Info

2024๋…„ 12์›”์— ๊ฒฝํ—˜ํ•œ ๋‚ด์šฉ์„ ๋‹ค๋ฃจ๊ณ  ์žˆ์Šต๋‹ˆ๋‹ค.

NGINX์˜ ๋ช‡ ๊ฐ€์ง€ ๋ณด์•ˆ ์„ค์ •์„ ์ •๋ฆฌํ•œ ๋‚ด์šฉ์ž…๋‹ˆ๋‹ค.

NGINX ๋ฒ„์ „ ์ˆจ๊ธฐ๊ธฐ

NGINX ๋ฒ„์ „์„ ๋…ธ์ถœ์‹œํ‚ฌ ๊ฒฝ์šฐ, ๊ณต๊ฒฉ์ž๊ฐ€ ์ทจ์•ฝ์ ์„ ํƒ์ง€ํ•˜๊ธฐ ์œ„ํ•œ ์ •๋ณด๋ฅผ ์ œ๊ณตํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.
๋‹ค์Œ ์„ค์ •์„ ํ†ตํ•ด ๋ฒ„์ „์„ ์ˆจ๊ธธ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

server_tokens off;

Kubernetes์˜ NGINX Ingress Controller๋Š” ๊ธฐ๋ณธ์ ์œผ๋กœ ์ด ์„ค์ •์ด ์ ์šฉ๋˜์–ด ์žˆ์Šต๋‹ˆ๋‹ค.

Basic Auth

์ธ์ฆ์€ ๋ณดํ†ต ๋‹ค๋ฅธ ๊ตฌ์„ฑ ์š”์†Œ์—์„œ ์„ค์ •ํ•˜์ง€๋งŒ, NGINX์—์„œ๋„ ๊ธฐ๋ณธ์ ์ธ ์ธ์ฆ ๊ธฐ๋Šฅ์„ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค.
์•„๋ž˜๋Š” ์ œ๊ฐ€ ์‚ฌ์šฉํ•œ ๋ฐฉ๋ฒ•์ž…๋‹ˆ๋‹ค.

  1. ์ธ์ฆ ์ •๋ณด๋ฅผ ์ €์žฅํ•  ํŒŒ์ผ์„ ์ƒ์„ฑํ•ฉ๋‹ˆ๋‹ค. ์—ฌ๊ธฐ์„œ๋Š” htpasswd ๋ช…๋ น์–ด๋ฅผ ์‚ฌ์šฉํ•ฉ๋‹ˆ๋‹ค.

    htpasswd -nb user password > htpasswd
  2. NGINX ๋‚ด๋ถ€ ๊ฒฝ๋กœ์— ์ƒ์„ฑํ•œ ํŒŒ์ผ์„ ๋ณต์‚ฌํ•ฉ๋‹ˆ๋‹ค. ์˜ˆ๋ฅผ ๋“ค์–ด, /etc/nginx/htpasswd ๊ฒฝ๋กœ์— ๋ณต์‚ฌํ•ฉ๋‹ˆ๋‹ค.

  3. NGINX ์„ค์ • ํŒŒ์ผ์— ์ธ์ฆ ์ •๋ณด๋ฅผ ์ถ”๊ฐ€ํ•ฉ๋‹ˆ๋‹ค.

    location / {
        auth_basic "Restricted";
        auth_basic_user_file /etc/nginx/htpasswd;
    }

์ฐธ๊ณ  ์ž๋ฃŒ