cmc/dotfiles

Using GNU Stow to manage my dotfiles. config dotfiles macos stow

Commit 0f11584bff

0f11584bff5fb485a929f60065c17a6b1639d0fd

parent: 99425e089f

Verified · cmc

cmc <hello@cleberg.net> · 2026-02-16 18:08 UTC

slightly minify nginx files

Layout: unified · split

linux/nginx/etc/nginx/conf.d/ao.conf +2 −25
@@ -1,39 +1,16 @@
1# ----------------------------------------------------------------------
2# | Config file for host |
3# ----------------------------------------------------------------------
41server {
52 listen [::]:443 ssl;
63 listen 443 ssl;
74 http2 on;
8
95 server_name ao.cleberg.net;
10
116 include custom.d/tls/ssl_engine.conf;
127 include custom.d/tls/certificate_files.conf;
138 include custom.d/tls/policy_balanced.conf;
149 include custom.d/basic.conf;
15
16 # ----------------------------------------------------------------------
17 # | Custom rules & config for specific website |
18 # ----------------------------------------------------------------------
1910 location / {
20 set $upstream http://127.0.0.1:9380;
21 proxy_pass $upstream;
22
11 set $upstream http://127.0.0.1:9380;
12 proxy_pass $upstream;
2313 include custom.d/reverse_proxy/basic.conf;
2414 }
25
2615 include custom.d/security/robots_index_only.conf;
27 # ----------------------------------------------------------------------
28}
29
30# ----------------------------------------------------------------------
31# | Config file for non-secure host |
32# ----------------------------------------------------------------------
33server {
34 listen [::]:80;
35 listen 80;
36 server_name ao.cleberg.net;
37
38 return 301 https://$host$request_uri;
3916}
linux/nginx/etc/nginx/conf.d/art.conf +3 −26
@@ -1,39 +1,16 @@
1# ----------------------------------------------------------------------
2# | Config file for host |
3# ----------------------------------------------------------------------
41server {
52 listen [::]:443 ssl;
63 listen 443 ssl;
74 http2 on;
8
95 server_name art.cleberg.net;
10
116 include custom.d/tls/ssl_engine.conf;
127 include custom.d/tls/certificate_files.conf;
138 include custom.d/tls/policy_balanced.conf;
149 include custom.d/basic.conf;
15
16 # ----------------------------------------------------------------------
17 # | Custom rules & config for specific website |
18 # ----------------------------------------------------------------------
1910 location / {
20 set $upstream http://127.0.0.1:3003;
21 proxy_pass $upstream;
22
11 set $upstream http://127.0.0.1:3003;
12 proxy_pass $upstream;
2313 include custom.d/reverse_proxy/basic.conf;
2414 }
25
26 include custom.d/security/robots_index_only.conf;
27 # ----------------------------------------------------------------------
28}
29
30# ----------------------------------------------------------------------
31# | Config file for non-secure host |
32# ----------------------------------------------------------------------
33server {
34 listen [::]:80;
35 listen 80;
36 server_name art.cleberg.net;
37
38 return 301 https://$host$request_uri;
15 include custom.d/security/robots_index_only.conf;
3916}
linux/nginx/etc/nginx/conf.d/auth.conf +3 −29
@@ -1,42 +1,16 @@
1# ----------------------------------------------------------------------
2# | Config file for host |
3# ----------------------------------------------------------------------
41server {
52 listen [::]:443 ssl;
63 listen 443 ssl;
74 http2 on;
8
95 server_name auth.cleberg.net;
10
116 include custom.d/tls/ssl_engine.conf;
127 include custom.d/tls/certificate_files.conf;
138 include custom.d/tls/policy_balanced.conf;
149 include custom.d/basic.conf;
15
16 # ----------------------------------------------------------------------
17 # | Custom rules & config for specific website |
18 # ----------------------------------------------------------------------
19 set $upstream http://127.0.0.1:9092;
20
10 set $upstream http://127.0.0.1:9092;
2111 location / {
22 proxy_pass $upstream;
23
12 proxy_pass $upstream;
2413 include custom.d/reverse_proxy/basic.conf;
2514 }
26
27 location /api/verify {
28 proxy_pass $upstream;
29 }
30 # ----------------------------------------------------------------------
31}
32
33# ----------------------------------------------------------------------
34# | Config file for non-secure host |
35# ----------------------------------------------------------------------
36server {
37 listen [::]:80;
38 listen 80;
39 server_name auth.cleberg.net;
40
41 return 301 https://$host$request_uri;
15 location /api/verify { proxy_pass $upstream; }
4216}
linux/nginx/etc/nginx/conf.d/br.conf +5 −28
@@ -1,39 +1,16 @@
1# ----------------------------------------------------------------------
2# | Config file for host |
3# ----------------------------------------------------------------------
41server {
52 listen [::]:443 ssl;
63 listen 443 ssl;
74 http2 on;
8
95 server_name br.cleberg.net;
10
116 include custom.d/tls/ssl_engine.conf;
127 include custom.d/tls/certificate_files.conf;
138 include custom.d/tls/policy_balanced.conf;
149 include custom.d/basic.conf;
15
16 # ----------------------------------------------------------------------
17 # | Custom rules & config for specific website |
18 # ----------------------------------------------------------------------
19 location / {
20 set $upstream http://127.0.0.1:3030;
21 proxy_pass $upstream;
22
10 location / {
11 set $upstream http://127.0.0.1:3030;
12 proxy_pass $upstream;
2313 include custom.d/reverse_proxy/basic.conf;
24 }
25
26 include custom.d/security/robots_index_only.conf;
27 # ----------------------------------------------------------------------
28}
29
30# ----------------------------------------------------------------------
31# | Config file for non-secure host |
32# ----------------------------------------------------------------------
33server {
34 listen [::]:80;
35 listen 80;
36 server_name br.cleberg.net;
37
38 return 301 https://$host$request_uri;
14 }
15 include custom.d/security/robots_index_only.conf;
3916}
linux/nginx/etc/nginx/conf.d/bt.conf +4 −32
@@ -1,46 +1,18 @@
1# ----------------------------------------------------------------------
2# | Config file for host |
3# ----------------------------------------------------------------------
41server {
52 listen [::]:443 ssl;
63 listen 443 ssl;
74 http2 on;
8
95 server_name bt.cleberg.net;
10
116 include custom.d/tls/ssl_engine.conf;
127 include custom.d/tls/certificate_files.conf;
138 include custom.d/tls/policy_balanced.conf;
149 include custom.d/basic.conf;
15
16 # ----------------------------------------------------------------------
17 # | Custom rules & config for specific website |
18 # ----------------------------------------------------------------------
19 set $upstream http://127.0.0.1:9091;
20
21 location /authelia {
22 include custom.d/reverse_proxy/authelia.conf;
23 }
24
10 set $upstream http://127.0.0.1:9091;
11 location /authelia { include custom.d/reverse_proxy/authelia.conf; }
2512 location / {
26 proxy_pass $upstream;
27
13 proxy_pass $upstream;
2814 include custom.d/reverse_proxy/authelia_request.conf;
29 # include custom.d/reverse_proxy/basic.conf;
3015 proxy_pass_header X-bt-Session-Id;
3116 }
32
33 include custom.d/security/robots_index_only.conf;
34 # ----------------------------------------------------------------------
35}
36
37# ----------------------------------------------------------------------
38# | Config file for non-secure host |
39# ----------------------------------------------------------------------
40server {
41 listen [::]:80;
42 listen 80;
43 server_name bt.cleberg.net;
44
45 return 301 https://$host$request_uri;
17 include custom.d/security/robots_index_only.conf;
4618}
linux/nginx/etc/nginx/conf.d/bw.conf +14 −37
@@ -1,39 +1,16 @@
1# ----------------------------------------------------------------------
2# | Config file for host |
3# ----------------------------------------------------------------------
41server {
5 listen [::]:443 ssl;
6 listen 443 ssl;
7 http2 on;
8
9 server_name bw.cleberg.net;
10
11 include custom.d/tls/ssl_engine.conf;
12 include custom.d/tls/certificate_files.conf;
13 include custom.d/tls/policy_balanced.conf;
14 include custom.d/basic.conf;
15
16 # ----------------------------------------------------------------------
17 # | Custom rules & config for specific website |
18 # ----------------------------------------------------------------------
19 location / {
20 set $upstream http://127.0.0.1:10416;
21 proxy_pass $upstream;
22
23 include custom.d/reverse_proxy/basic.conf;
24 }
25
26 include custom.d/security/robots_index_only.conf;
27 # ----------------------------------------------------------------------
28}
29
30# ----------------------------------------------------------------------
31# | Config file for non-secure host |
32# ----------------------------------------------------------------------
33server {
34 listen [::]:80;
35 listen 80;
36 server_name bw.cleberg.net;
37
38 return 301 https://$host$request_uri;
2 listen [::]:443 ssl;
3 listen 443 ssl;
4 http2 on;
5 server_name bw.cleberg.net;
6 include custom.d/tls/ssl_engine.conf;
7 include custom.d/tls/certificate_files.conf;
8 include custom.d/tls/policy_balanced.conf;
9 include custom.d/basic.conf;
10 location / {
11 set $upstream http://127.0.0.1:10416;
12 proxy_pass $upstream;
13 include custom.d/reverse_proxy/basic.conf;
14 }
15 include custom.d/security/robots_index_only.conf;
3916}
linux/nginx/etc/nginx/conf.d/cc.conf +3 −26
@@ -1,39 +1,16 @@
1# ----------------------------------------------------------------------
2# | Config file for host |
3# ----------------------------------------------------------------------
41server {
52 listen [::]:443 ssl;
63 listen 443 ssl;
74 http2 on;
8
95 server_name cc.cleberg.net;
10
116 include custom.d/tls/ssl_engine.conf;
127 include custom.d/tls/certificate_files.conf;
