[文章作者:张宴 本文版本:v1.2 最后修改:2008.01.02 转载请注明出处:http://blog.zyan.cc]

  我曾经写过一篇文章──《初步试用Squid的替代产品──Varnish Cache网站加速器》,但当时仅仅是用着玩,没做深入研究。

  今天写的这篇关于Varnish的文章,已经是一篇可以完全替代Squid做网站缓存加速器的详细解决方案了。网上关于Varnish的资料很少,中文资料更是微乎其微,希望本文能够吸引更多的人研究、使用Varnish。

  在我看来,使用Varnish代替Squid的理由有三点:
  1、Varnish采用了“Visual Page Cache”技术,在内存的利用上,Varnish比Squid具有优势,它避免了Squid频繁在内存、磁盘中交换文件,性能要比Squid高。
  2、Varnish的稳定性还不错,我管理的一台图片服务器运行Varnish已经有一个月,没有发生过故障,而进行相同工作的Squid服务器就倒过几次。
  3、通过Varnish管理端口,可以使用正则表达式快速、批量地清除部分缓存,这一点是Squid不能具备的。

  点击在新窗口中浏览此图片


  下面来安装Varnish网站缓存加速器(Linux系统):
  1、创建www用户和组,以及Varnish缓存文件存放目录(/var/vcache):
/usr/sbin/groupadd www -g 48
/usr/sbin/useradd -u 48 -g www www
mkdir -p /var/vcache
chmod +w /var/vcache
chown -R www:www /var/vcache


  2、创建Varnish日志目录(/var/logs/):
mkdir -p /var/logs
chmod +w /var/logs
chown -R www:www /var/logs


  3、编译安装varnish:
wget http://blog.zyan.cc/soft/linux/varnish/varnish-1.1.2.tar.gz
tar zxvf varnish-1.1.2.tar.gz
cd varnish-1.1.2
./configure --prefix=/usr/local/varnish
make && make install


  4、创建Varnish配置文件:
vi /usr/local/varnish/vcl.conf

  输入以下内容:
引用
backend myblogserver {
       set backend.host = "192.168.0.5";
       set backend.port = "80";
}

acl purge {
       "localhost";
       "127.0.0.1";
       "192.168.1.0"/24;
}

sub vcl_recv {
       if (req.request == "PURGE") {
               if (!client.ip ~ purge) {
                       error 405 "Not allowed.";
               }
               lookup;
       }

       if (req.http.host ~ "^blog.zyan.cc") {
               set req.backend = myblogserver;
               if (req.request != "GET" && req.request != "HEAD") {
                       pipe;
               }
               else {
                       lookup;
               }
       }
       else {
               error 404 "Zhang Yan Cache Server";
               lookup;
       }
}

sub vcl_hit {
       if (req.request == "PURGE") {
               set obj.ttl = 0s;
               error 200 "Purged.";
       }
}

sub vcl_miss {
       if (req.request == "PURGE") {
               error 404 "Not in cache.";
       }
}

sub vcl_fetch {
       if (req.request == "GET" && req.url ~ "\.(txt|js)$") {
               set obj.ttl = 3600s;
       }
       else {
               set obj.ttl = 30d;
       }
}

  这里,我对这段配置文件解释一下:
  (1)、Varnish通过反向代理请求后端IP为192.168.0.5,端口为80的web服务器;
  (2)、Varnish允许localhost、127.0.0.1、192.168.0.***三个来源IP通过PURGE方法清除缓存;
  (3)、Varnish对域名为blog.zyan.cc的请求进行处理,非blog.zyan.cc域名的请求则返回“Zhang Yan Cache Server”;
  (4)、Varnish对HTTP协议中的GET、HEAD请求进行缓存,对POST请求透过,让其直接访问后端Web服务器。之所以这样配置,是因为POST请求一般是发送数据给服务器的,需要服务器接收、处理,所以不缓存;
  (5)、Varnish对以.txt和.js结尾的URL缓存时间设置1小时,对其他的URL缓存时间设置为30天。

  5、启动Varnish
ulimit -SHn 51200
/usr/local/varnish/sbin/varnishd -n /var/vcache -f /usr/local/varnish/vcl.conf -a 0.0.0.0:80 -s file,/var/vcache/varnish_cache.data,1G -g www -u www -w 30000,51200,10 -T 127.0.0.1:3500 -p client_http11=on


  6、启动varnishncsa用来将Varnish访问日志写入日志文件:
/usr/local/varnish/bin/varnishncsa -n /var/vcache -w /var/logs/varnish.log &


