You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何修改OpenRC的nginx init脚本以实现chroot环境运行?

问题描述

已成功通过以下命令在chroot环境运行Nginx:

chroot /srv/http/ /usr/bin/nginx -g 'pid /run/nginx.pid;'

现需将该命令的核心参数(-g 'pid /run/nginx.pid;')整合到默认的/etc/init.d/nginx OpenRC脚本中,实现chroot环境下Nginx的启动、重启和停止。原始脚本内容如下:

#!/usr/bin/openrc-run
# Copyright 1999-2017 Gentoo Foundation
# Distributed under the terms of the GNU General Public License v2

extra_commands="configtest"
extra_started_commands="upgrade reload"

description="Robust, small and high performance http and reverse proxy server"
description_configtest="Run nginx' internal config check."
description_upgrade="Upgrade the nginx binary without losing connections."
description_reload="Reload the nginx configuration without losing connections."

NGINX_CONFIGFILE=${NGINX_CONFIGFILE:-/etc/nginx/nginx.conf}

command="/usr/bin/nginx"
command_args="-c \"${NGINX_CONFIGFILE}\""
start_stop_daemon_args=${NGINX_SSDARGS:-"--wait 1000"}
pidfile=${NGINX_PIDFILE:-/run/nginx.pid}
user=${NGINX_USER:-nginx}
group=${NGINX_GROUP:-nginx}
retry=${NGINX_TERMTIMEOUT:-"TERM/60/KILL/5"}

depend() {
        need net
        use dns logger netmount
}

start_pre() {
        if [ "${RC_CMD}" != "restart" ]; then
                configtest || return 1
        fi
}

stop_pre() {
        if [ "${RC_CMD}" = "restart" ]; then
                configtest || return 1
        fi
}

stop_post() {
        rm -f ${pidfile}
}

reload() {
        configtest || return 1
        ebegin "Refreshing nginx' configuration"
        start-stop-daemon --signal SIGHUP --pidfile "${pidfile}"
        eend $? "Failed to reload nginx"
}

upgrade() {
        configtest || return 1
        ebegin "Upgrading nginx"

        einfo "Sending USR2 to old binary"
        start-stop-daemon --signal SIGUSR2 --pidfile "${pidfile}"

        einfo "Sleeping 3 seconds before pid-files checking"
        sleep 3

        if [ ! -f "${pidfile}.oldbin" ]; then
                eerror "File with old pid not found"
                return 1
        fi

        if [ ! -f "${pidfile}" ]; then
                eerror "New binary failed to start"
                return 1
        fi

        einfo "Sleeping 3 seconds before WINCH"
        sleep 3
        # Cannot send "WINCH" using start-stop-daemon yet, https://bugs.gentoo.org/604986
        kill -WINCH $(cat "${pidfile}.oldbin")

        einfo "Sending QUIT to old binary"
        start-stop-daemon --signal SIGQUIT --pidfile "${pidfile}.oldbin"

        einfo "Upgrade completed"
        eend $? "Upgrade failed"
}

configtest() {
        ebegin "Checking nginx' configuration"
        ${command} -c "${NGINX_CONFIGFILE}" -t -q

        if [ $? -ne 0 ]; then
                ${command} -c "${NGINX_CONFIGFILE}" -t
        fi

        eend $? "failed, please correct errors above"
}

使用系统为Artix Linux(Arch分支),未在Alpine、Gentoo等OpenRC发行版找到相关资料,邮件列表提问无回复。

解决方案

需要修改脚本的核心命令、PID文件路径及配置检查逻辑,适配chroot环境:

关键修改点

  1. 定义chroot路径变量:新增CHROOT_DIR="/srv/http",方便后续维护
  2. 调整主命令:将command改为/usr/bin/chroot,并更新command_args包含chroot路径、Nginx命令及所需参数
  3. 修正PID文件路径:chroot内的/run/nginx.pid对应主机的/srv/http/run/nginx.pid,需更新pidfile指向主机侧路径
  4. 适配配置检查:configtest函数需在chroot环境下执行,因此要调整命令为chroot调用
  5. 确保chroot环境依赖:确认/srv/http内存在/run、/etc/nginx目录,且Nginx依赖库已部署(你已手动运行成功,此步可忽略)

