.js to  Build Great  Streaming Services - HTML5 Dev ConfUsing Node.js to  Build Great  Streaming Services - HTML5 Dev Conf
Using Node.js to Build Great Streaming Services - HTML5 Dev Conf
Tom Croucher
 
Streams are Awesome - (Node.js) TimesOpen Sep 2012
Streams are Awesome - (Node.js) TimesOpen Sep 2012 Streams are Awesome - (Node.js) TimesOpen Sep 2012
Streams are Awesome - (Node.js) TimesOpen Sep 2012
Tom Croucher
 

Mais procurados (20)

Using ngx_lua in UPYUN 2
Using ngx_lua in UPYUN 2Using ngx_lua in UPYUN 2
Using ngx_lua in UPYUN 2
 
Using Node.js to Build Great Streaming Services - HTML5 Dev Conf
Using Node.js to  Build Great  Streaming Services - HTML5 Dev ConfUsing Node.js to  Build Great  Streaming Services - HTML5 Dev Conf
Using Node.js to Build Great Streaming Services - HTML5 Dev Conf
 
Node.js streaming csv downloads proxy
Node.js streaming csv downloads proxyNode.js streaming csv downloads proxy
Node.js streaming csv downloads proxy
 
Application Logging in the 21st century - 2014.key
Application Logging in the 21st century - 2014.keyApplication Logging in the 21st century - 2014.key
Application Logging in the 21st century - 2014.key
 
Streams are Awesome - (Node.js) TimesOpen Sep 2012
Streams are Awesome - (Node.js) TimesOpen Sep 2012 Streams are Awesome - (Node.js) TimesOpen Sep 2012
Streams are Awesome - (Node.js) TimesOpen Sep 2012
 
OWASP Proxy
OWASP ProxyOWASP Proxy
OWASP Proxy
 
Perl Memory Use 201209
Perl Memory Use 201209Perl Memory Use 201209
Perl Memory Use 201209
 
Relayd: a load balancer for OpenBSD
Relayd: a load balancer for OpenBSD Relayd: a load balancer for OpenBSD
Relayd: a load balancer for OpenBSD
 
Using ngx_lua in upyun 2
Using ngx_lua in upyun 2Using ngx_lua in upyun 2
Using ngx_lua in upyun 2
 
tdc2012
tdc2012tdc2012
tdc2012
 
Bootstrapping multidc observability stack
Bootstrapping multidc observability stackBootstrapping multidc observability stack
Bootstrapping multidc observability stack
 
On UnQLite
On UnQLiteOn UnQLite
On UnQLite
 
Nodejs - A quick tour (v6)
Nodejs - A quick tour (v6)Nodejs - A quick tour (v6)
Nodejs - A quick tour (v6)
 
Pf: the OpenBSD packet filter
Pf: the OpenBSD packet filterPf: the OpenBSD packet filter
Pf: the OpenBSD packet filter
 
Новый InterSystems: open-source, митапы, хакатоны
Новый InterSystems: open-source, митапы, хакатоныНовый InterSystems: open-source, митапы, хакатоны
Новый InterSystems: open-source, митапы, хакатоны
 
Tuning Solr for Logs
Tuning Solr for LogsTuning Solr for Logs
Tuning Solr for Logs
 
Node.js in production
Node.js in productionNode.js in production
Node.js in production
 
PL/Perl - New Features in PostgreSQL 9.0 201012
PL/Perl - New Features in PostgreSQL 9.0 201012PL/Perl - New Features in PostgreSQL 9.0 201012
PL/Perl - New Features in PostgreSQL 9.0 201012
 
Top Node.js Metrics to Watch
Top Node.js Metrics to WatchTop Node.js Metrics to Watch
Top Node.js Metrics to Watch
 
Integrating icinga2 and the HashiCorp suite
Integrating icinga2 and the HashiCorp suiteIntegrating icinga2 and the HashiCorp suite
Integrating icinga2 and the HashiCorp suite
 

Destaque

Как и зачем создавать NginX-модуль - теория, практика, профит / Василий Сошни...
Как и зачем создавать NginX-модуль - теория, практика, профит / Василий Сошни...Как и зачем создавать NginX-модуль - теория, практика, профит / Василий Сошни...
Как и зачем создавать NginX-модуль - теория, практика, профит / Василий Сошни...
Ontico
 
Devinsampa nginx-scripting
Devinsampa nginx-scriptingDevinsampa nginx-scripting
Devinsampa nginx-scripting
Tony Fabeen
 

Destaque (20)