138 include custom.d/tls/policy_balanced.conf;
149 include custom.d/basic.conf;
15
16 # ----------------------------------------------------------------------
17 # | Custom rules & config for specific website |
18 # ----------------------------------------------------------------------
1910 location / {
20 set $upstream http://127.0.0.1:8111;
21 proxy_pass $upstream;
22
11 set $upstream http://127.0.0.1:8111;
12 proxy_pass $upstream;
2313 include custom.d/reverse_proxy/basic.conf;
2414 }
25
26 include custom.d/security/robots_index_only.conf;
27 # ----------------------------------------------------------------------
28}
29
30# ----------------------------------------------------------------------
31# | Config file for non-secure host |
32# ----------------------------------------------------------------------
33server {
34 listen [::]:80;
35 listen 80;
36 server_name cc.cleberg.net;
37
38 return 301 https://$host$request_uri;
15 include custom.d/security/robots_index_only.conf;
3916}
linux/nginx/etc/nginx/conf.d/cleberg.io deleted −54
@@ -1,54 +0,0 @@
1# ----------------------------------------------------------------------
2# | Config file for host |
3# ----------------------------------------------------------------------
4server {
5 listen [::]:443 ssl;
6 listen 443 ssl;
7 http2 on;
8
9 server_name www.cleberg.io cleberg.io;
10
11 include custom.d/tls/ssl_engine.conf;
12 include custom.d/tls/policy_balanced.conf;
13# include custom.d/tls/certificate_files.conf;
14 ssl_certificate /etc/letsencrypt/live/cleberg.io/fullchain.pem;
15 ssl_certificate_key /etc/letsencrypt/live/cleberg.io/privkey.pem;
16 ssl_trusted_certificate /etc/letsencrypt/live/cleberg.io/chain.pem;
17
18 return 301 $scheme://cleberg.io$request_uri;
19}
20
21
22server {
23 listen [::]:443 ssl;
24 listen 443 ssl;
25 http2 on;
26
27 server_name cleberg.io;
28
29 include custom.d/tls/ssl_engine.conf;
30 include custom.d/tls/policy_balanced.conf;
31 include custom.d/basic.conf;
32
33# include custom.d/tls/certificate_files.conf;
34 ssl_certificate /etc/letsencrypt/live/cleberg.io/fullchain.pem;
35 ssl_certificate_key /etc/letsencrypt/live/cleberg.io/privkey.pem;
36 ssl_trusted_certificate /etc/letsencrypt/live/cleberg.io/chain.pem;
37
38 # ----------------------------------------------------------------------
39 # | Custom rules & config for specific website |
40 # ----------------------------------------------------------------------
41 return 301 https://cleberg.net;
42 # ----------------------------------------------------------------------
43}
44
45# ----------------------------------------------------------------------
46# | Config file for non-secure host |
47# ----------------------------------------------------------------------
48server {
49 listen [::]:80;
50 listen 80;
51 server_name www.cleberg.io cleberg.io;
52
53 return 301 https://cleberg.io$request_uri;
54}
linux/nginx/etc/nginx/conf.d/cleberg.io.conf added +20
@@ -0,0 +1,20 @@
1server {
2 listen [::]:443 ssl;
3 listen 443 ssl;
4 http2 on;
5 server_name cleberg.io;
6 include custom.d/tls/ssl_engine.conf;
7 include custom.d/tls/policy_balanced.conf;
8 include custom.d/basic.conf;
9 ssl_certificate /etc/letsencrypt/live/cleberg.io/fullchain.pem;
10 ssl_certificate_key /etc/letsencrypt/live/cleberg.io/privkey.pem;
11 ssl_trusted_certificate /etc/letsencrypt/live/cleberg.io/chain.pem;
12 return 301 https://cleberg.net;
13}
14
15server {
16 listen [::]:80;
17 listen 80;
18 server_name www.cleberg.io cleberg.io;
19 return 301 https://cleberg.io$request_uri;
20}
linux/nginx/etc/nginx/conf.d/cleberg.net.conf +5 −41
@@ -1,70 +1,34 @@
1# ----------------------------------------------------------------------
2# | Config file for host |
3# ----------------------------------------------------------------------
41server {
52 listen [::]:443 ssl;
63 listen 443 ssl;
74 http2 on;
8
95 server_name www.cleberg.net;
10
116 include custom.d/tls/ssl_engine.conf;
127 include custom.d/tls/certificate_files.conf;
138 include custom.d/tls/policy_balanced.conf;
14
159 return 301 $scheme://cleberg.net$request_uri;
1610}
1711
18
1912server {
2013 listen [::]:443 ssl;
2114 listen 443 ssl;
2215 http2 on;
23
2416 server_name cleberg.net;
25
2617 include custom.d/tls/ssl_engine.conf;
2718 include custom.d/tls/certificate_files.conf;
2819 include custom.d/tls/policy_balanced.conf;
2920 include custom.d/basic.conf;
30
3121 root /var/www/cleberg.net/;
32
33 # ----------------------------------------------------------------------
34 # | Custom rules & config for specific website |
35 # ----------------------------------------------------------------------
36 location / {
37 try_files $uri $uri/ =404;
38 }
39
40 # fix: redirect blog & wiki posts from "/" to ".html"
41 location /blog/ {
42 rewrite ^/blog/((?!index)[^/]+)/(.*)$ /blog/$1.html permanent;
43 }
44
45 location /wiki/ {
46 rewrite ^/wiki/((?!index)[^/]+)/(.*)$ /wiki/$1.html permanent;
47 }
48
49 # fix: redirect atom.xml to feed.xml
50 location /atom.xml {
51 return 301 $scheme://$host/feed.xml;
52 }
53
54 # fix: redirect salary page
55 location /blog/salary-transparency.html {
56 return 301 $scheme://$host/salary/;
57 }
58 # ----------------------------------------------------------------------
22 location / { try_files $uri $uri/ =404; }
23 location /blog/ { rewrite ^/blog/((?!index)[^/]+)/(.*)$ /blog/$1.html permanent; }
24 location /wiki/ { rewrite ^/wiki/((?!index)[^/]+)/(.*)$ /wiki/$1.html permanent; }
25 location /atom.xml { return 301 $scheme://$host/feed.xml; }
26 location /blog/salary-transparency.html { return 301 $scheme://$host/salary/; }
5927}
6028
61# ----------------------------------------------------------------------
62# | Config file for non-secure host |
63# ----------------------------------------------------------------------
6429server {
6530 listen [::]:80;
6631 listen 80;
6732 server_name www.cleberg.net cleberg.net;
68
6933 return 301 https://cleberg.net$request_uri;
7034}
linux/nginx/etc/nginx/conf.d/cleberg.net_wildcard.conf −24
@@ -4,27 +4,3 @@ server {
44 server_name .cleberg.net;
55 return 301 https://$host$request_uri;
66}
7
8server {
9 listen 443 ssl;
10 listen [::]:443 ssl;
11 http2 on;
12
13 server_name .cleberg.net;
14
15 include custom.d/tls/ssl_engine.conf;
16 include custom.d/tls/certificate_files.conf;
17 include custom.d/tls/policy_balanced.conf;
18 include custom.d/basic.conf;
19
20 location / {
21 if ($backend_address = "") {
22 return 404;
23 }
24
25 proxy_pass $backend_address;
26 include custom.d/reverse_proxy/basic.conf;
27 }
28
29 include custom.d/security/robots_index_only.conf;
30}
linux/nginx/etc/nginx/conf.d/cv.conf +1 −25
@@ -1,37 +1,13 @@
1# ----------------------------------------------------------------------
2# | Config file for host |
3# ----------------------------------------------------------------------
41server {
52 listen [::]:443 ssl;
63 listen 443 ssl;
74 http2 on;
8
95 server_name cv.cleberg.net;
10
116 include custom.d/tls/ssl_engine.conf;
127 include custom.d/tls/certificate_files.conf;
138 include custom.d/tls/policy_balanced.conf;
149 include custom.d/basic.conf;
15
1610 root /var/www/cv/;
1711 autoindex on;
18
19 # ----------------------------------------------------------------------
20 # | Custom rules & config for specific website |
21 # ----------------------------------------------------------------------
22 location / {
23 try_files $uri $uri/ /index.html;
24 }
25 # ----------------------------------------------------------------------
26}
27
28# ----------------------------------------------------------------------
29# | Config file for non-secure host |
30# ----------------------------------------------------------------------
31server {
32 listen [::]:80;
33 listen 80;
34 server_name cv.cleberg.net;
35
36 return 301 https://$host$request_uri;
12 location / { try_files $uri $uri/ /index.html; }
3713}
linux/nginx/etc/nginx/conf.d/ddns.conf +4 −30
@@ -1,44 +1,18 @@
1# ----------------------------------------------------------------------
2# | Config file for host |
3# ----------------------------------------------------------------------
41server {
52 listen [::]:443 ssl;
63 listen 443 ssl;
74 http2 on;
8
95 server_name ddns.cleberg.net;
10
116 include custom.d/tls/ssl_engine.conf;
127 include custom.d/tls/certificate_files.conf;
138 include custom.d/tls/policy_balanced.conf;
149 include custom.d/basic.conf;
15
16 # ----------------------------------------------------------------------
17 # | Custom rules & config for specific website |
18 # ----------------------------------------------------------------------
19 location /authelia {
20 include custom.d/reverse_proxy/authelia.conf;
21 }
22
10 location /authelia { include custom.d/reverse_proxy/authelia.conf; }
2311 location / {
24 set $upstream http://127.0.0.1:8097;
25 proxy_pass $upstream;
26
12 set $upstream http://127.0.0.1:8097;
13 proxy_pass $upstream;
2714 include custom.d/reverse_proxy/authelia_request.conf;
2815 include custom.d/reverse_proxy/basic.conf;
2916 }
30
31 include custom.d/security/robots_index_only.conf;
32 # ----------------------------------------------------------------------
33}
34
35# ----------------------------------------------------------------------
36# | Config file for non-secure host |
37# ----------------------------------------------------------------------
38server {
39 listen [::]:80;
40 listen 80;
41 server_name ddns.cleberg.net;
42
43 return 301 https://$host$request_uri;
17 include custom.d/security/robots_index_only.conf;
4418}
linux/nginx/etc/nginx/conf.d/default.conf +12 −28
@@ -1,33 +1,17 @@
1# ----------------------------------------------------------------------
2# | Default behavior for unknown hosts |
3# ----------------------------------------------------------------------
4#
5# Drop requests for unknown hosts.