  7、配置开机自动启动Varnish
vi /etc/rc.local

  在末尾增加以下内容:
引用
ulimit -SHn 51200
/usr/local/varnish/sbin/varnishd -n /var/vcache -f /usr/local/varnish/vcl.conf -a 0.0.0.0:80 -s file,/var/vcache/varnish_cache.data,1G -g www -u www -w 30000,51200,10 -T 127.0.0.1:3500 -p client_http11=on
/usr/local/varnish/bin/varnishncsa -n /var/vcache -w /var/logs/youvideo.log &


  8、优化Linux内核参数
vi /etc/sysctl.conf

  在末尾增加以下内容:
引用
net.ipv4.tcp_fin_timeout = 30
net.ipv4.tcp_keepalive_time = 300
net.ipv4.tcp_syncookies = 1
net.ipv4.tcp_tw_reuse = 1
net.ipv4.tcp_tw_recycle = 1
net.ipv4.ip_local_port_range = 5000    65000



  再看看如何管理Varnish:
  1、查看Varnish服务器连接数与命中率:
/usr/local/varnish/bin/varnishstat

  点击在新窗口中浏览此图片

  2、通过Varnish管理端口进行管理:
  用help看看可以使用哪些Varnish命令:
/usr/local/varnish/bin/varnishadm -T 127.0.0.1:3500 help

引用
Available commands:
ping [timestamp]
status
start
stop
stats
vcl.load
vcl.inline
vcl.use
vcl.discard
vcl.list
vcl.show
param.show [-l] []
param.set
help [command]
url.purge
dump.pool


  3、通过Varnish管理端口,使用正则表达式批量清除缓存:
  (1)、例:清除类似http://blog.zyan.cc/a/zhangyan.html的URL地址):
/usr/local/varnish/bin/varnishadm -T 127.0.0.1:3500 url.purge /a/

  (2)、例:清除类似http://blog.zyan.cc/tech的URL地址:
/usr/local/varnish/bin/varnishadm -T 127.0.0.1:3500 url.purge w*$

  (3)、例:清除所有缓存:
/usr/local/varnish/bin/varnishadm -T 127.0.0.1:3500 url.purge *$


  4、一个清除Squid缓存的PHP函数(清除Varnish缓存同样可以使用该函数,无需作任何修改,十分方便):


  附1:Varnish官方网站:http://www.varnish-cache.org/

  附2:2007年12月10日,我写了一个每天0点运行,按天切割Varnish日志,生成一个压缩文件,同时删除上个月旧日志的脚本(/var/logs/cutlog.sh):
  /var/logs/cutlog.sh文件内容如下:
引用
#!/bin/sh
# This file run at 00:00
date=$(date -d "yesterday" +"%Y-%m-%d")
pkill -9 varnishncsa
mv /var/logs/youvideo.log /var/logs/${date}.log
/usr/local/varnish/bin/varnishncsa -n /var/vcache -w /var/logs/youvideo.log &
mkdir -p /var/logs/youvideo/
gzip -c /var/logs/${date}.log > /var/logs/youvideo/${date}.log.gz
rm -f /var/logs/${date}.log
rm -f /var/logs/youvideo/$(date -d "-1 month" +"%Y-%m*").log.gz

  设置在每天00:00定时执行:
  
/usr/bin/crontab -e
  或者  
vi /var/spool/cron/root
  输入以下内容:
引用
0 0 * * * /bin/sh /var/logs/cutlog.sh



