Update nginx-reverse.yml
This commit is contained in:
+8
-25
@@ -1,16 +1,16 @@
|
|||||||
version: '3.7'
|
version: '3.7'
|
||||||
services:
|
services:
|
||||||
reverse:
|
nginx:
|
||||||
container_name: reverse
|
container_name: nginx
|
||||||
ports:
|
ports:
|
||||||
- "0.0.0.0:80:80"
|
- "0.0.0.0:80:80"
|
||||||
- "0.0.0.0:443:443"
|
- "0.0.0.0:443:443"
|
||||||
image: "theraw/reversed:L7"
|
image: ""
|
||||||
shm_size: '512MB'
|
shm_size: '512MB'
|
||||||
privileged: true
|
privileged: true
|
||||||
restart: unless-stopped
|
restart: unless-stopped
|
||||||
networks:
|
networks:
|
||||||
reverse_net:
|
nginx_net:
|
||||||
ipv4_address: 172.69.0.70
|
ipv4_address: 172.69.0.70
|
||||||
dns:
|
dns:
|
||||||
- "1.1.1.1"
|
- "1.1.1.1"
|
||||||
@@ -20,29 +20,12 @@ services:
|
|||||||
cap_add:
|
cap_add:
|
||||||
- "CAP_SYS_RESOURCE"
|
- "CAP_SYS_RESOURCE"
|
||||||
- "CAP_SYS_TIME"
|
- "CAP_SYS_TIME"
|
||||||
sysctls:
|
volumes:
|
||||||
- "vm.nr_hugepages = 0"
|
- /nginx:/nginx
|
||||||
- "vm.vfs_cache_pressure = 100"
|
- /hostdata:/hostdata
|
||||||
- "fs.file-max = 1000000"
|
|
||||||
- "kernel.randomize_va_space = 2"
|
|
||||||
- "net.ipv4.ip_forward = 1"
|
|
||||||
- "net.ipv4.tcp_syncookies = 1"
|
|
||||||
- "net.ipv4.ip_local_port_range = 12000 65535"
|
|
||||||
- "net.ipv4.tcp_window_scaling = 1"
|
|
||||||
- "net.core.somaxconn = 65535"
|
|
||||||
- "net.core.netdev_max_backlog = 2000"
|
|
||||||
- "net.ipv4.tcp_max_syn_backlog = 2048"
|
|
||||||
- "net.ipv4.tcp_fin_timeout = 30"
|
|
||||||
- "net.ipv4.tcp_tw_recycle = 1"
|
|
||||||
- "net.ipv4.tcp_tw_reuse = 1"
|
|
||||||
- "net.core.default_qdisc = fq"
|
|
||||||
- "net.ipv4.tcp_congestion_control = bbr"
|
|
||||||
- "net.ipv4.tcp_synack_retries = 2"
|
|
||||||
- "net.ipv4.tcp_syn_retries = 2"
|
|
||||||
- "kernel.sched_autogroup_enabled = 0"
|
|
||||||
|
|
||||||
networks:
|
networks:
|
||||||
reverse_net:
|
nginx_net:
|
||||||
driver: bridge
|
driver: bridge
|
||||||
driver_opts:
|
driver_opts:
|
||||||
com.docker.network.enable_ipv6: "false"
|
com.docker.network.enable_ipv6: "false"
|
||||||
|
|||||||
Reference in New Issue
Block a user