6#
7# If no default server is defined, Nginx will use the first found server.
8# To prevent host header attacks, or other potential problems when an unknown
9# server name is used in a request, it's recommended to drop the request
10# returning 444 "No Response".
11
121server {
13 listen [::]:443 ssl default_server;
14 listen 443 ssl default_server;
15 http2 on;
16
17 server_name _;
18
19 include custom.d/tls/ssl_engine.conf;
20 include custom.d/tls/certificate_files.conf;
21 include custom.d/tls/policy_balanced.conf;
22
23 return 444;
2 listen [::]:443 ssl default_server;
3 listen 443 ssl default_server;
4 http2 on;
5 server_name _;
6 include custom.d/tls/ssl_engine.conf;
7 include custom.d/tls/certificate_files.conf;
8 include custom.d/tls/policy_balanced.conf;
9 return 444;
2410}
2511
2612server {
27 listen [::]:80;
28 listen 80;
29
30 server_name _;
31
32 return 444;
13 listen [::]:80;
14 listen 80;
15 server_name _;
16 return 444;
3317}
linux/nginx/etc/nginx/conf.d/docker.conf +4 −30
@@ -1,44 +1,18 @@
1# ----------------------------------------------------------------------
2# | Config file for host |
3# ----------------------------------------------------------------------
41server {
52 listen [::]:443 ssl;
63 listen 443 ssl;
74 http2 on;
8
95 server_name docker.cleberg.net;
10
116 include custom.d/tls/ssl_engine.conf;
127 include custom.d/tls/certificate_files.conf;
138 include custom.d/tls/policy_balanced.conf;
149 include custom.d/basic.conf;
15
16 # ----------------------------------------------------------------------
17 # | Custom rules & config for specific website |
18 # ----------------------------------------------------------------------
19 location /authelia {
20 include custom.d/reverse_proxy/authelia.conf;
21 }
22
10 location /authelia { include custom.d/reverse_proxy/authelia.conf; }
2311 location / {
24 set $upstream http://127.0.0.1:3777;
25 proxy_pass $upstream;
26
12 set $upstream http://127.0.0.1:3777;
13 proxy_pass $upstream;
2714 include custom.d/reverse_proxy/authelia_request.conf;
2815 include custom.d/reverse_proxy/basic.conf;
2916 }
30
31 include custom.d/security/robots_index_only.conf;
32 # ----------------------------------------------------------------------
33}
34
35# ----------------------------------------------------------------------
36# | Config file for non-secure host |
37# ----------------------------------------------------------------------
38server {
39 listen [::]:80;
40 listen 80;
41 server_name docker.cleberg.net;
42
43 return 301 https://$host$request_uri;
17 include custom.d/security/robots_index_only.conf;
4418}
linux/nginx/etc/nginx/conf.d/files.conf +1 −28
@@ -1,40 +1,13 @@
1# ----------------------------------------------------------------------
2# | Config file for files.cleberg.net host |
3# ----------------------------------------------------------------------
41server {
52 listen [::]:443 ssl;
63 listen 443 ssl;
74 http2 on;
8
9 # The host name to respond to
105 server_name files.cleberg.net;
11
126 include custom.d/tls/ssl_engine.conf;
137 include custom.d/tls/certificate_files.conf;
148 include custom.d/tls/policy_balanced.conf;
159 include custom.d/basic.conf;
16
1710 root /var/www/files/;
1811 autoindex on;
19
20 # Include the basic custom.d config set
21
22 # ----------------------------------------------------------------------
23 # | Custom rules & config for specific website |
24 # ----------------------------------------------------------------------
25 location / {
26 try_files $uri $uri/ /index.html;
27 }
28 # ----------------------------------------------------------------------
29}
30
31# ----------------------------------------------------------------------
32# | Config file for non-secure cleberg.net host |
33# ----------------------------------------------------------------------
34server {
35 listen [::]:80;
36 listen 80;
37 server_name files.cleberg.net;
38
39 return 301 https://$host$request_uri;
12 location / { try_files $uri $uri/ /index.html; }
4013}
linux/nginx/etc/nginx/conf.d/gh.conf +2 −25
@@ -1,39 +1,16 @@
1# ----------------------------------------------------------------------
2# | Config file for host |
3# ----------------------------------------------------------------------
41server {
52 listen [::]:443 ssl;
63 listen 443 ssl;
74 http2 on;
8
95 server_name gh.cleberg.net;
10
116 include custom.d/tls/ssl_engine.conf;
127 include custom.d/tls/certificate_files.conf;
138 include custom.d/tls/policy_balanced.conf;
149 include custom.d/basic.conf;
15
16 # ----------------------------------------------------------------------
17 # | Custom rules & config for specific website |
18 # ----------------------------------------------------------------------
1910 location / {
20 set $upstream http://192.168.0.251:3039;
21 proxy_pass $upstream;
22
11 set $upstream http://192.168.0.251:3039;
12 proxy_pass $upstream;
2313 include custom.d/reverse_proxy/basic.conf;
2414 }
25
2615 include custom.d/security/robots_index_only.conf;
27 # ----------------------------------------------------------------------
28}
29
30# ----------------------------------------------------------------------
31# | Config file for non-secure host |
32# ----------------------------------------------------------------------
33server {
34 listen [::]:80;
35 listen 80;
36 server_name gh.cleberg.net;
37
38 return 301 https://$host$request_uri;
3916}
linux/nginx/etc/nginx/conf.d/ha.conf +3 −27
@@ -1,46 +1,22 @@
1# ----------------------------------------------------------------------
2# | Config file for host |
3# ----------------------------------------------------------------------
41server {
52 listen [::]:443 ssl;
63 listen 443 ssl;
74 http2 on;
8
95 server_name ha.cleberg.net;
10
116 include custom.d/tls/ssl_engine.conf;
127 include custom.d/tls/certificate_files.conf;
138 include custom.d/tls/policy_balanced.conf;
149 include custom.d/basic.conf;
15
16 # ----------------------------------------------------------------------
17 # | Custom rules & config for specific website |
18 # ----------------------------------------------------------------------
19 set $upstream http://192.168.0.214:8123;
20
10 set $upstream http://192.168.0.214:8123;
2111 location / {
22 proxy_pass $upstream;
12 proxy_pass $upstream;
2313 proxy_set_header X-Forwarded-For $remote_addr;
2414 }
25
2615 location /api/websocket {
2716 proxy_pass $upstream;
2817 proxy_http_version 1.1;
2918 proxy_set_header Upgrade $http_upgrade;
3019 proxy_set_header Connection "upgrade";
3120 }
32
33 include custom.d/security/robots_index_only.conf;
34 # ----------------------------------------------------------------------
35}
36
37# ----------------------------------------------------------------------
38# | Config file for non-secure host |
39# ----------------------------------------------------------------------
40server {
41 listen [::]:80;
42 listen 80;
43 server_name ha.cleberg.net;
44
45 return 301 https://$host$request_uri;
21 include custom.d/security/robots_index_only.conf;
4622}
linux/nginx/etc/nginx/conf.d/hat.conf +3 −26
@@ -1,39 +1,16 @@
1# ----------------------------------------------------------------------
2# | Config file for host |
3# ----------------------------------------------------------------------
41server {
52 listen [::]:443 ssl;
63 listen 443 ssl;
74 http2 on;
8
95 server_name hat.cleberg.net;
10
116 include custom.d/tls/ssl_engine.conf;
127 include custom.d/tls/certificate_files.conf;
138 include custom.d/tls/policy_balanced.conf;
149 include custom.d/basic.conf;
15
16 # ----------------------------------------------------------------------
17 # | Custom rules & config for specific website |
18 # ----------------------------------------------------------------------
1910 location / {
20 set $upstream http://192.168.0.251:3991;
21 proxy_pass $upstream;
22
11 set $upstream http://192.168.0.251:3991;
12 proxy_pass $upstream;
2313 include custom.d/reverse_proxy/basic.conf;
2414 }
25
26 include custom.d/security/robots_index_only.conf;
27 # ----------------------------------------------------------------------
28}
29