OAuth and OpenID Connect for Microservices
OAuth and OpenID Connect for MicroservicesOAuth and OpenID Connect for Microservices
OAuth and OpenID Connect for Microservices
 
Stateless authentication for microservices
Stateless authentication for microservicesStateless authentication for microservices
Stateless authentication for microservices
 
Nginx Internals
Nginx InternalsNginx Internals
Nginx Internals
 
Hacking Nginx at Taobao
Hacking Nginx at TaobaoHacking Nginx at Taobao
Hacking Nginx at Taobao
 
Nginx+lua在阿里巴巴的使用
Nginx+lua在阿里巴巴的使用Nginx+lua在阿里巴巴的使用
Nginx+lua在阿里巴巴的使用
 
Accelerating Nginx Web Server Performance
Accelerating Nginx Web Server PerformanceAccelerating Nginx Web Server Performance
Accelerating Nginx Web Server Performance
 
Running PHP on Nginx / PHP wgtn
Running PHP on Nginx / PHP wgtnRunning PHP on Nginx / PHP wgtn
Running PHP on Nginx / PHP wgtn
 
Webpage Caches - the big picture (WordPress too)
Webpage Caches - the big picture (WordPress too)Webpage Caches - the big picture (WordPress too)
Webpage Caches - the big picture (WordPress too)
 
5 critical-optimizations.v2
5 critical-optimizations.v25 critical-optimizations.v2
5 critical-optimizations.v2
 
Web Performance, Scalability, and Testing Techniques - Boston PHP Meetup
Web Performance, Scalability, and Testing Techniques - Boston PHP MeetupWeb Performance, Scalability, and Testing Techniques - Boston PHP Meetup
Web Performance, Scalability, and Testing Techniques - Boston PHP Meetup
 
Caching and tuning fun for high scalability @ FOSDEM 2012
Caching and tuning fun for high scalability @ FOSDEM 2012Caching and tuning fun for high scalability @ FOSDEM 2012
Caching and tuning fun for high scalability @ FOSDEM 2012
 
基于OpenResty的百万级长连接推送
基于OpenResty的百万级长连接推送基于OpenResty的百万级长连接推送
基于OpenResty的百万级长连接推送
 
High Performance Php My Sql Scaling Techniques
High Performance Php My Sql Scaling TechniquesHigh Performance Php My Sql Scaling Techniques
High Performance Php My Sql Scaling Techniques
 
Nginx lua
Nginx luaNginx lua
Nginx lua
 
Maximizing PHP Performance with NGINX
Maximizing PHP Performance with NGINXMaximizing PHP Performance with NGINX
Maximizing PHP Performance with NGINX
 
Practical ngx_mruby
Practical ngx_mrubyPractical ngx_mruby
Practical ngx_mruby
 
Nginx pres
Nginx presNginx pres
Nginx pres
 
Как и зачем создавать NginX-модуль - теория, практика, профит / Василий Сошни...
Как и зачем создавать NginX-модуль - теория, практика, профит / Василий Сошни...Как и зачем создавать NginX-модуль - теория, практика, профит / Василий Сошни...
Как и зачем создавать NginX-модуль - теория, практика, профит / Василий Сошни...
 
Using ngx_lua / lua-nginx-module in pixiv
Using ngx_lua / lua-nginx-module in pixivUsing ngx_lua / lua-nginx-module in pixiv
Using ngx_lua / lua-nginx-module in pixiv
 
Devinsampa nginx-scripting
Devinsampa nginx-scriptingDevinsampa nginx-scripting
Devinsampa nginx-scripting
 

Semelhante a Nginx Scripting - Extending Nginx Functionalities with Lua

Tips on how to improve the performance of your custom modules for high volume...
Tips on how to improve the performance of your custom modules for high volume...Tips on how to improve the performance of your custom modules for high volume...
Tips on how to improve the performance of your custom modules for high volume...
Odoo
 
Refactoring to symfony components
Refactoring to symfony componentsRefactoring to symfony components
Refactoring to symfony components
Michael Peacock
 
Marko Gargenta_Remixing android
Marko Gargenta_Remixing androidMarko Gargenta_Remixing android
Marko Gargenta_Remixing android
Droidcon Berlin
 
Introduction to Ansible
Introduction to AnsibleIntroduction to Ansible
Introduction to Ansible
Mattias Gees
 

Semelhante a Nginx Scripting - Extending Nginx Functionalities with Lua (20)

Noah Zoschke at Waza 2013: Heroku Secrets
Noah Zoschke at Waza 2013: Heroku SecretsNoah Zoschke at Waza 2013: Heroku Secrets
Noah Zoschke at Waza 2013: Heroku Secrets
 
Beginner workshop to angularjs presentation at Google
Beginner workshop to angularjs presentation at GoogleBeginner workshop to angularjs presentation at Google
Beginner workshop to angularjs presentation at Google
 
Tips on how to improve the performance of your custom modules for high volume...
Tips on how to improve the performance of your custom modules for high volume...Tips on how to improve the performance of your custom modules for high volume...
Tips on how to improve the performance of your custom modules for high volume...
 
