Sign inSign up

i81b4u/byo-nginx

By i81b4u

•Updated 11 days ago

A close drop-in replacement for the nginx mainline alpine-slim image.

Image
Web servers
0

575

i81b4u/byo-nginx repository overview

⁠Custom-built nginx

i81b4u/byo-nginx is designed as a close drop-in replacement for the nginx mainline-alpine-slim docker image

The final stage is the exact official nginx image, so its entrypoint, configuration tree, nginx user (UID/GID 101), permissions, environment, logging symlinks, exposed ports and default command are retained.

Only these binaries are replaced:

/usr/sbin/nginx
/usr/sbin/nginx-debug

The replacement binaries are built from the latest mainline nginx version using the official image's configure baseline, with additional functionality aimed primarily at TLS 1.3, HTTP/3 and post-quantum cryptography testing.

⁠Added functionality

This image adds:

  • OpenSSL 4.0.2, statically linked into nginx
  • HTTP/3 / QUIC support
  • statically compiled ngx_brotli
  • certificate compression support through OpenSSL
  • the nginx-brand-i81b4u patch
  • the nginx-dynamic-tls-records-1.29.2-plus patch
  • an independently built /usr/sbin/nginx-debug binary using --with-debug

Alpine's system OpenSSL libraries are left untouched.

⁠PQC / KEM support

The image can be used to test KEMs and hybrid groups such as:

MLKEM512
MLKEM768
MLKEM1024
SecP256r1MLKEM768
X25519MLKEM768
SecP384r1MLKEM1024
curveSM2MLKEM768

This makes the image useful for experimenting with current and emerging TLS/PQC interoperability.

Together with i81b4u/byo-curl⁠, it provides a convenient client/server environment for PQC-related TLS testing.

⁠Build information for latest

nginx version: nginx/1.31.6
built by gcc 15.2.0 (Alpine 15.2.0)
built with OpenSSL 4.0.2 25 Aug 2026
TLS SNI support enabled

Configure arguments:

--prefix=/etc/nginx
--sbin-path=/usr/sbin/nginx
--modules-path=/usr/lib/nginx/modules
--conf-path=/etc/nginx/nginx.conf
--error-log-path=/var/log/nginx/error.log
--http-log-path=/var/log/nginx/access.log
--pid-path=/run/nginx.pid
--lock-path=/run/nginx.lock
--http-client-body-temp-path=/var/cache/nginx/client_temp
--http-proxy-temp-path=/var/cache/nginx/proxy_temp
--http-fastcgi-temp-path=/var/cache/nginx/fastcgi_temp
--http-uwsgi-temp-path=/var/cache/nginx/uwsgi_temp
--http-scgi-temp-path=/var/cache/nginx/scgi_temp
--with-perl_modules_path=/usr/lib/perl5/vendor_perl
--user=nginx
--group=nginx
--with-compat
--with-control-api
--with-file-aio
--with-threads
--with-http_addition_module
--with-http_auth_request_module
--with-http_dav_module
--with-http_flv_module
--with-http_gunzip_module
--with-http_gzip_static_module
--with-http_json_module
--with-http_mp4_module
--with-http_random_index_module
--with-http_realip_module
--with-http_secure_link_module
--with-http_slice_module
--with-http_ssl_module
--with-http_stub_status_module
--with-http_sub_module
--with-http_v2_module
--with-http_v3_module
--with-mail
--with-mail_ssl_module
--with-stream
--with-stream_realip_module
--with-stream_ssl_module
--with-stream_ssl_preread_module
--add-module=/src/ngx_brotli
--with-openssl=/src/openssl
--with-openssl-opt='no-shared no-tests enable-zlib enable-tls1_3 enable-ec_nistp_64_gcc_128'
--with-cc-opt='-Os -fstack-clash-protection -Wformat -Werror=format-security -fno-plt -g'
--with-ld-opt='-Wl,--as-needed,-O1,--sort-common -Wl,-z,pack-relative-relocs'

⁠Usage

For most existing deployments, replacing:

nginx:1.31.6-alpine-slim or nginx:mainline-alpine-slim

with:

i81b4u/byo-nginx:1.31.6-alpine-slim or i81b4u/byo-nginx:latest

should be sufficient.

The image is intended to stay as close as reasonably possible to the behavior of the official image while adding the functionality listed above.

It is nevertheless a custom build, so test it against your own configuration before using it in production.

For a configuration example, see:

tlsv1.3-nginx⁠

⁠Version history

⁠1.31.6-alpine-slim-2026091801
  • Updated from alpine 3.24.1 to 3.24.2
⁠1.31.6-alpine-slim-2026091601
  • Updated nginx from 1.31.5 to 1.31.6
⁠1.31.5-alpine-slim-2026090501
  • Added "with-control-api" and "with-http_json_module" compile options
⁠1.31.5-alpine-slim-2026090301
  • Updated nginx from 1.31.4 to 1.31.5
⁠1.31.4-alpine-slim-2026082501
  • Updated OpenSSL from 4.0.1 to 4.0.2

i81b4u/byo-curl⁠

Both projects were originally created to make PQC-related TLS testing easier, but they can also be used as alternatives to their official counterparts.

Have fun!

Tag summary

Content type

Image

Digest

sha256:2eb413219…

Size

12.8 MB

Last updated

11 days ago

docker pull i81b4u/byo-nginx