30# ----------------------------------------------------------------------
31# | Config file for non-secure host |
32# ----------------------------------------------------------------------
33server {
34 listen [::]:80;
35 listen 80;
36 server_name hat.cleberg.net;
37
38 return 301 https://$host$request_uri;
15 include custom.d/security/robots_index_only.conf;
3916}
linux/nginx/etc/nginx/conf.d/hn.conf +12 −25
@@ -1,27 +1,14 @@
11server {
2 listen [::]:443 ssl;
3 listen 443 ssl;
4 http2 on;
5
6 server_name hn.cleberg.net r3yfeffyj7ornpikojmw75u3sn2la7tqnmcmwgv2ov7if24sm5czqeid.onion;
7 root /var/www/hn/output/;
8 autoindex on;
9 add_header Onion-Location http://r3yfeffyj7ornpikojmw75u3sn2la7tqnmcmwgv2ov7if24sm5czqeid.onion;
10
11 include custom.d/tls/ssl_engine.conf;
12 include custom.d/tls/certificate_files.conf;
13 include custom.d/tls/policy_balanced.conf;
14 include custom.d/basic.conf;
15
16 location / {
17 try_files $uri $uri/ /index.html;
18 }
19}
20
21server {
22 listen [::]:80;
23 listen 80;
24 server_name hn.cleberg.net;
25
26 return 301 https://$host$request_uri;
2 listen [::]:443 ssl;
3 listen 443 ssl;
4 http2 on;
5 server_name hn.cleberg.net r3yfeffyj7ornpikojmw75u3sn2la7tqnmcmwgv2ov7if24sm5czqeid.onion;
6 root /var/www/hn/output/;
7 autoindex on;
8 add_header Onion-Location http://r3yfeffyj7ornpikojmw75u3sn2la7tqnmcmwgv2ov7if24sm5czqeid.onion;
9 include custom.d/tls/ssl_engine.conf;
10 include custom.d/tls/certificate_files.conf;
11 include custom.d/tls/policy_balanced.conf;
12 include custom.d/basic.conf;
13 location / { try_files $uri $uri/ /index.html; }
2714}
linux/nginx/etc/nginx/conf.d/img.conf +1 −25
@@ -1,37 +1,13 @@
1# ----------------------------------------------------------------------
2# | Config file for host |
3# ----------------------------------------------------------------------
41server {
52 listen [::]:443 ssl;
63 listen 443 ssl;
74 http2 on;
8
95 server_name img.cleberg.net;
10
116 include custom.d/tls/ssl_engine.conf;
127 include custom.d/tls/certificate_files.conf;
138 include custom.d/tls/policy_balanced.conf;
149 include custom.d/basic.conf;
15
1610 root /var/www/img/;
1711 autoindex on;
18
19 # ----------------------------------------------------------------------
20 # | Custom rules & config for specific website |
21 # ----------------------------------------------------------------------
22 location / {
23 try_files $uri $uri/ =404;
24 }
25 # ----------------------------------------------------------------------
26}
27
28# ----------------------------------------------------------------------
29# | Config file for non-secure host |
30# ----------------------------------------------------------------------
31server {
32 listen [::]:80;
33 listen 80;
34 server_name img.cleberg.net;
35
36 return 301 https://img.cleberg.net$request_uri;
12 location / { try_files $uri $uri/ =404; }
3713}
linux/nginx/etc/nginx/conf.d/irc.conf +4 −30
@@ -1,44 +1,18 @@
1# ----------------------------------------------------------------------
2# | Config file for host |
3# ----------------------------------------------------------------------
41server {
52 listen [::]:443 ssl;
63 listen 443 ssl;
74 http2 on;
8
95 server_name irc.cleberg.net;
10
116 include custom.d/tls/ssl_engine.conf;
127 include custom.d/tls/certificate_files.conf;
138 include custom.d/tls/policy_balanced.conf;
149 include custom.d/basic.conf;
15
16 # ----------------------------------------------------------------------
17 # | Custom rules & config for specific website |
18 # ----------------------------------------------------------------------
19 location /authelia {
20 include custom.d/reverse_proxy/authelia.conf;
21 }
22
10 location /authelia { include custom.d/reverse_proxy/authelia.conf; }
2311 location / {
24 set $upstream http://192.168.0.251:9900;
25 proxy_pass $upstream;
26
12 set $upstream http://192.168.0.251:9900;
13 proxy_pass $upstream;
2714 include custom.d/reverse_proxy/authelia_request.conf;
2815 include custom.d/reverse_proxy/basic.conf;
2916 }
30
31 include custom.d/security/robots_index_only.conf;
32 # ----------------------------------------------------------------------
33}
34
35# ----------------------------------------------------------------------
36# | Config file for non-secure host |
37# ----------------------------------------------------------------------
38server {
39 listen [::]:80;
40 listen 80;
41 server_name irc.cleberg.net;
42
43 return 301 https://$host$request_uri;
17 include custom.d/security/robots_index_only.conf;
4418}
linux/nginx/etc/nginx/conf.d/ld.conf +3 −26
@@ -1,39 +1,16 @@
1# ----------------------------------------------------------------------
2# | Config file for host |
3# ----------------------------------------------------------------------
41server {
52 listen [::]:443 ssl;
63 listen 443 ssl;
74 http2 on;
8
95 server_name ld.cleberg.net;
10
116 include custom.d/tls/ssl_engine.conf;
127 include custom.d/tls/certificate_files.conf;
138 include custom.d/tls/policy_balanced.conf;
149 include custom.d/basic.conf;
15
16 # ----------------------------------------------------------------------
17 # | Custom rules & config for specific website |
18 # ----------------------------------------------------------------------
1910 location / {
20 set $upstream http://127.0.0.1:3004;
21 proxy_pass $upstream;
22
11 set $upstream http://127.0.0.1:3004;
12 proxy_pass $upstream;
2313 include custom.d/reverse_proxy/basic.conf;
2414 }
25
26 include custom.d/security/robots_index_only.conf;
27 # ----------------------------------------------------------------------
28}
29
30# ----------------------------------------------------------------------
31# | Config file for non-secure host |
32# ----------------------------------------------------------------------
33server {
34 listen [::]:80;
35 listen 80;
36 server_name ld.cleberg.net;
37
38 return 301 https://$host$request_uri;
15 include custom.d/security/robots_index_only.conf;
3916}
linux/nginx/etc/nginx/conf.d/lemmy.conf +3 −26
@@ -1,39 +1,16 @@
1# ----------------------------------------------------------------------
2# | Config file for host |
3# ----------------------------------------------------------------------
41server {
52 listen [::]:443 ssl;
63 listen 443 ssl;
74 http2 on;
8
95 server_name lemmy.cleberg.net;
10
116 include custom.d/tls/ssl_engine.conf;
127 include custom.d/tls/certificate_files.conf;
138 include custom.d/tls/policy_balanced.conf;
149 include custom.d/basic.conf;
15
16 # ----------------------------------------------------------------------
17 # | Custom rules & config for specific website |
18 # ----------------------------------------------------------------------
1910 location / {
20 set $upstream http://127.0.0.1:10633;
21 proxy_pass $upstream;
22
11 set $upstream http://127.0.0.1:10633;
12 proxy_pass $upstream;
2313 include custom.d/reverse_proxy/basic.conf;
2414 }
25
26 include custom.d/security/robots_index_only.conf;
27 # ----------------------------------------------------------------------
28}
29
30# ----------------------------------------------------------------------
31# | Config file for non-secure host |
32# ----------------------------------------------------------------------
33server {
34 listen [::]:80;
35 listen 80;
36 server_name lemmy.cleberg.net;
37
38 return 301 https://$host$request_uri;
15 include custom.d/security/robots_index_only.conf;
3916}
linux/nginx/etc/nginx/conf.d/lt.conf +4 −27
@@ -1,39 +1,16 @@
1# ----------------------------------------------------------------------
2# | Config file for host |
3# ----------------------------------------------------------------------
41server {
52 listen [::]:443 ssl;
63 listen 443 ssl;
74 http2 on;
8
95 server_name lt.cleberg.net;
10
116 include custom.d/tls/ssl_engine.conf;
127 include custom.d/tls/certificate_files.conf;
138 include custom.d/tls/policy_balanced.conf;
149 include custom.d/basic.conf;
15
16 # ----------------------------------------------------------------------
17 # | Custom rules & config for specific website |
18 # ----------------------------------------------------------------------
1910 location / {
20 set $upstream http://127.0.0.1:5000;