Refactoring to symfony components
Refactoring to symfony componentsRefactoring to symfony components
Refactoring to symfony components
 
Marko Gargenta_Remixing android
Marko Gargenta_Remixing androidMarko Gargenta_Remixing android
Marko Gargenta_Remixing android
 
linux-namespaces.pdf
linux-namespaces.pdflinux-namespaces.pdf
linux-namespaces.pdf
 
PostgreSQL Administration for System Administrators
PostgreSQL Administration for System AdministratorsPostgreSQL Administration for System Administrators
PostgreSQL Administration for System Administrators
 
Perl - laziness, impatience, hubris, and one liners
Perl - laziness, impatience, hubris, and one linersPerl - laziness, impatience, hubris, and one liners
Perl - laziness, impatience, hubris, and one liners
 
Null Bachaav - May 07 Attack Monitoring workshop.
Null Bachaav - May 07 Attack Monitoring workshop.Null Bachaav - May 07 Attack Monitoring workshop.
Null Bachaav - May 07 Attack Monitoring workshop.
 
Keep it simple web development stack
Keep it simple web development stackKeep it simple web development stack
Keep it simple web development stack
 
Introduction to Ansible
Introduction to AnsibleIntroduction to Ansible
Introduction to Ansible
 
An Introduction to CSS Preprocessors
An Introduction to CSS PreprocessorsAn Introduction to CSS Preprocessors
An Introduction to CSS Preprocessors
 
php[world] 2016 - You Don’t Need Node.js - Async Programming in PHP
php[world] 2016 - You Don’t Need Node.js - Async Programming in PHPphp[world] 2016 - You Don’t Need Node.js - Async Programming in PHP
php[world] 2016 - You Don’t Need Node.js - Async Programming in PHP
 
Zend con 2016 - Asynchronous Prorgamming in PHP
Zend con 2016 - Asynchronous Prorgamming in PHPZend con 2016 - Asynchronous Prorgamming in PHP
Zend con 2016 - Asynchronous Prorgamming in PHP
 
Javascript fundamentals for php developers
Javascript fundamentals for php developersJavascript fundamentals for php developers
Javascript fundamentals for php developers
 
Awesome Traefik - Ingress Controller for Kubernetes - Swapnasagar Pradhan
Awesome Traefik - Ingress Controller for Kubernetes - Swapnasagar PradhanAwesome Traefik - Ingress Controller for Kubernetes - Swapnasagar Pradhan
Awesome Traefik - Ingress Controller for Kubernetes - Swapnasagar Pradhan
 
Attack monitoring using ElasticSearch Logstash and Kibana
Attack monitoring using ElasticSearch Logstash and KibanaAttack monitoring using ElasticSearch Logstash and Kibana
Attack monitoring using ElasticSearch Logstash and Kibana
 
CoreOS: Control Your Fleet
CoreOS: Control Your FleetCoreOS: Control Your Fleet
CoreOS: Control Your Fleet
 
JavaFX, because you're worth it
JavaFX, because you're worth itJavaFX, because you're worth it
JavaFX, because you're worth it
 
Debugging: Rules And Tools - PHPTek 11 Version
Debugging: Rules And Tools - PHPTek 11 VersionDebugging: Rules And Tools - PHPTek 11 Version
Debugging: Rules And Tools - PHPTek 11 Version
 

Último

+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
?#DUbAI#??##{{(☎️+971_581248768%)**%*]'#abortion pills for sale in dubai@
 
Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and Myths
Joaquim Jorge
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Safe Software
 

Último (20)

+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
 
GenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdfGenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdf
 
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of Terraform
 
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...
 
Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and Myths
 
Manulife - Insurer Innovation Award 2024
Manulife - Insurer Innovation Award 2024Manulife - Insurer Innovation Award 2024
Manulife - Insurer Innovation Award 2024
 
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
 
Top 10 Most Downloaded Games on Play Store in 2024
Top 10 Most Downloaded Games on Play Store in 2024Top 10 Most Downloaded Games on Play Store in 2024
Top 10 Most Downloaded Games on Play Store in 2024
 
Artificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : UncertaintyArtificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : Uncertainty
 
🐬 The future of MySQL is Postgres 🐘
🐬  The future of MySQL is Postgres   🐘🐬  The future of MySQL is Postgres   🐘
🐬 The future of MySQL is Postgres 🐘
 
Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Script
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processors
 
Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...
Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...
Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...
 
Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...
 
Real Time Object Detection Using Open CV
Real Time Object Detection Using Open CVReal Time Object Detection Using Open CV
Real Time Object Detection Using Open CV
 
Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
 
Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024
 

Nginx Scripting - Extending Nginx Functionalities with Lua

  • 1. NGINX SCRIPTING EXTENDING NGINX FUNCTIONALITIES WITH LUA Tony Fabeen / @tonyfabeen / SlimStacks
  • 3. NGINX ("ENGINE-X") High performance HTTP, POP/IMAP and reverse proxy server. Started in 2002 by Igor Sysoev, public in 2004. Entirely written in C. Hosts nearly 12.18% of active sites across all domains. Nginx.com in 2011.
  • 5. $p ax|ge nix s u rp gn ro 339..nix mse poes/p/gn/bnnix ot 12 . gn: atr rcs otnixsi/gn ww 330..nix wre poes w 13 . gn: okr rcs
  • 6.
  • 7. MASTER PROCESS reading and validating configuration creating, binding and closing sockets starting, terminating and maintaining the configured number of w r e okr processes re-opening log files compiling embedded Perl scripts
  • 8. WORKER PROCESS Do all important stuff Handle connection from clients Reverse Proxy and Filtering functionalities
  • 10.
  • 12. SERVER REWRITE PHASE request URI transformation on virtual server level
  • 14. REWRITE PHASE request URI transformation on location level
  • 16. TRY FILES PHASE try_files directive processing phase
  • 20. CORE MODULE Event Loop Module execution control
  • 21. FUNCTIONAL MODULES Read from / Write to Network and Storage Transform Content Outbound Filtering Server Side Includes Upstream Server communication ...etc
  • 22. LUA ON THE STAGE
  • 23. A BIT OF LUA Created in Brazil Portable Simple Small Easy to embed Fast
  • 25. LUA NGINX MODULE https://github.com/chaoslawful/lua-nginx-module/ Created by TaoBao.com Engineers High concurrent and non-blocking request processing Programs can be written in the plain-old sequential way Nginx takes care of I/O operations and Lua Nginx Module restore the context and resume the program logic
  • 26. LUA NGINX MODULE https://github.com/chaoslawful/lua-nginx-module Introduces directives for running Lua inside Nginx Exposes the Nginx environment to Lua via an Api It's fast Is even faster when compiled with LUA JIT(Just in Time Compiler)
  • 28. DIRECTIVES Configuration directives serve as gateways to the Lua API within the nginx.conf file. cnetb_u LASRP_TIG otn_yla U_CITSRN rwieb_u LASRP_TIG ert_yla U_CITSRN acs_ylaLASRP_TIG cesb_u U_CITSRN cnetb_u_iePT_OLASRP_IE otn_ylafl AHT_U_CITFL rwieb_u_iePT_OLASRP_IE ert_ylafl AHT_U_CITFL acs_ylafl PT_OLASRP_IE cesb_u_ie AHT_U_CITFL Unless you set l a c d _ a h to o f modules will be loaded once on the first request. u_oecce f ,
