Re: Enabling both gzip & brotli

2017-11-10 Thread Dewangga Bachrul Alam
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hello! On 11/10/2017 11:36 PM, rihad wrote: > Hello. Can I enable both brotli & gzip? Yeah sure, I was test it using this module https://github.com/google/ngx_brotli > brotli on; gzip on; > > with the idea to support both newer & older clients, b

Too many define location directive

2017-04-22 Thread Dewangga Bachrul Alam
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hello! I got confused and no hint(s) about map directive co-exist with try_files directive. Is it right to think using map directive? Or any alternative? The goals is, I want to avoid many location like : ... snip ... index index.php;

Re: How to encrypt proxy cache

2017-04-03 Thread Dewangga Bachrul Alam
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hello! On 04/03/2017 08:21 PM, sachin.she...@gmail.com wrote: > Hi, > > We are testing using nginx as a file cache in front of our app, > but the contents of the proxy cache directory are readable to any > body who has access to the machine. [..]

stale-while-revalidate and stale-if-error implementation

2017-03-05 Thread Dewangga Bachrul Alam
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hello! I tried to use "stale-if-error=864000" and "stale-while-revalidate=864000" co-exist with "expires max;" directive. Is it possible? My configurations looks like : ... snip ... expires max; add_header Cache-Control "stale-while-revalidate=8640

Re: Nginx configuration Issue

2017-03-03 Thread Dewangga Bachrul Alam
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hello! On 03/03/2017 04:15 PM, abhipower.abhi wrote: > I am using nginx-1.10.3 as a load balancer. In my architecture, I > have two servers- > > Hostname - sal15062hkb152, IP Address - 172.15.54.116 Hostname - > sal15062hkb184, IP Address - 172.15.

Re: AW: IPv6 upstream problem

2017-03-02 Thread Dewangga Bachrul Alam
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hello! Yes I've force my system to read IPv4 first. But, just curios, why IPv6 upstream can't serve the traffic? If I access the IP Address using browser, it's normal. I am using Cent OS 7. On 03/01/2017 09:04 PM, Lukas Tribus wrote: >> Did anyone

Re: IPv6 upstream problem

2017-02-28 Thread Dewangga Bachrul Alam
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hello! On 03/01/2017 12:15 AM, Maxim Dounin wrote: > Hello! > > On Tue, Feb 28, 2017 at 10:57:01PM +0700, Dewangga Bachrul Alam > wrote: > >> Currently I have problem with upstream with IPv6. For example I >> have an or

IPv6 upstream problem

2017-02-28 Thread Dewangga Bachrul Alam
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hello! Currently I have problem with upstream with IPv6. For example I have an origin with subdomain dual-stack-ipv4-ipv6.xtremenitro.org. dual-stack-ipv4-ipv6.xtremenitro.org IN A 192.168.1.1 dual-stack-ipv4-ipv6.xtremenitro.org IN 2001:xx:xx

Re: How to cache image urls with query strings?

2017-02-24 Thread Dewangga Bachrul Alam
Hello! On 02/24/2017 07:33 PM, 0liver wrote: > We've recently started delivering image urls with query strings for > cropping, like > > http://images-camping.info/CampsiteImages/116914_Large.jpg?width=453&height=302&mode=crop > Try add: proxy_ignore_headers Cache-Control Expires; Ref: http:/

Re: Question about proxy_cache_key

2017-02-19 Thread Dewangga Bachrul Alam
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hello! Thanks Francis, yes it's about 'Vary' header should be ignored on proxy_ignore_headers. Thanks for the hints. On 02/16/2017 07:41 PM, Francis Daly wrote: > On Thu, Feb 16, 2017 at 01:08:35PM +0700, Dewangga Bachrul Ala

Re: Question about proxy_cache_key

2017-02-15 Thread Dewangga Bachrul Alam
Key : /artikel/berita/a-pen-by-hair?view=desktop Path: /var/cache/nginx/networksninja_cache/f/bf/f3863443c164cdfa95f6fe870be7db ff nginx/1.11.10 On 02/16/2017 01:08 PM, Dewangga Bachrul Alam wrote: > Hello! > > I've compiled latest nginx 1.11.10 with ngx_cache_purge, my > c