21 proxy_pass $upstream;
22
11 set $upstream http://127.0.0.1:5000;
12 proxy_pass $upstream;
2313 include custom.d/reverse_proxy/basic.conf;
2414 }
25
26 include custom.d/security/robots_index_only.conf;
27 # ----------------------------------------------------------------------
28}
29
30# ----------------------------------------------------------------------
31# | Config file for non-secure host |
32# ----------------------------------------------------------------------
33server {
34 listen [::]:80;
35 listen 80;
36 server_name lt.cleberg.net;
37
38 return 301 https://$host$request_uri;
39}
15 include custom.d/security/robots_index_only.conf;
16}
\ No newline at end of file
linux/nginx/etc/nginx/conf.d/mz.conf +4 −27
@@ -1,39 +1,16 @@
1# ----------------------------------------------------------------------
2# | Config file for host |
3# ----------------------------------------------------------------------
41server {
52 listen [::]:443 ssl;
63 listen 443 ssl;
74 http2 on;
8
95 server_name mz.cleberg.net;
10
116 include custom.d/tls/ssl_engine.conf;
127 include custom.d/tls/certificate_files.conf;
138 include custom.d/tls/policy_balanced.conf;
149 include custom.d/basic.conf;
15
16 # ----------------------------------------------------------------------
17 # | Custom rules & config for specific website |
18 # ----------------------------------------------------------------------
1910 location / {
20 set $upstream http://127.0.0.1:3474;
21 proxy_pass $upstream;
22
11 set $upstream http://127.0.0.1:3474;
12 proxy_pass $upstream;
2313 include custom.d/reverse_proxy/basic.conf;
2414 }
25
26 include custom.d/security/robots_index_only.conf;
27 # ----------------------------------------------------------------------
28}
29
30# ----------------------------------------------------------------------
31# | Config file for non-secure host |
32# ----------------------------------------------------------------------
33server {
34 listen [::]:80;
35 listen 80;
36 server_name mz.cleberg.net;
37
38 return 301 https://$host$request_uri;
39}
15 include custom.d/security/robots_index_only.conf;
16}
\ No newline at end of file
linux/nginx/etc/nginx/conf.d/no-ssl.default.conf +4 −25
@@ -1,27 +1,6 @@
1# ----------------------------------------------------------------------
2# | Default behavior for unknown hosts |
3# ----------------------------------------------------------------------
4#
5# Drop requests for unknown hosts.
6#
7# If no default server is defined, Nginx will use the first found server.
8# To prevent host header attacks, or other potential problems when an unknown
9# server name is used in a request, it's recommended to drop the request
10# returning 444 "No Response".
11#
12# (1) In production, only secure hosts should be used (all `no-ssl` disabled).
13# If so, redirect first ANY request to a secure connection before handling
14# it, even if the host is unknown.
15#
16# https://observatory.mozilla.org/faq/
17
181server {
19 listen [::]:80 default_server deferred;
20 listen 80 default_server deferred;
21
22 server_name _;
23
24 # (1)
25 return 301 https://$host$request_uri;
26 # return 444;
2 listen [::]:80 default_server deferred;
3 listen 80 default_server deferred;
4 server_name _;
5 return 301 https://$host$request_uri;
276}
linux/nginx/etc/nginx/conf.d/office.conf +2 −25
@@ -1,35 +1,12 @@
1# ----------------------------------------------------------------------
2# | Config file for host |
3# ----------------------------------------------------------------------
41server {
52 listen [::]:443 ssl;
63 listen 443 ssl;
74 http2 on;
8
95 server_name office.cleberg.net;
106 root /var/www/office/;
11
127 include custom.d/tls/ssl_engine.conf;
138 include custom.d/tls/certificate_files.conf;
149 include custom.d/tls/policy_balanced.conf;
1510 include custom.d/basic.conf;
16
17 # ----------------------------------------------------------------------
18 # | Custom rules & config for specific website |
19 # ----------------------------------------------------------------------
20 location / {
21 try_files $uri $uri/ /index.html;
22 }
23 # ----------------------------------------------------------------------
24}
25
26# ----------------------------------------------------------------------
27# | Config file for non-secure host |
28# ----------------------------------------------------------------------
29server {
30 listen [::]:80;
31 listen 80;
32 server_name office.cleberg.net;
33
34 return 301 https://$host$request_uri;
35}
11 location / { try_files $uri $uri/ /index.html; }
12}
\ No newline at end of file
linux/nginx/etc/nginx/conf.d/org.conf +2 −25
@@ -1,35 +1,12 @@
1# ----------------------------------------------------------------------
2# | Config file for host |
3# ----------------------------------------------------------------------
41server {
52 listen [::]:443 ssl;
63 listen 443 ssl;
74 http2 on;
8
95 server_name org.cleberg.net;
106 root /var/www/org/;
11
127 include custom.d/tls/ssl_engine.conf;
138 include custom.d/tls/certificate_files.conf;
149 include custom.d/tls/policy_balanced.conf;
1510 include custom.d/basic.conf;
16
17 # ----------------------------------------------------------------------
18 # | Custom rules & config for specific website |
19 # ----------------------------------------------------------------------
20 location / {
21 try_files $uri $uri/ /index.html;
22 }
23 # ----------------------------------------------------------------------
24}
25
26# ----------------------------------------------------------------------
27# | Config file for non-secure host |
28# ----------------------------------------------------------------------
29server {
30 listen [::]:80;
31 listen 80;
32 server_name org.cleberg.net;
33
34 return 301 https://$host$request_uri;
35}
11 location / { try_files $uri $uri/ /index.html; }
12}
\ No newline at end of file
linux/nginx/etc/nginx/conf.d/paste.conf +4 −27
@@ -1,39 +1,16 @@
1# ----------------------------------------------------------------------
2# | Config file for host |
3# ----------------------------------------------------------------------
41server {
52 listen [::]:443 ssl;
63 listen 443 ssl;
74 http2 on;
8
95 server_name paste.cleberg.net;
10
116 include custom.d/tls/ssl_engine.conf;
127 include custom.d/tls/certificate_files.conf;
138 include custom.d/tls/policy_balanced.conf;
149 include custom.d/basic.conf;
15
16 # ----------------------------------------------------------------------
17 # | Custom rules & config for specific website |
18 # ----------------------------------------------------------------------
1910 location / {
20 set $upstream http://127.0.0.1:8084;
21 proxy_pass $upstream;
22
11 set $upstream http://127.0.0.1:8084;
12 proxy_pass $upstream;
2313 include custom.d/reverse_proxy/basic.conf;
2414 }
25
26 include custom.d/security/robots_index_only.conf;
27 # ----------------------------------------------------------------------
28}
29
30# ----------------------------------------------------------------------
31# | Config file for non-secure host |
32# ----------------------------------------------------------------------
33server {
34 listen [::]:80;
35 listen 80;
36 server_name paste.cleberg.net;
37
38 return 301 https://$host$request_uri;
39}
15 include custom.d/security/robots_index_only.conf;
16}
\ No newline at end of file
linux/nginx/etc/nginx/conf.d/pb.conf +3 −27
@@ -1,39 +1,15 @@
1# ----------------------------------------------------------------------
2# | Config file for host |
3# ----------------------------------------------------------------------
41server {
52 listen [::]:443 ssl;
63 listen 443 ssl;
74 http2 on;
8
95 server_name pb.cleberg.net;
10
116 include custom.d/tls/ssl_engine.conf;
127 include custom.d/tls/certificate_files.conf;
138 include custom.d/tls/policy_balanced.conf;
149 include custom.d/basic.conf;
15
16 # ----------------------------------------------------------------------
17 # | Custom rules & config for specific website |
18 # ----------------------------------------------------------------------
1910 location / {
20 set $upstream http://127.0.0.1:8745;