  • 29. NGX PACKAGE Nginx Environment is exposed via n x g package nxagulag g.r.r_r nxvrVRAL_AE g.a.AIBENM nxhae.EDRATIUE g.edrHAE_TRBT nxcx g.t
  • 30. HELLO WORLD ! lcto /el-srb-u { oain hloue-yla dfuttp "etpan; eal_ye tx/li" cnetb_u ' otn_yla nxsy"el," nxvragnm,"" g.a(Hlo , g.a.r_ae !) '; } lcto /el-srb-gn { oain hloue-ynix eh "el,$r_ae!; co Hlo agnm " } $cr ht:/oahs/el-srb-u?aeDvnap ul tp/lclothloue-ylanm=eISma Hlo Dvnap ! el, eISma $cr ht:/oahs/el-srb-gn?aeDvnap ul tp/lclothloue-ynixnm=eISma Hlo Dvnap ! el, eISma
  • 31. NGINX VARS lcto /csignixag { oain aesn-gn-rs st$is 3; e frt 5 st$eod6; e scn 5 stb_u $u ' e_yla sm rtr nxvrfrt+nxvrscn eun g.a.is g.a.eod '; eh "h smi $u" co Te u s sm; } $cr ht:/oahs/csignixag ul tp/lclotaesn-gn-rs Tesmi 9 h u s 9
  • 32. NGINX SUBREQUESTS lcto /u-urqet { oain lasbeuss cnetb_u ' otn_yla lclrsos =nxlcto.atr(/el-srb-gn?ae oa epne g.oaincpue"hloue-ynixnm= Dvnap" eISma) i rsos.tts> 50te f epnesau = 0 hn nxei(epnesau) g.xtrsos.tts ed n nxsau =rsos.tts g.tts epnesau nxsyrsos.oy g.a(epnebd) '; } $cr ht:/oahs/u-urqet ul tp/lclotlasbeuss Hlo Dvnap ! el, eISma
  • 33. NON BLOCKING I/O SUBREQUESTS lcto /nltc-nrmn { oain aayisiceet cnetb_u ' otn_yla lclrsos =nxlcto.atr(/ei" oa epne g.oaincpue"rds, {rs={m ="nr,ky=nxvragln}) ag cd ic" e g.a.r_ik} nxsy"nrmne t :,nxvragln) g.a(Iceetd o " g.a.r_ik '; } lcto /ei { oain rds itra; nenl stuecp_r $e $r_e; e_nsaeui ky agky stuecp_r $m $r_m; e_nsaeui cd agcd rds_ur $m $e; ei2qey cd ky rds_as1700167; ei2ps 2...:39 } $cr ht:/oahs/nltc-nrmn?ikht:/w.eismacmb ul tp/lclotaayisiceetln=tp/wwdvnap.o.r Iceetdt :tp/wwdvnap.o.r nrmne o ht:/w.eismacmb
  • 35. HEADER FILTERS lcto /{ oain poyps ht:/oahs:00 rx_as tp/lclot88; hae_itrb_u 'g.edrSre ="yLtl Sre"; edrfle_yla nxhae.evr M ite evr' } $cr - - HA ht:/oahs/edrfle ul i X ED tp/lclothae-itr HT/. 20O TP11 0 K Dt:Sn 0 Sp21 2:81 GT ae u, 9 e 02 11:1 M Sre:M Ltl Sre evr y ite evr CnetTp:tx/tlcastuf8 otn-ye ethm;hre=t- CnetLnt:49 otn-egh 4 Cneto:ke-lv oncin epaie Sau:20O tts 0 K XFaeOtos smoii -rm-pin: aergn XXSPoeto:1 md=lc -S-rtcin ; oebok XCsae ps -acd: as XRc-ah:ms -akCce is
  • 36. BODY FILTERS lcto /oyfle { oain bd-itr eh "ycnet; co M otn" bd_itrb_u ' oyfle_yla nxag1 =srn.sbnxag1,"y,"or) g.r[] tiggu(g.r[] M" Yu" nxag2 =tu -stefo ls canbfe g.r[] re -e o r at hi ufr '; } $cr ht:/oahs/oyfle ul tp/lclotbd-itr Yu cnet or otn
  • 37. COSOCKETS Non Blocking, of course Communicate via TCP or Unix domain sockets Keepalive mechanism avoid connect/close for each request
  • 38. COSOCKETS lcto /ecce-rmla{ oain mmahdfo-u cnetb_u ' otn_yla lclsc =nxsce.onc(17001,121 oa ok g.oktcnet"2..." 11) lclbts er=sc:ed"e fobrrn) oa ye, r oksn(st o a" i ntbtste f o ye hn nxsy"aldt sn. " er g.a(fie o ed. n, r) rtr eun ed n lcldt =sc:eev( oa aa okrcie) i ntdt te f o aa hn nxsy"aldt rciedt." g.a(Fie o eev aa.n) ed n nxsy"eut:" dt) g.a(Rsl , aa '; }
  • 39. SOME LIBRARIES USING PURE COSOCKETS https://github.com/agentzh/lua-resty-memcached https://github.com/agentzh/lua-resty-redis https://github.com/agentzh/lua-resty-mysql
  • 40. SUMMARY The Nginx architecture is excellent for highly scalable applications. Nginx can do a variety of things thanks to module extensions, and one can resuse those extensions by issuing sub-requests in Lua. lua-nginx-module makes use of the evented architecture in Nginx, providing a powerful and performant programming environment. It's possible to do 100% non-blocking I/O with readable code.
  • 42. BOOKS