修改后的完整脚本

#!/usr/bin/openrc-run
# Copyright 1999-2017 Gentoo Foundation
# Distributed under the terms of the GNU General Public License v2

extra_commands="configtest"
extra_started_commands="upgrade reload"

description="Robust, small and high performance http and reverse proxy server (chrooted)"
description_configtest="Run nginx' internal config check in chroot."
description_upgrade="Upgrade the nginx binary without losing connections (chrooted)."
description_reload="Reload the nginx configuration without losing connections (chrooted)."

# 定义chroot路径
CHROOT_DIR="/srv/http"
NGINX_CONFIGFILE=${NGINX_CONFIGFILE:-/etc/nginx/nginx.conf}

# 主命令改为chroot,参数包含chroot路径、nginx命令及自定义pid参数
command="/usr/bin/chroot"
command_args="${CHROOT_DIR} /usr/bin/nginx -c \"${NGINX_CONFIGFILE}\" -g 'pid /run/nginx.pid;'"
start_stop_daemon_args=${NGINX_SSDARGS:-"--wait 1000"}
# PID文件指向主机上的chroot内路径
pidfile=${NGINX_PIDFILE:-${CHROOT_DIR}/run/nginx.pid}
user=${NGINX_USER:-nginx}
group=${NGINX_GROUP:-nginx}
retry=${NGINX_TERMTIMEOUT:-"TERM/60/KILL/5"}

depend() {
        need net
        use dns logger netmount
}

start_pre() {
        if [ "${RC_CMD}" != "restart" ]; then
                configtest || return 1
        fi
}

stop_pre() {
        if [ "${RC_CMD}" = "restart" ]; then
                configtest || return 1
        fi
}

stop_post() {
        rm -f ${pidfile}
}

reload() {
        configtest || return 1
        ebegin "Refreshing nginx' configuration"
        start-stop-daemon --signal SIGHUP --pidfile "${pidfile}"
        eend $? "Failed to reload nginx"
}

upgrade() {
        configtest || return 1
        ebegin "Upgrading nginx"

        einfo "Sending USR2 to old binary"
        start-stop-daemon --signal SIGUSR2 --pidfile "${pidfile}"

        einfo "Sleeping 3 seconds before pid-files checking"
        sleep 3

        if [ ! -f "${pidfile}.oldbin" ]; then
                eerror "File with old pid not found"
                return 1
        fi

        if [ ! -f "${pidfile}" ]; then
                eerror "New binary failed to start"
                return 1
        fi

        einfo "Sleeping 3 seconds before WINCH"
        sleep 3
        # Cannot send "WINCH" using start-stop-daemon yet, https://bugs.gentoo.org/604986
        kill -WINCH $(cat "${pidfile}.oldbin")

        einfo "Sending QUIT to old binary"
        start-stop-daemon --signal SIGQUIT --pidfile "${pidfile}.oldbin"

        einfo "Upgrade completed"
        eend $? "Upgrade failed"
}

configtest() {
        ebegin "Checking nginx' configuration in chroot"
        # 在chroot环境下执行配置检查
        /usr/bin/chroot ${CHROOT_DIR} /usr/bin/nginx -c "${NGINX_CONFIGFILE}" -t -q

        if [ $? -ne 0 ]; then
                /usr/bin/chroot ${CHROOT_DIR} /usr/bin/nginx -c "${NGINX_CONFIGFILE}" -t
        fi

        eend $? "failed, please correct errors above"
}

验证步骤

  1. 保存修改后的脚本,赋予执行权限:chmod +x /etc/init.d/nginx
  2. 测试配置检查:rc-service nginx configtest
  3. 启动Nginx:rc-service nginx start
  4. 验证进程状态:rc-service nginx status,或检查/srv/http/run/nginx.pid是否存在

内容的提问来源于stack exchange,提问作者somenxavier

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.13 10:54:56