21 proxy_pass $upstream;
22
11 set $upstream http://127.0.0.1:8745;
12 proxy_pass $upstream;
2313 include custom.d/reverse_proxy/basic.conf;
2414 }
25
26 # include custom.d/security/robots_index_only.conf;
27 # ----------------------------------------------------------------------
28}
29
30# ----------------------------------------------------------------------
31# | Config file for non-secure host |
32# ----------------------------------------------------------------------
33server {
34 listen [::]:80;
35 listen 80;
36 server_name pb.cleberg.net;
37
38 return 301 https://$host$request_uri;
39}
15}
\ No newline at end of file
linux/nginx/etc/nginx/conf.d/pgp.conf +2 −26
@@ -1,37 +1,13 @@
1# ----------------------------------------------------------------------
2# | Config file for host |
3# ----------------------------------------------------------------------
41server {
52 listen [::]:443 ssl;
63 listen 443 ssl;
74 http2 on;
8
95 server_name pgp.cleberg.net;
106 root /var/www/pgp/;
11
127 include custom.d/tls/ssl_engine.conf;
138 include custom.d/tls/certificate_files.conf;
149 include custom.d/tls/policy_balanced.conf;
1510 include custom.d/basic.conf;
16
17 # ----------------------------------------------------------------------
18 # | Custom rules & config for specific website |
19 # ----------------------------------------------------------------------
20 location / {
21 try_files $uri $uri/ /index.html;
22 }
23
24 include custom.d/security/robots_index_only.conf;
25 # ----------------------------------------------------------------------
26}
27
28# ----------------------------------------------------------------------
29# | Config file for non-secure host |
30# ----------------------------------------------------------------------
31server {
32 listen [::]:80;
33 listen 80;
34 server_name pgp.cleberg.net;
35
36 return 301 https://$host$request_uri;
11 location / { try_files $uri $uri/ /index.html; }
12 include custom.d/security/robots_index_only.conf;
3713}
linux/nginx/etc/nginx/conf.d/photos.conf +2 −33
@@ -1,54 +1,23 @@
1# ----------------------------------------------------------------------
2# | Config file for host |
3# ----------------------------------------------------------------------
41server {
52 listen [::]:443 ssl;
63 listen 443 ssl;
74 http2 on;
8
95 server_name photos.cleberg.net;
10
116 include custom.d/tls/ssl_engine.conf;
127 include custom.d/tls/certificate_files.conf;
138 include custom.d/tls/policy_balanced.conf;
149 include custom.d/basic.conf;
15
16 # ----------------------------------------------------------------------
17 # | Custom rules & config for specific website |
18 # ----------------------------------------------------------------------
19 # allow large file uploads
2010 client_max_body_size 50000M;
21
22 # Set headers
2311 proxy_set_header Host $host;
2412 proxy_set_header X-Real-IP $remote_addr;
2513 proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
2614 proxy_set_header X-Forwarded-Proto $scheme;
27
28 # enable websockets: http://nginx.org/en/docs/http/websocket.html
2915 proxy_http_version 1.1;
3016 proxy_set_header Upgrade $http_upgrade;
3117 proxy_set_header Connection "upgrade";
3218 proxy_redirect off;
33
34 # set timeout
3519 proxy_read_timeout 600s;
3620 proxy_send_timeout 600s;
3721 send_timeout 600s;
38
39 location / {
40 proxy_pass http://127.0.0.1:2283;
41 }
42 # ----------------------------------------------------------------------
43}
44
45# ----------------------------------------------------------------------
46# | Config file for non-secure host |
47# ----------------------------------------------------------------------
48server {
49 listen [::]:80;
50 listen 80;
51 server_name photos.cleberg.net;
52
53 return 301 https://$host$request_uri;
54}
22 location / { proxy_pass http://127.0.0.1:2283; }
23}
\ No newline at end of file
linux/nginx/etc/nginx/conf.d/pin.conf +3 −26
@@ -1,39 +1,16 @@
1# ----------------------------------------------------------------------
2# | Config file for host |
3# ----------------------------------------------------------------------
41server {
52 listen [::]:443 ssl;
63 listen 443 ssl;
74 http2 on;
8
95 server_name pin.cleberg.net;
10
116 include custom.d/tls/ssl_engine.conf;
127 include custom.d/tls/certificate_files.conf;
138 include custom.d/tls/policy_balanced.conf;
149 include custom.d/basic.conf;
15
16 # ----------------------------------------------------------------------
17 # | Custom rules & config for specific website |
18 # ----------------------------------------------------------------------
1910 location / {
20 set $upstream http://127.0.0.1:8086;
21 proxy_pass $upstream;
22
11 set $upstream http://127.0.0.1:8086;
12 proxy_pass $upstream;
2313 include custom.d/reverse_proxy/basic.conf;
2414 }
25
26 include custom.d/security/robots_index_only.conf;
27 # ----------------------------------------------------------------------
28}
29
30# ----------------------------------------------------------------------
31# | Config file for non-secure host |
32# ----------------------------------------------------------------------
33server {
34 listen [::]:80;
35 listen 80;
36 server_name pin.cleberg.net;
37
38 return 301 https://$host$request_uri;
15 include custom.d/security/robots_index_only.conf;
3916}
linux/nginx/etc/nginx/conf.d/piped.conf +4 −28
@@ -1,40 +1,16 @@
1# ----------------------------------------------------------------------
2# | Config file for host |
3# ----------------------------------------------------------------------
41server {
52 listen [::]:443 ssl;
63 listen 443 ssl;
74 http2 on;
8
95 server_name piped.cleberg.net pipedapi.cleberg.net pipedproxy.cleberg.net;
10
116 include custom.d/tls/ssl_engine.conf;
127 include custom.d/tls/certificate_files.conf;
138 include custom.d/tls/policy_balanced.conf;
149 include custom.d/basic.conf;
15
16 # ----------------------------------------------------------------------
17 # | Custom rules & config for specific website |
18 # ----------------------------------------------------------------------
1910 location / {
20 set $upstream http://127.0.0.1:8077;
21 proxy_pass $upstream;
22
11 set $upstream http://127.0.0.1:8077;
12 proxy_pass $upstream;
2313 proxy_set_header Host $host;
24 # include custom.d/reverse_proxy/basic.conf;
2514 }
26
27 include custom.d/security/robots_index_only.conf;
28 # ----------------------------------------------------------------------
29}
30
31# ----------------------------------------------------------------------
32# | Config file for non-secure host |
33# ----------------------------------------------------------------------
34server {
35 listen [::]:80;
36 listen 80;
37 server_name piped.cleberg.net pipedapi.cleberg.net pipedproxy.cleberg.net;
38
39 return 301 https://$host$request_uri;
40}
15 include custom.d/security/robots_index_only.conf;
16}
\ No newline at end of file
linux/nginx/etc/nginx/conf.d/projects.conf +1 −24
@@ -1,36 +1,13 @@
1# ----------------------------------------------------------------------
2# | Config file for host |
3# ----------------------------------------------------------------------
41server {
52 listen [::]:443 ssl;
63 listen 443 ssl;
74 http2 on;
8
95 server_name projects.cleberg.net;
106 root /var/www/projects/;
117 autoindex on;
12
138 include custom.d/tls/ssl_engine.conf;
149 include custom.d/tls/certificate_files.conf;
1510 include custom.d/tls/policy_balanced.conf;
1611 include custom.d/basic.conf;
17
18 # ----------------------------------------------------------------------
19 # | Custom rules & config for specific website |
20 # ----------------------------------------------------------------------
21 location / {
22 try_files $uri $uri/ /index.html;
23 }
24 # ----------------------------------------------------------------------
25}
26
27# ----------------------------------------------------------------------
28# | Config file for non-secure host |
29# ----------------------------------------------------------------------
30server {
31 listen [::]:80;
32 listen 80;
33 server_name projects.cleberg.net;
34
35 return 301 https://$host$request_uri;