Question about proxy_cache_key

2017-02-15 Thread Dewangga Bachrul Alam
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hello! I've compiled latest nginx 1.11.10 with ngx_cache_purge, my configurations likes: proxy_cache_key "$uri$is_args$args"; proxy_cache_path /var/cache/nginx/proxy_cache levels=1:2 keys_zone=networksninja_cache:60m inactive=60m use_temp_path=off

Set header $upstream_response_time with proxy_cache directive

2016-11-04 Thread Dewangga Bachrul Alam
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hello! I have problem how to debugs current response time to upstream, my configuration is looks likes : ... upstream upstream_distribution { server full-fqdn.tld; } # common configuration location ~ \.(jpe?g|png|gif|webp)$ {

ngx_brotli

2016-09-29 Thread Dewangga Bachrul Alam
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hello! Is there any best practice or some example to see how brotli compression works? I've patch the nginx using ngx_brotli[1], but I didn't see any brotli header, there's only gzip. Many thanks. [1] https://github.com/cloudflare/ngx_brotli_modul

Re: No HTTPS on nginx.org by default

2016-08-22 Thread Dewangga Bachrul Alam
Hello! On 08/22/2016 10:58 PM, rai...@ultra-secure.de wrote: > > nginx doesn't provide an auto-update mechanism that stupidly downloads > and accepts all and everything somebody makes available under some > spoofed address. You can use PGP key[1] to verified the binary was correct or "injected"

Re: map directive using $default as origin

2016-08-09 Thread Dewangga Bachrul Alam
Hello steve! On 08/10/2016 10:47 AM, steve wrote: > Hi! > > On 08/10/2016 03:07 PM, Dewangga Bachrul Alam wrote: >> Hello! >> >> I am using module small_light >> (https://github.com/cubicdaiya/ngx_small_light), since the module can't >> detect whic

map directive using $default as origin

2016-08-09 Thread Dewangga Bachrul Alam
Hello! I am using module small_light (https://github.com/cubicdaiya/ngx_small_light), since the module can't detect which browser can process webp transformation, I creating a simple directive on nginx to detect chrome and opera only and fallback the rest to jpeg/jpg. But, if the origin is not jp

Re: Load balancing algorithm

2016-08-01 Thread Dewangga Bachrul Alam
the same table in multiple > servers being written to at the same time. See this blog post for more > information: > > https://www.nginx.com/blog/advanced-mysql-load-balancing-with-nginx-plus/ > > Kind Regards > Andrew > > On 01/08/16 09:20, Dewangga Bachrul Alam

Load balancing algorithm

2016-08-01 Thread Dewangga Bachrul Alam
Hello! I got curios with load balancing algorithm, I got scenarios like this. I have 3 galera cluster, each cluster have 3 node and it was solved with stream module. Cluster1: Node1-Cluster1: 192.168.11.1 Node2-Cluster1: 192.168.11.2 Node3-Cluster1: 192.168.11.3 Cluster2: Node1-Cluster2: 192.16

Re: ngx_stream module build error on 1.11.3

2016-07-28 Thread Dewangga Bachrul Alam
Thanks Maxim, its works. :) On 07/28/2016 03:29 PM, Maxim Konovalov wrote: > Hi Dewangga, > > On 7/28/16 10:31 AM, Dewangga Bachrul Alam wrote: >> Hello! >> >> I've tried to build nginx 1.11.3 with --with-stream module parameter, >> but, attached below:

ngx_stream module build error on 1.11.3

2016-07-28 Thread Dewangga Bachrul Alam
Hello! I've tried to build nginx 1.11.3 with --with-stream module parameter, but, attached below: .. snip .. ./configure \ --prefix=%{_sysconfdir}/nginx \ --sbin-path=%{_sbindir}/nginx \ --conf-path=%{_sysconfdir}/nginx/nginx.conf \ --error-log-path=%{_localstated

Re: nginx plus dashboard for clusters

2016-02-25 Thread Dewangga Bachrul Alam
Hello! On 02/26/2016 05:54 AM, dshe wrote: > I think dashboard is a great feature in nginx plus but I was wondering if it > can aggregate metrics from a cluster of nginx servers or each server has its > own dashboard. You can try amplify.nginx.com :) > Thanks > > Posted at Nginx Forum: > https

Re: load balancer on nginx : how to monitoring backend ?

