A close drop-in replacement for the nginx mainline alpine-slim image.
575
i81b4u/byo-nginx is designed as a close drop-in replacement for the nginx mainline-alpine-slim docker image
The final stage is the exact official nginx image, so its entrypoint, configuration tree, nginx user (UID/GID 101), permissions, environment, logging symlinks, exposed ports and default command are retained.
Only these binaries are replaced:
/usr/sbin/nginx
/usr/sbin/nginx-debug
The replacement binaries are built from the latest mainline nginx version using the official image's configure baseline, with additional functionality aimed primarily at TLS 1.3, HTTP/3 and post-quantum cryptography testing.
This image adds:
ngx_brotlinginx-brand-i81b4u patchnginx-dynamic-tls-records-1.29.2-plus patch/usr/sbin/nginx-debug binary using --with-debugAlpine's system OpenSSL libraries are left untouched.
The image can be used to test KEMs and hybrid groups such as:
MLKEM512
MLKEM768
MLKEM1024
SecP256r1MLKEM768
X25519MLKEM768
SecP384r1MLKEM1024
curveSM2MLKEM768
This makes the image useful for experimenting with current and emerging TLS/PQC interoperability.
Together with i81b4u/byo-curl, it provides a convenient client/server environment for PQC-related TLS testing.
latestnginx version: nginx/1.31.6
built by gcc 15.2.0 (Alpine 15.2.0)
built with OpenSSL 4.0.2 25 Aug 2026
TLS SNI support enabled
Configure arguments:
--prefix=/etc/nginx
--sbin-path=/usr/sbin/nginx
--modules-path=/usr/lib/nginx/modules
--conf-path=/etc/nginx/nginx.conf
--error-log-path=/var/log/nginx/error.log
--http-log-path=/var/log/nginx/access.log
--pid-path=/run/nginx.pid
--lock-path=/run/nginx.lock
--http-client-body-temp-path=/var/cache/nginx/client_temp
--http-proxy-temp-path=/var/cache/nginx/proxy_temp
--http-fastcgi-temp-path=/var/cache/nginx/fastcgi_temp
--http-uwsgi-temp-path=/var/cache/nginx/uwsgi_temp
--http-scgi-temp-path=/var/cache/nginx/scgi_temp
--with-perl_modules_path=/usr/lib/perl5/vendor_perl
--user=nginx
--group=nginx
--with-compat
--with-control-api
--with-file-aio
--with-threads
--with-http_addition_module
--with-http_auth_request_module
--with-http_dav_module
--with-http_flv_module
--with-http_gunzip_module
--with-http_gzip_static_module
--with-http_json_module
--with-http_mp4_module
--with-http_random_index_module
--with-http_realip_module
--with-http_secure_link_module
--with-http_slice_module
--with-http_ssl_module
--with-http_stub_status_module
--with-http_sub_module
--with-http_v2_module
--with-http_v3_module
--with-mail
--with-mail_ssl_module
--with-stream
--with-stream_realip_module
--with-stream_ssl_module
--with-stream_ssl_preread_module
--add-module=/src/ngx_brotli
--with-openssl=/src/openssl
--with-openssl-opt='no-shared no-tests enable-zlib enable-tls1_3 enable-ec_nistp_64_gcc_128'
--with-cc-opt='-Os -fstack-clash-protection -Wformat -Werror=format-security -fno-plt -g'
--with-ld-opt='-Wl,--as-needed,-O1,--sort-common -Wl,-z,pack-relative-relocs'
For most existing deployments, replacing:
nginx:1.31.6-alpine-slim or nginx:mainline-alpine-slim
with:
i81b4u/byo-nginx:1.31.6-alpine-slim or i81b4u/byo-nginx:latest
should be sufficient.
The image is intended to stay as close as reasonably possible to the behavior of the official image while adding the functionality listed above.
It is nevertheless a custom build, so test it against your own configuration before using it in production.
For a configuration example, see:
Both projects were originally created to make PQC-related TLS testing easier, but they can also be used as alternatives to their official counterparts.
Have fun!
Content type
Image
Digest
sha256:2eb413219…
Size
12.8 MB
Last updated
11 days ago
docker pull i81b4u/byo-nginx