12 location / { try_files $uri $uri/ /index.html; }
3613}
linux/nginx/etc/nginx/conf.d/rd.conf +4 −27
@@ -1,39 +1,16 @@
1# ----------------------------------------------------------------------
2# | Config file for host |
3# ----------------------------------------------------------------------
41server {
52 listen [::]:443 ssl;
63 listen 443 ssl;
74 http2 on;
8
95 server_name rd.cleberg.net;
10
116 include custom.d/tls/ssl_engine.conf;
127 include custom.d/tls/certificate_files.conf;
138 include custom.d/tls/policy_balanced.conf;
149 include custom.d/basic.conf;
15
16 # ----------------------------------------------------------------------
17 # | Custom rules & config for specific website |
18 # ----------------------------------------------------------------------
1910 location / {
20 set $upstream http://127.0.0.1:5758;
21 proxy_pass $upstream;
22
11 set $upstream http://127.0.0.1:5758;
12 proxy_pass $upstream;
2313 include custom.d/reverse_proxy/basic.conf;
2414 }
25
26 include custom.d/security/robots_index_only.conf;
27 # ----------------------------------------------------------------------
28}
29
30# ----------------------------------------------------------------------
31# | Config file for non-secure host |
32# ----------------------------------------------------------------------
33server {
34 listen [::]:80;
35 listen 80;
36 server_name rd.cleberg.net;
37
38 return 301 https://$host$request_uri;
39}
15 include custom.d/security/robots_index_only.conf;
16}
\ No newline at end of file
linux/nginx/etc/nginx/conf.d/reminiscecleberg.com.conf +1 −22
@@ -1,20 +1,13 @@
1# ----------------------------------------------------------------------
2# | Config file for host |
3# ----------------------------------------------------------------------
41server {
52 listen [::]:443 ssl;
63 listen 443 ssl;
74 http2 on;
8
95 server_name www.reminiscecleberg.com;
10
116 include custom.d/tls/ssl_engine.conf;
127 include custom.d/tls/policy_balanced.conf;
13 # include custom.d/tls/certificate_files.conf;
148 ssl_certificate /etc/letsencrypt/live/reminiscecleberg.com/fullchain.pem;
159 ssl_certificate_key /etc/letsencrypt/live/reminiscecleberg.com/privkey.pem;
1610 ssl_trusted_certificate /etc/letsencrypt/live/reminiscecleberg.com/chain.pem;
17
1811 return 301 $scheme://reminiscecleberg.com$request_uri;
1912}
2013
@@ -23,34 +16,20 @@ server {
2316 listen [::]:443 ssl;
2417 listen 443 ssl;
2518 http2 on;
26
2719 server_name reminiscecleberg.com;
2820 root /var/www/reminiscecleberg.com/;
29
3021 include custom.d/tls/ssl_engine.conf;
3122 include custom.d/tls/policy_balanced.conf;
3223 include custom.d/basic.conf;
33 # include custom.d/tls/certificate_files.conf;
3424 ssl_certificate /etc/letsencrypt/live/reminiscecleberg.com/fullchain.pem;
3525 ssl_certificate_key /etc/letsencrypt/live/reminiscecleberg.com/privkey.pem;
3626 ssl_trusted_certificate /etc/letsencrypt/live/reminiscecleberg.com/chain.pem;
37
38 # ----------------------------------------------------------------------
39 # | Custom rules & config for specific website |
40 # ----------------------------------------------------------------------
41 location / {
42 try_files $uri $uri/ =404;
43 }
44 # ----------------------------------------------------------------------
27 location / { try_files $uri $uri/ =404; }
4528}
4629
47# ----------------------------------------------------------------------
48# | Config file for non-secure host |
49# ----------------------------------------------------------------------
5030server {
5131 listen [::]:80;
5232 listen 80;
5333 server_name www.reminiscecleberg.com reminiscecleberg.com;
54
5534 return 301 https://reminiscecleberg.com$request_uri;
5635}
linux/nginx/etc/nginx/conf.d/rimgo.conf +3 −26
@@ -1,39 +1,16 @@
1# ----------------------------------------------------------------------
2# | Config file for host |
3# ----------------------------------------------------------------------
41server {
52 listen [::]:443 ssl;
63 listen 443 ssl;
74 http2 on;
8
95 server_name rimgo.cleberg.net;
10
116 include custom.d/tls/ssl_engine.conf;
127 include custom.d/tls/certificate_files.conf;
138 include custom.d/tls/policy_balanced.conf;
149 include custom.d/basic.conf;
15
16 # ----------------------------------------------------------------------
17 # | Custom rules & config for specific website |
18 # ----------------------------------------------------------------------
1910 location / {
20 set $upstream http://127.0.0.1:3869;
21 proxy_pass $upstream;
22
11 set $upstream http://127.0.0.1:3869;
12 proxy_pass $upstream;
2313 include custom.d/reverse_proxy/basic.conf;
2414 }
25
26 include custom.d/security/robots_index_only.conf;
27 # ----------------------------------------------------------------------
28}
29
30# ----------------------------------------------------------------------
31# | Config file for non-secure host |
32# ----------------------------------------------------------------------
33server {
34 listen [::]:80;
35 listen 80;
36 server_name rimgo.cleberg.net;
37
38 return 301 https://$host$request_uri;
15 include custom.d/security/robots_index_only.conf;
3916}
linux/nginx/etc/nginx/conf.d/rl.conf +4 −30
@@ -1,44 +1,18 @@
1# ----------------------------------------------------------------------
2# | Config file for host |
3# ----------------------------------------------------------------------
41server {
52 listen [::]:443 ssl;
63 listen 443 ssl;
74 http2 on;
8
95 server_name rl.cleberg.net;
10
116 include custom.d/tls/ssl_engine.conf;
127 include custom.d/tls/certificate_files.conf;
138 include custom.d/tls/policy_balanced.conf;
149 include custom.d/basic.conf;
15
16 # ----------------------------------------------------------------------
17 # | Custom rules & config for specific website |
18 # ----------------------------------------------------------------------
19 location /authelia {
20 include custom.d/reverse_proxy/authelia.conf;
21 }
22
10 location /authelia { include custom.d/reverse_proxy/authelia.conf; }
2311 location / {
24 set $upstream http://192.168.0.251:8983;
25 proxy_pass $upstream;
26
12 set $upstream http://192.168.0.251:8983;
13 proxy_pass $upstream;
2714 include custom.d/reverse_proxy/authelia_request.conf;
2815 include custom.d/reverse_proxy/basic.conf;
2916 }
30
31 include custom.d/security/robots_index_only.conf;
32 # ----------------------------------------------------------------------
33}
34
35# ----------------------------------------------------------------------
36# | Config file for non-secure host |
37# ----------------------------------------------------------------------
38server {
39 listen [::]:80;
40 listen 80;
41 server_name rl.cleberg.net;
42
43 return 301 https://$host$request_uri;
17 include custom.d/security/robots_index_only.conf;
4418}
linux/nginx/etc/nginx/conf.d/rss.conf +4 −35
@@ -1,31 +1,15 @@
1# ----------------------------------------------------------------------
2# | Config file for host |
3# ----------------------------------------------------------------------
4upstream freshrss {
5 server 192.168.0.251:8081;
6 keepalive 64;
7}
8
1upstream freshrss { server 192.168.0.251:8081; keepalive 64; }
92server {
103 listen [::]:443 ssl;
114 listen 443 ssl;
125 http2 on;
13
146 server_name rss.cleberg.net;
15
167 include custom.d/tls/ssl_engine.conf;
178 include custom.d/tls/certificate_files.conf;
189 include custom.d/tls/policy_balanced.conf;
1910 include custom.d/basic.conf;
20
21 # ----------------------------------------------------------------------
22 # | Custom rules & config for specific website |
23 # ----------------------------------------------------------------------
2411 location / {
25 proxy_pass http://freshrss/;
26
27 # include custom.d/reverse_proxy/basic.conf;
28
12 proxy_pass http://freshrss/;
2913 add_header X-Frame-Options SAMEORIGIN;
3014 add_header X-XSS-Protection "1; mode=block";
3115 proxy_redirect off;
@@ -36,23 +20,8 @@ server {
3620 proxy_set_header X-Forwarded-Proto $scheme;
3721 proxy_set_header X-Forwarded-Port $server_port;
3822 proxy_read_timeout 90;
39
40 # Forward the Authorization header for the Google Reader API.