2016-01-28 Thread Dewangga Bachrul Alam
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hello! If you are in development, you can try this module https://github.com/yaoweibin/nginx_upstream_check_module. But, not recommended if use on production, better use n+. On 01/28/2016 02:36 PM, Alexandre wrote: > Hello, > > On 28/01/16 08:27,

Re: Exclude specific location from cache

2015-12-24 Thread Dewangga Bachrul Alam
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hello! On 12/24/2015 04:28 PM, Maxim Konovalov wrote: > On 12/24/15 12:24 PM, Dewangga Bachrul Alam wrote: >> Sorry I forgot something, I'm using Nginx Plus R7. > > [...] > > Hi Dewangga, > > please open a sup

Re: Exclude specific location from cache

2015-12-24 Thread Dewangga Bachrul Alam
-Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions - -fstack-protector-strong --param=ssp-buffer-size=4 - -grecord-gcc-switches -m64 -mtune=generic' On 12/24/2015 04:01 PM, Dewangga Bachrul Alam wrote: > Hello! > > Currently my configuration looks like this : > > map $request_method $pur

Exclude specific location from cache

2015-12-24 Thread Dewangga Bachrul Alam
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hello! Currently my configuration looks like this : map $request_method $purge_method { PURGE 1; default 0; } map $arg_geoloc $bypass { default 1; 1 0; } # Exclude from cache # Expected URL http://domain.tld/ locatio

Re: purger directive not available

2015-11-28 Thread Dewangga Bachrul Alam
nx.com/products/>: > > |purger|=|on|||off| My bad, didn't read the whole pages. :) Thank you, bro :) > > > On Sat, Nov 28, 2015 at 8:10 AM, Dewangga Bachrul Alam > mailto:dewangg...@xtremenitro.org>> > wrote: > > Hello! > > I am using nginx 1.8.0 on Cent

purger directive not available

2015-11-28 Thread Dewangga Bachrul Alam
Hello! I am using nginx 1.8.0 on Cent OS 7, tried to enable purger directive, mentioned on http://nginx.org/en/docs/http/ngx_http_proxy_module.html#proxy_cache_path But got error like this : nginx[46931]: nginx: [emerg] invalid parameter "purge=on" in /etc/nginx/conf.d/proxy.conf:5 My complete d

Re: Nginx HTTP/2 module (ALPN) TLS on RHEL 7.*

2015-09-28 Thread Dewangga Bachrul Alam
Like this? nginx version: nginx/1.9.5 built by gcc 4.8.3 20140911 (Red Hat 4.8.3-9) (GCC) built with OpenSSL 1.0.2d-fips 9 Jul 2015 TLS SNI support enabled configure arguments: --prefix=/etc/nginx --sbin-path=/usr/sbin/nginx --conf-path=/etc/nginx/nginx.conf --error-log-path=/var/log/nginx/error.l

Re: Nginx HTTP/2 module (ALPN) TLS on RHEL 7.*

2015-09-28 Thread Dewangga Bachrul Alam
Hello! On 09/28/2015 08:40 PM, rik...@deds.nl wrote: > Dear, > > Does the Nginx HTTP/2 module work on RHEL 7.1 with (ALPN) TLS? > > It seems like the HTTP/2 module is enabled by default in your RHEL 7.1 > based rpm and srpm. > > Your Nginx website writes about: > > "Note that accepting HTTP/2

Re: DocumentRoot should end up on specific file !

