aboutsummaryrefslogtreecommitdiff
path: root/roles/nginx_docker/templates
diff options
context:
space:
mode:
authorKumar Damani <me@kumardamani.net>2022-09-07 20:40:17 +0000
committerKumar Damani <me@kumardamani.net>2022-09-07 20:40:17 +0000
commitbbe10895d9df8dd7899bbd65575d5bf12e57f8c8 (patch)
tree244d2f1ad38320863fb60f695c88c97799be1171 /roles/nginx_docker/templates
parent4d34de2f5e757bfeae5738547aabb61d3d28a2f8 (diff)
parentc85806e3289b5e207d51d382f8dc75edad04404d (diff)
Merge branch 'alpine' into 'master'
switched to alpine initial commit See merge request kdam0/vps!2
Diffstat (limited to 'roles/nginx_docker/templates')
-rw-r--r--roles/nginx_docker/templates/app.nginx.conf.j225
-rw-r--r--roles/nginx_docker/templates/http.nginx.conf.j224
2 files changed, 49 insertions, 0 deletions
diff --git a/roles/nginx_docker/templates/app.nginx.conf.j2 b/roles/nginx_docker/templates/app.nginx.conf.j2
new file mode 100644
index 0000000..82c3610
--- /dev/null
+++ b/roles/nginx_docker/templates/app.nginx.conf.j2
@@ -0,0 +1,25 @@
+server {
+ listen 443 ssl;
+ root _;
+ server_name {{ item.conf.access_domain }};
+ ssl_certificate /etc/letsencrypt/live/{{ nginx_global_apps_domain }}/fullchain.pem;
+ ssl_certificate_key /etc/letsencrypt/live/{{ nginx_global_apps_domain }}/privkey.pem;
+ ssl_protocols TLSv1.1 TLSv1.2;
+ ssl_ciphers HIGH:!aNULL:!MD5;
+
+ location / {
+{% if item.app == "nextcloud" %} {# Nextcloud requires https internally #}
+ proxy_pass https://127.0.0.1:{{ item.conf.port }};
+{% else %}
+ proxy_pass http://127.0.0.1:{{ item.conf.port }};
+{% endif %}
+ proxy_set_header Host $host;
+ proxy_set_header X-Real-IP $remote_addr;
+ proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
+ proxy_set_header X-Forwarded-Host $server_name;
+ proxy_set_header X-Forwarded-Proto https;
+ proxy_read_timeout 1200s;
+ client_max_body_size 0;
+ error_log /var/log/nginx/{{ item.app }}.error.log;
+ }
+}
diff --git a/roles/nginx_docker/templates/http.nginx.conf.j2 b/roles/nginx_docker/templates/http.nginx.conf.j2
new file mode 100644
index 0000000..2d4c61b
--- /dev/null
+++ b/roles/nginx_docker/templates/http.nginx.conf.j2
@@ -0,0 +1,24 @@
+server {
+ {% if item == "default" %}
+ listen 80 default_server;
+ server_name _;
+ return 301 https://$host$request_uri;
+ {% else %}
+ listen 443 ssl;
+ root /var/www/{{ item }}/html;
+ server_name {{ item }} www.{{ item }};
+ ssl_certificate /etc/letsencrypt/live/{{ item }}/fullchain.pem;
+ ssl_certificate_key /etc/letsencrypt/live/{{ item }}/privkey.pem;
+ ssl_protocols TLSv1.1 TLSv1.2;
+ ssl_ciphers HIGH:!aNULL:!MD5;
+ index index.html index.htm index.nginx-debian.html;
+
+ location ~ /.well-known {
+ allow all;
+ }
+
+ location / {
+ try_files $uri $uri/ =404;
+ }
+ {% endif %}
+}