
如果你使用 DeepSeek、元宝 AI、Copilot、ChatGPT 等 AI 工具,协助配置轩辕镜像、编写 docker pull 命令、修改 Docker Compose 镜像地址、配置镜像加速、排查镜像拉取失败、分析报错日志等问题,请先让 AI 阅读并遵守轩辕镜像的规则文档。
只需在 AI 对话中先发送下面这段话即可:
请先阅读并遵守:https://xuanyuan.cloud/agents.md
未读文档前不要生成 pull 命令或排错方案。查看 agents.md 用法指南与完整示范。国内用户首推 元宝 AI、DeepSeek 的深度思考模式,不推荐豆包 AI;Cursor 等编辑器可在对话 @ 该链接,或加入 User Rules。 若 AI 无法访问外链,可 打开说明文档 复制全文粘贴。文档会随站点更新,复制内容可能过期,建议定期检查。
此镜像基于官方https://hub.docker.com/_/nginx/构建,提供稳定且最新的nginx版本,支持https://nginx.org/en/docs/http/ngx_http_v3_module.html、https://github.com/google/ngx_brotli、https://nginx.org/en/docs/njs/及https://ssl-config.mozilla.org/,适用于需要高性能、安全且支持现代网络协议的Web服务场景。
$ docker run -it macbre/nginx-http3 nginx -V nginx version: nginx/1.25.2 (quic-44536076405c-boringssl-e1b8685770d0e82e5a4a3c5d24ad1602e05f2e83) built by gcc 12.2.1 20220924 (Alpine 12.2.1_git20220924-r4) built with OpenSSL 1.1.1 (compatible; BoringSSL) (running with BoringSSL) TLS SNI support enabled configure arguments: --build=quic-44536076405c-boringssl-e1b8685770d0e82e5a4a3c5d24ad1602e05f2e83 --prefix=/etc/nginx --sbin-path=/usr/sbin/nginx --modules-path=/usr/lib/nginx/modules --conf-path=/etc/nginx/nginx.conf --error-log-path=/var/log/nginx/error.log --http-log-path=/var/log/nginx/access.log --pid-path=/var/run/nginx.pid --lock-path=/var/run/nginx.lock --http-client-body-temp-path=/var/cache/nginx/client_temp --http-proxy-temp-path=/var/cache/nginx/proxy_temp --http-fastcgi-temp-path=/var/cache/nginx/fastcgi_temp --http-uwsgi-temp-path=/var/cache/nginx/uwsgi_temp --http-scgi-temp-path=/var/cache/nginx/scgi_temp --user=nginx --group=nginx --with-http_ssl_module --with-http_realip_module --with-http_addition_module --with-http_sub_module --with-http_dav_module --with-http_flv_module --with-http_mp4_module --with-http_gunzip_module --with-http_gzip_static_module --with-http_random_index_module --with-http_secure_link_module --with-http_stub_status_module --with-http_auth_request_module --with-http_xslt_module=dynamic --with-http_image_filter_module=dynamic --with-http_geoip_module=dynamic --with-http_perl_module=dynamic --with-threads --with-stream --with-stream_ssl_module --with-stream_ssl_preread_module --with-stream_realip_module --with-stream_geoip_module=dynamic --with-http_slice_module --with-mail --with-mail_ssl_module --with-compat --with-file-aio --with-http_v2_module --with-http_v3_module --add-module=/usr/src/ngx_brotli --add-module=/usr/src/headers-more-nginx-module-0.34 --add-module=/usr/src/njs/nginx --add-dynamic-module=/usr/src/ngx_http_geoip2_module --with-cc-opt=-I../boringssl/include --with-ld-opt='-L../boringssl/build/ssl -L../boringssl/build/crypto' $ docker run -it macbre/nginx-http3 njs -v 0.8.1
此镜像基于官方https://hub.docker.com/_/nginx/,除标准配置外,还支持Brotli模块特定指令(详见https://github.com/google/ngx_brotli#configuration-directives)。
从Docker Hub拉取:
docker pull docker.xuanyuan.run/macbre/nginx-http3:latest
从GitHub Container Registry拉取:
docker pull ***-ghcr.xuanyuan.run/macbre/nginx-http3:latest
QUIC + HTTP/3支持
server { # http/3 listen 443 quic reuseport; # http/2 和 http/1.1 listen 443 ssl; http2 on; server_name localhost; # 自定义为您的域名 # 运行容器时需挂载以下文件 ssl_certificate /etc/nginx/ssl/localhost.crt; ssl_certificate_key /etc/nginx/ssl/localhost.key; # QUIC需要TLSv1.3 ssl_protocols TLSv1.2 TLSv1.3; # 0-RTT QUIC连接恢复 ssl_early_data on; # 添加Alt-Svc头协商HTTP/3 add_header alt-svc 'h3=":443"; ma=86400'; # 当使用QUIC时发送 add_header QUIC-Status $http3; location / { # 自定义配置 } }
SSL A级处理
参考https://ssl-config.mozilla.org/,镜像已内置DHE密码套件的DH参数(路径:`/etc/ssl/dhparam.pem`):
ssl_dhparam /etc/ssl/dhparam.pem;
/etc/nginx/main.d目录下的.conf文件将被包含在nginx主配置上下文(如可使用http://nginx.org/en/docs/ngx_core_module.html#env)/etc/nginx/conf.d目录下的.conf文件将被包含在http配置上下文docker pull ***-ghcr.xuanyuan.run/macbre/nginx-http3:latest DOCKER_BUILDKIT=1 docker build . -t macbre/nginx --cache-from=ghcr.io/macbre/nginx-http3:latest --progress=plain
参考run-docker.sh脚本了解如何正确挂载配置文件和资源。
您可以使用以下命令拉取该镜像。请将 <标签> 替换为具体的标签版本。如需查看所有可用标签版本,请访问 标签列表页面。
来自真实用户的反馈,见证轩辕镜像的优质服务