4123 proxy_set_header Authorization $http_authorization;
4224 proxy_pass_header Authorization;
4325 }
44
45 include custom.d/security/robots_index_only.conf;
46 # ----------------------------------------------------------------------
47}
48
49# ----------------------------------------------------------------------
50# | Config file for non-secure host |
51# ----------------------------------------------------------------------
52server {
53 listen [::]:80;
54 listen 80;
55 server_name rss.cleberg.net;
56
57 return 301 https://$host$request_uri;
58}
26 include custom.d/security/robots_index_only.conf;
27}
\ No newline at end of file
linux/nginx/etc/nginx/conf.d/search.conf +3 −27
@@ -1,44 +1,20 @@
1# ----------------------------------------------------------------------
2# | Config file for host |
3# ----------------------------------------------------------------------
41server {
52 listen [::]:443 ssl;
63 listen 443 ssl;
74 http2 on;
8
95 server_name search.cleberg.net;
10
116 include custom.d/tls/ssl_engine.conf;
127 include custom.d/tls/certificate_files.conf;
138 include custom.d/tls/policy_balanced.conf;
149 include custom.d/basic.conf;
15
16 # ----------------------------------------------------------------------
17 # | Custom rules & config for specific website |
18 # ----------------------------------------------------------------------
1910 location / {
20 set $upstream http://127.0.0.1:9191;
21 proxy_pass $upstream;
22
23 # include custom.d/reverse_proxy/basic.conf;
11 set $upstream http://127.0.0.1:9191;
12 proxy_pass $upstream;
2413 proxy_set_header Host $host;
2514 proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
2615 proxy_set_header Upgrade $http_upgrade;
2716 proxy_set_header Connection "upgrade";
2817 proxy_http_version 1.1;
2918 }
30
31 include custom.d/security/robots_index_only.conf;
32 # ----------------------------------------------------------------------
33}
34
35# ----------------------------------------------------------------------
36# | Config file for non-secure host |
37# ----------------------------------------------------------------------
38server {
39 listen [::]:80;
40 listen 80;
41 server_name search.cleberg.net;
42
43 return 301 https://$host$request_uri;
19 include custom.d/security/robots_index_only.conf;
4420}
linux/nginx/etc/nginx/conf.d/send.conf +3 −26
@@ -1,39 +1,16 @@
1# ----------------------------------------------------------------------
2# | Config file for host |
3# ----------------------------------------------------------------------
41server {
52 listen [::]:443 ssl;
63 listen 443 ssl;
74 http2 on;
8
95 server_name send.cleberg.net;
10
116 include custom.d/tls/ssl_engine.conf;
127 include custom.d/tls/certificate_files.conf;
138 include custom.d/tls/policy_balanced.conf;
149 include custom.d/basic.conf;
15
16 # ----------------------------------------------------------------------
17 # | Custom rules & config for specific website |
18 # ----------------------------------------------------------------------
1910 location / {
20 set $upstream http://192.168.0.251:1443;
21 proxy_pass $upstream;
22
11 set $upstream http://192.168.0.251:1443;
12 proxy_pass $upstream;
2313 include custom.d/reverse_proxy/basic.conf;
2414 }
25
26 include custom.d/security/robots_index_only.conf;
27 # ----------------------------------------------------------------------
28}
29
30# ----------------------------------------------------------------------
31# | Config file for non-secure host |
32# ----------------------------------------------------------------------
33server {
34 listen [::]:80;
35 listen 80;
36 server_name send.cleberg.net;
37
38 return 301 https://$host$request_uri;
15 include custom.d/security/robots_index_only.conf;
3916}
linux/nginx/etc/nginx/conf.d/slash.conf +4 −27
@@ -1,39 +1,16 @@
1# ----------------------------------------------------------------------
2# | Config file for host |
3# ----------------------------------------------------------------------
41server {
52 listen [::]:443 ssl;
63 listen 443 ssl;
74 http2 on;
8
95 server_name slash.cleberg.net;
10
116 include custom.d/tls/ssl_engine.conf;
127 include custom.d/tls/certificate_files.conf;
138 include custom.d/tls/policy_balanced.conf;
149 include custom.d/basic.conf;
15
16 # ----------------------------------------------------------------------
17 # | Custom rules & config for specific website |
18 # ----------------------------------------------------------------------
1910 location / {
20 set $upstream http://192.168.0.251:5231;
21 proxy_pass $upstream;
22
11 set $upstream http://192.168.0.251:5231;
12 proxy_pass $upstream;
2313 include custom.d/reverse_proxy/basic.conf;
2414 }
25
26 include custom.d/security/robots_index_only.conf;
27 # ----------------------------------------------------------------------
28}
29
30# ----------------------------------------------------------------------
31# | Config file for non-secure host |
32# ----------------------------------------------------------------------
33server {
34 listen [::]:80;
35 listen 80;
36 server_name slash.cleberg.net;
37
38 return 301 https://$host$request_uri;
39}
15 include custom.d/security/robots_index_only.conf;
16}
\ No newline at end of file
linux/nginx/etc/nginx/conf.d/small.conf +4 −27
@@ -1,39 +1,16 @@
1# ----------------------------------------------------------------------
2# | Config file for host |
3# ----------------------------------------------------------------------
41server {
52 listen [::]:443 ssl;
63 listen 443 ssl;
74 http2 on;
8
95 server_name small.cleberg.net;
10
116 include custom.d/tls/ssl_engine.conf;
127 include custom.d/tls/certificate_files.conf;
138 include custom.d/tls/policy_balanced.conf;
149 include custom.d/basic.conf;
15
16 # ----------------------------------------------------------------------
17 # | Custom rules & config for specific website |
18 # ----------------------------------------------------------------------
1910 location / {
20 set $upstream http://127.0.0.1:8002;
21 proxy_pass $upstream;
22
11 set $upstream http://127.0.0.1:8002;
12 proxy_pass $upstream;
2313 include custom.d/reverse_proxy/basic.conf;
2414 }
25
26 include custom.d/security/robots_index_only.conf;
27 # ----------------------------------------------------------------------
28}
29
30# ----------------------------------------------------------------------
31# | Config file for non-secure host |
32# ----------------------------------------------------------------------
33server {
34 listen [::]:80;
35 listen 80;
36 server_name small.cleberg.net;
37
38 return 301 https://$host$request_uri;
39}
15 include custom.d/security/robots_index_only.conf;
16}
\ No newline at end of file
linux/nginx/etc/nginx/conf.d/ssh.conf +5 −31
@@ -1,44 +1,18 @@
1# ----------------------------------------------------------------------
2# | Config file for host |
3# ----------------------------------------------------------------------
41server {
52 listen [::]:443 ssl;
63 listen 443 ssl;
74 http2 on;
8
95 server_name ssh.cleberg.net;
10
116 include custom.d/tls/ssl_engine.conf;
127 include custom.d/tls/certificate_files.conf;
138 include custom.d/tls/policy_balanced.conf;
149 include custom.d/basic.conf;
15
16 # ----------------------------------------------------------------------
17 # | Custom rules & config for specific website |
18 # ----------------------------------------------------------------------
19 location /authelia {
20 include custom.d/reverse_proxy/authelia.conf;
21 }
22
10 location /authelia { include custom.d/reverse_proxy/authelia.conf; }
2311 location / {
24 set $upstream http://127.0.0.1:8169;
25 proxy_pass $upstream;
26
12 set $upstream http://127.0.0.1:8169;
13 proxy_pass $upstream;
2714 include custom.d/reverse_proxy/authelia_request.conf;
2815 include custom.d/reverse_proxy/basic.conf;
2916 }
30
31 include custom.d/security/robots_index_only.conf;
32 # ----------------------------------------------------------------------
33}
34
35# ----------------------------------------------------------------------
36# | Config file for non-secure host |
37# ----------------------------------------------------------------------
38server {
39 listen [::]:80;
40 listen 80;
41 server_name ssh.cleberg.net;
42
43 return 301 https://$host$request_uri;
44}
17 include custom.d/security/robots_index_only.conf;
18}
\ No newline at end of file
linux/nginx/etc/nginx/conf.d/teddit.conf +5 −31
@@ -1,44 +1,18 @@
1# ----------------------------------------------------------------------
2# | Config file for host |
3# ----------------------------------------------------------------------
41server {
52 listen [::]:443 ssl;
63 listen 443 ssl;
74 http2 on;
8
95 server_name teddit.cleberg.net;
10
116 include custom.d/tls/ssl_engine.conf;
127 include custom.d/tls/certificate_files.conf;
138 include custom.d/tls/policy_balanced.conf;
149 include custom.d/basic.conf;
15
16 # ----------------------------------------------------------------------
17 # | Custom rules & config for specific website |
18 # ----------------------------------------------------------------------
19 location /authelia {
20 include custom.d/reverse_proxy/authelia.conf;
21 }
22
10 location /authelia { include custom.d/reverse_proxy/authelia.conf; }
2311 location / {
24 set $upstream http://192.168.0.251:8181;
25 proxy_pass $upstream;
26
12 set $upstream http://192.168.0.251:8181;
13 proxy_pass $upstream;
2714 include custom.d/reverse_proxy/authelia_request.conf;
2815 include custom.d/reverse_proxy/basic.conf;
2916 }
30
31 include custom.d/security/robots_index_only.conf;
32 # ----------------------------------------------------------------------
33}
34
35# ----------------------------------------------------------------------
36# | Config file for non-secure host |
37# ----------------------------------------------------------------------
38server {
39 listen [::]:80;
40 listen 80;
41 server_name teddit.cleberg.net;
42
43 return 301 https://$host$request_uri;
44}
17 include custom.d/security/robots_index_only.conf;
18}
\ No newline at end of file
linux/nginx/etc/nginx/conf.d/wyl.conf +4 −30
@@ -1,44 +1,18 @@
1# ----------------------------------------------------------------------
2# | Config file for host |
3# ----------------------------------------------------------------------
41server {
52 listen [::]:443 ssl;
63 listen 443 ssl;
74 http2 on;
8
95 server_name wyl.cleberg.net;
10
116 include custom.d/tls/ssl_engine.conf;
127 include custom.d/tls/certificate_files.conf;
138 include custom.d/tls/policy_balanced.conf;
149 include custom.d/basic.conf;
15
16 # ----------------------------------------------------------------------
17 # | Custom rules & config for specific website |
18 # ----------------------------------------------------------------------
19 location /authelia {
20 include custom.d/reverse_proxy/authelia.conf;
21 }
22
10 location /authelia { include custom.d/reverse_proxy/authelia.conf; }
2311 location / {
24 set $upstream http://192.168.0.251:8840;
25 proxy_pass $upstream;
26
12 set $upstream http://192.168.0.251:8840;
13 proxy_pass $upstream;
2714 include custom.d/reverse_proxy/authelia_request.conf;
2815 include custom.d/reverse_proxy/basic.conf;
2916 }
30
31 include custom.d/security/robots_index_only.conf;
32 # ----------------------------------------------------------------------
33}
34
35# ----------------------------------------------------------------------
36# | Config file for non-secure host |
37# ----------------------------------------------------------------------
38server {
39 listen [::]:80;
40 listen 80;
41 server_name wyl.cleberg.net;
42
43 return 301 https://$host$request_uri;
17 include custom.d/security/robots_index_only.conf;
4418}