2015-08-31 Thread Dewangga Bachrul Alam
Hello! On 08/31/2015 09:29 PM, shahzaib shahzaib wrote: > Hi, > > We want nginx vhost to access the file audo_portal.php without > specifying it,i.e instead of using > URL http://domain.com/audio_portal.php , can we access it with > http://domain.com ? So it'll directly access audio_portal.php

Re: Reverse proxy configuration on el7

2015-05-06 Thread Dewangga Bachrul Alam
gga Bachrul Alam > mailto:dewangg...@xtremenitro.org>> wrote: > > Hello! > > On 05/07/2015 09:45 AM, Nurahmadie Nurahmadie wrote: > > Hi > > > > On Thu, May 7, 2015 at 11:38 AM, Dewangga Bachrul Alam > > mailto:dewangg...@x

Re: Reverse proxy configuration on el7

2015-05-06 Thread Dewangga Bachrul Alam
Hello! On 05/07/2015 09:45 AM, Nurahmadie Nurahmadie wrote: > Hi > > On Thu, May 7, 2015 at 11:38 AM, Dewangga Bachrul Alam > mailto:dewangg...@xtremenitro.org>> wrote: > > Hello! > > Did anyone have same problem when configuring reverse proxy nginx +

Reverse proxy configuration on el7

2015-05-06 Thread Dewangga Bachrul Alam
Hello! Did anyone have same problem when configuring reverse proxy nginx + apache, when the request came from nginx, the IP didn't shows real visitor. Example access.log: 127.0.0.1 - - [07/May/2015:09:27:30 +0700] "GET / HTTP/1.0" 200 61925 127.0.0.1 - - [07/May/2015:09:27:35 +0700] "GET / HTTP/1

Re: https to http error "too many redirects"

2015-03-20 Thread Dewangga Bachrul Alam
Hi! You'll _never_ reach http request since you set HSTS configuration :) If you still want some http request on your web server, disable your HSTS directive. (see Daniel statement on previous email). On 03/20/2015 05:14 PM, Gena Makhomed wrote: > On 20.03.2015 11:35, Daniƫl Mostertman wrote: >

Need best practice on GeoIP/GeoDNS

2015-01-20 Thread Dewangga Bachrul Alam
Hi, I have project that will be used multilocation webserver, but still confuse about implementing GeoDNS or GeoIP. Which method are powerfull? I want to separate user between Country A to WebServer A, Country B to Webserver B. Each webserver are located on each country.

Re: TLS_FALLBACK_SCSV

2014-10-17 Thread Dewangga Bachrul Alam
Hi mex, Yes, it's apacheconfig, Litespeed is drop-in replacement for Apache. Here is my full nginx -V http://fpaste.org/142890/60334141/raw I don't have nginx with different openssl-library installed. Thanks. On 10/17/2014 10:29 PM, mex wrote: >> Regarding POODLEbleed[1] issue, I've disable SS

TLS_FALLBACK_SCSV

2014-10-17 Thread Dewangga Bachrul Alam
Hi there, Regarding POODLEbleed[1] issue, I've disable SSLv3 on `ssl_protocols` directive. But, ssllabs.com says that : snip Downgrade attack prevention No, TLS_FALLBACK_SCSV not supported (more info[2]) snip But on LiteSpeed[3] configuration, it says yes. snip

Re: Redirect loop problems

2014-10-15 Thread Dewangga Bachrul Alam
oop problems >> >> Update: >> >> I just want to redirect specific URL contains `/go/*` to HTTP, and force >> others to HTTPS. >> >> On 10/14/2014 12:03 PM, Dewangga Bachrul Alam wrote: >>> Hi, >>> >>> Today, I was implement redi

Re: Redirect loop problems

2014-10-13 Thread Dewangga Bachrul Alam
Update: I just want to redirect specific URL contains `/go/*` to HTTP, and force others to HTTPS. On 10/14/2014 12:03 PM, Dewangga Bachrul Alam wrote: > Hi, > > Today, I was implement redirect using return 301, here's my snippet: > > server { > listen 80

Redirect loop problems

2014-10-13 Thread Dewangga Bachrul Alam
Hi, Today, I was implement redirect using return 301, here's my snippet: server { listen 80; server_name domain.tld; error_log /dev/null; access_log off; return 301 https://www.domain.tld$request_uri; } server { listen 80; server

Re: nginx cannot listen to port 8090

2014-09-29 Thread Dewangga Bachrul Alam
Are you familiar with SELinux? If not, just disable it :) Try run 'getenforce' (without quotes) on your console, it must be enforcing. On 09/29/2014 06:31 PM, mert1972 wrote: > Thanks Anton for your response, > Would you please provide some hints about how I can overcome this issue. > This is a ne