diff options
| author | Kumar Damani <me@kumardamani.net> | 2022-09-07 20:40:17 +0000 |
|---|---|---|
| committer | Kumar Damani <me@kumardamani.net> | 2022-09-07 20:40:17 +0000 |
| commit | bbe10895d9df8dd7899bbd65575d5bf12e57f8c8 (patch) | |
| tree | 244d2f1ad38320863fb60f695c88c97799be1171 /roles/nginx_docker/templates | |
| parent | 4d34de2f5e757bfeae5738547aabb61d3d28a2f8 (diff) | |
| parent | c85806e3289b5e207d51d382f8dc75edad04404d (diff) | |
Merge branch 'alpine' into 'master'
switched to alpine initial commit
See merge request kdam0/vps!2
Diffstat (limited to 'roles/nginx_docker/templates')
| -rw-r--r-- | roles/nginx_docker/templates/app.nginx.conf.j2 | 25 | ||||
| -rw-r--r-- | roles/nginx_docker/templates/http.nginx.conf.j2 | 24 |
2 files changed, 49 insertions, 0 deletions
diff --git a/roles/nginx_docker/templates/app.nginx.conf.j2 b/roles/nginx_docker/templates/app.nginx.conf.j2 new file mode 100644 index 0000000..82c3610 --- /dev/null +++ b/roles/nginx_docker/templates/app.nginx.conf.j2 @@ -0,0 +1,25 @@ +server { + listen 443 ssl; + root _; + server_name {{ item.conf.access_domain }}; + ssl_certificate /etc/letsencrypt/live/{{ nginx_global_apps_domain }}/fullchain.pem; + ssl_certificate_key /etc/letsencrypt/live/{{ nginx_global_apps_domain }}/privkey.pem; + ssl_protocols TLSv1.1 TLSv1.2; + ssl_ciphers HIGH:!aNULL:!MD5; + + location / { +{% if item.app == "nextcloud" %} {# Nextcloud requires https internally #} + proxy_pass https://127.0.0.1:{{ item.conf.port }}; +{% else %} + proxy_pass http://127.0.0.1:{{ item.conf.port }}; +{% endif %} + proxy_set_header Host $host; + proxy_set_header X-Real-IP $remote_addr; + proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; + proxy_set_header X-Forwarded-Host $server_name; + proxy_set_header X-Forwarded-Proto https; + proxy_read_timeout 1200s; + client_max_body_size 0; + error_log /var/log/nginx/{{ item.app }}.error.log; + } +} diff --git a/roles/nginx_docker/templates/http.nginx.conf.j2 b/roles/nginx_docker/templates/http.nginx.conf.j2 new file mode 100644 index 0000000..2d4c61b --- /dev/null +++ b/roles/nginx_docker/templates/http.nginx.conf.j2 @@ -0,0 +1,24 @@ +server { + {% if item == "default" %} + listen 80 default_server; + server_name _; + return 301 https://$host$request_uri; + {% else %} + listen 443 ssl; + root /var/www/{{ item }}/html; + server_name {{ item }} www.{{ item }}; + ssl_certificate /etc/letsencrypt/live/{{ item }}/fullchain.pem; + ssl_certificate_key /etc/letsencrypt/live/{{ item }}/privkey.pem; + ssl_protocols TLSv1.1 TLSv1.2; + ssl_ciphers HIGH:!aNULL:!MD5; + index index.html index.htm index.nginx-debian.html; + + location ~ /.well-known { + allow all; + } + + location / { + try_files $uri $uri/ =404; + } + {% endif %} +} |