Tags: , , ,



技术大类 » Cache与存储 | 评论(8712) | 引用(0) | 阅读(840281)
AMANI Email Homepage
2021-11-27 20:44
MetaMask login accounts do not require you to sign up for it. You only have to get the browser extension installed for your crypto wallet, and settle on a “hard to guess” and “easy to remember” password to begin storing and trading in crypto funds. https://metamasks-login.webflow.io/ https://cryptocomlogine.webflow.io/ https://exodus-ewallets.webflow.io/
JONAS Email Homepage
2021-11-27 22:29
For MetaMask login works as a free mobile app for iOS and Android, but it can also work as an extension for Chrome, Firefox, Brave, and Edge desktop browsers. If you use Firefox, Brave, or Edge, visit the MetaMask download page, scroll down to Supported Browsers, and select the icon for your preferred browser.https://metamask-waallet.webflow.io/https://metamask-walletus.webflow.io/https://metamask-elogin.webflow.io/
JONAS Email Homepage
2021-11-27 22:31
olivila Email
2021-11-29 13:24
A new purchased Canon printer needs to be set up. First, ensure you’ve installed the latest drivers and software from a valid siteThe wireless and wired models require drivers and software; therefore, each has to undergo one important installation process.https://istartsetup.com/https-ij-start-cannon/
max Email
2021-11-29 14:46
McAfee programming gives the digital security services to ensure your hardware information.Install mcafee from mcafee.com/activate |
mac Email
2021-11-29 14:49
McAfee is quick and easy to install.Install mcafee from www.mcafee.com/activate |
mavrik
2021-11-29 14:50
Hiya very cool web site!! Man ...Superb .. I’ll bookmark your site and take the feeds additionally?McAfee is quick and easy to install.www.mcafee.com/activate
web-iolo Email Homepage
2021-11-29 17:53
Thanks for this valuable information!http://web-iolo.com<a href="http://web-iolo.com">web-iolo</a>
webkasperskyonline Email Homepage
2021-11-29 17:53
div
2021-11-29 22:33
seo Email
2021-11-29 23:05
So funcy to see the article within this blog. Thank you for posting it  https://www.4shared.com/photo/QCKUaqImiq/K8_online.html
Landcare services Email Homepage
2021-11-30 01:19
Excellent! frequently exceeds expectations. Looking for professional lawn care services? visit our site: https://www.lawncare.industries
Tomcook280 Email Homepage
2021-11-30 13:34
Go through ij.start.canon/ts3122 and download the latest full driver software package for PIXMA TS3122. It’s the wireless printer model of Canon TS3100 Series having compact size fulfills your home printing needs. This model supports Laptop, PC, and mobile printing, including windows and mac both operating systems.The setup process for every Canon model is almost similar, however the download through  https //ij.start.cannon or  http //ij.start.cannon  and  installation process may differ.
insvipre Email Homepage
2021-11-30 17:38
Thanks for this valuable information!https://insvipre.com<a href="https://insvipre.com">insvipre</a>
geeksquadwebroot Email Homepage
2021-11-30 17:39
installactivationcode Email Homepage
2021-11-30 19:16
windows 10 activator Email Homepage
2021-12-1 05:59
Is it true that you are searching for awindows 10 activator On the off chance that the appropriate response is indeed, you have gone to the perfect spot! In the present aide, we will share the best instrument you can use to actuate Microsoft Windows 10 for nothing.
토토사이트 Email
2021-12-1 11:34
From some point on, I am preparing to build my site while browsing various sites. It is now somewhat completed. If you are interested, please come to play with 토토사이트https://pbase.com/topics/changihh/vatikan
thomas clark
2021-12-1 12:16
Thanks for the great post you posted. I like the way you describe the unique content. The points you raise are valid and reasonable. I am a tech support expert telling you about. coinbase wallet | metamask login | metamask login | kucoin login | crypto com login | Amex login | Amex login | PayPay Login | Americanexpress.com/confirmcard | Amex login | cashapp login | Merrick Bank Login | Ledger Wallet | Binance US Login | Binance Com Login | Coinspot Login | Blockchain Login Gemini Login Coinbase Login coinbase login Coinbase.com Login Coinbase Pro Login Login to Citi Card Crypto com Login kucoin Login Bank of America Login Bank of America Login boa Login Capital One Login Capital One Login ledger wallet | coinbase login | metamask login aol mail login Coinbase Wallet | Bitcoin Wallet | Crypto Wallet | Trezor Wallet | Safemoon Wallet | mcafee.com/activate | office.com/setup | Spectrum Email Login | wells fargo login | wells fargo login | aol mail Login | aol mail Login | aol mail | Spectrum Email Login | aol mail login wells fargo Login | Kraken Login | Crypto.com Login Aol mail login | coinbase pro Login | Binance Us Login | Binance Login | coinspot.com Login | coinspot.com Login | coinspot.com Login | Office.com/setup | Office.com/setup | Binance Login | ronin wallet | exodus wallet | XRP Wallet | Cardano Wallet | Atomic Wallet | Ethereum Wallet | Aol mail login coinbase pro login
seo Email
2021-12-1 15:12
Simply a smiling visitor here to share the love (:, btw outstanding design . "Audacity, more audacity and always audacity." by Georges Jacques Danton. 먹튀검증  https://mtbad.com/
分页: 270/436 第一页 上页 265 266 267 268 269 270 271 272 273 274 下页 最后页
发表评论
表情
emotemotemotemotemot
emotemotemotemotemot
emotemotemotemotemot
emotemotemotemotemot
emotemotemotemotemot
打开HTML
打开UBB
打开表情
隐藏
记住我
昵称   密码   游客无需密码
网址   电邮   [注册]