cmc/dotfiles

Using GNU Stow to manage my dotfiles. config dotfiles macos stow

Commit 7c3385ccef

7c3385ccef593943a3e6d0838ced4ce584466419

parent: 91f3649beb

Verified · cmc

cmc <hello@cleberg.net> · 2026-02-16 01:28 UTC

add nginx and gpg

Layout: unified · split

common/gnupg/.gnupg/gpg-agent.conf added +2
@@ -0,0 +1,2 @@
1pinentry-program /usr/bin/pinentry-curses
2allow-loopback-pinentry
linux/nginx/etc/nginx/conf.d/ao.conf added +39
@@ -0,0 +1,39 @@
1# ----------------------------------------------------------------------
2# | Config file for host |
3# ----------------------------------------------------------------------
4server {
5 listen [::]:443 ssl;
6 listen 443 ssl;
7 http2 on;
8
9 server_name ao.cleberg.net;
10
11 include custom.d/tls/ssl_engine.conf;
12 include custom.d/tls/certificate_files.conf;
13 include custom.d/tls/policy_balanced.conf;
14 include custom.d/basic.conf;
15
16 # ----------------------------------------------------------------------
17 # | Custom rules & config for specific website |
18 # ----------------------------------------------------------------------
19 location / {
20 set $upstream http://127.0.0.1:9380;
21 proxy_pass $upstream;
22
23 include custom.d/reverse_proxy/basic.conf;
24 }
25
26 include custom.d/security/robots_index_only.conf;
27 # ----------------------------------------------------------------------
28}
29
30# ----------------------------------------------------------------------
31# | Config file for non-secure host |
32# ----------------------------------------------------------------------
33server {
34 listen [::]:80;
35 listen 80;
36 server_name ao.cleberg.net;
37
38 return 301 https://$host$request_uri;
39}
linux/nginx/etc/nginx/conf.d/art.conf added +39
@@ -0,0 +1,39 @@
1# ----------------------------------------------------------------------
2# | Config file for host |
3# ----------------------------------------------------------------------
4server {
5 listen [::]:443 ssl;
6 listen 443 ssl;
7 http2 on;
8
9 server_name art.cleberg.net;
10
11 include custom.d/tls/ssl_engine.conf;
12 include custom.d/tls/certificate_files.conf;
13 include custom.d/tls/policy_balanced.conf;
14 include custom.d/basic.conf;
15
16 # ----------------------------------------------------------------------
17 # | Custom rules & config for specific website |
18 # ----------------------------------------------------------------------
19 location / {
20 set $upstream http://127.0.0.1:3003;
21 proxy_pass $upstream;
22
23 include custom.d/reverse_proxy/basic.conf;
24 }
25
26 include custom.d/security/robots_index_only.conf;
27 # ----------------------------------------------------------------------
28}
29
30# ----------------------------------------------------------------------
31# | Config file for non-secure host |
32# ----------------------------------------------------------------------
33server {
34 listen [::]:80;
35 listen 80;
36 server_name art.cleberg.net;
37
38 return 301 https://$host$request_uri;
39}
linux/nginx/etc/nginx/conf.d/auth.conf added +42
@@ -0,0 +1,42 @@
1# ----------------------------------------------------------------------
2# | Config file for host |
3# ----------------------------------------------------------------------
4server {
5 listen [::]:443 ssl;
6 listen 443 ssl;
7 http2 on;
8
9 server_name auth.cleberg.net;
10
11 include custom.d/tls/ssl_engine.conf;
12 include custom.d/tls/certificate_files.conf;
13 include custom.d/tls/policy_balanced.conf;
14 include custom.d/basic.conf;
15
16 # ----------------------------------------------------------------------
17 # | Custom rules & config for specific website |
18 # ----------------------------------------------------------------------
19 set $upstream http://127.0.0.1:9092;
20
21 location / {
22 proxy_pass $upstream;
23
24 include custom.d/reverse_proxy/basic.conf;
25 }
26
27 location /api/verify {
28 proxy_pass $upstream;
29 }
30 # ----------------------------------------------------------------------
31}
32
33# ----------------------------------------------------------------------
34# | Config file for non-secure host |
35# ----------------------------------------------------------------------
36server {
37 listen [::]:80;
38 listen 80;
39 server_name auth.cleberg.net;
40
41 return 301 https://$host$request_uri;
42}
linux/nginx/etc/nginx/conf.d/br.conf added +39
@@ -0,0 +1,39 @@
1# ----------------------------------------------------------------------
2# | Config file for host |
3# ----------------------------------------------------------------------
4server {
5 listen [::]:443 ssl;
6 listen 443 ssl;
7 http2 on;
8
9 server_name br.cleberg.net;
10
11 include custom.d/tls/ssl_engine.conf;
12 include custom.d/tls/certificate_files.conf;
13 include custom.d/tls/policy_balanced.conf;
14 include custom.d/basic.conf;
15
16 # ----------------------------------------------------------------------
17 # | Custom rules & config for specific website |
18 # ----------------------------------------------------------------------
19 location / {
20 set $upstream http://127.0.0.1:3030;
21 proxy_pass $upstream;
22
23 include custom.d/reverse_proxy/basic.conf;
24 }
25
26 include custom.d/security/robots_index_only.conf;
27 # ----------------------------------------------------------------------
28}
29
30# ----------------------------------------------------------------------
31# | Config file for non-secure host |
32# ----------------------------------------------------------------------
33server {
34 listen [::]:80;
35 listen 80;
36 server_name br.cleberg.net;
37
38 return 301 https://$host$request_uri;
39}
linux/nginx/etc/nginx/conf.d/bt.conf added +46
@@ -0,0 +1,46 @@
1# ----------------------------------------------------------------------
2# | Config file for host |
3# ----------------------------------------------------------------------
4server {
5 listen [::]:443 ssl;
6 listen 443 ssl;
7 http2 on;
8
9 server_name bt.cleberg.net;
10
11 include custom.d/tls/ssl_engine.conf;
12 include custom.d/tls/certificate_files.conf;
13 include custom.d/tls/policy_balanced.conf;
14 include custom.d/basic.conf;
15
16 # ----------------------------------------------------------------------
17 # | Custom rules & config for specific website |
18 # ----------------------------------------------------------------------
19 set $upstream http://127.0.0.1:9091;
20
21 location /authelia {
22 include custom.d/reverse_proxy/authelia.conf;
23 }
24
25 location / {
26 proxy_pass $upstream;
27
28 include custom.d/reverse_proxy/authelia_request.conf;
29 # include custom.d/reverse_proxy/basic.conf;
30 proxy_pass_header X-bt-Session-Id;
31 }
32
33 include custom.d/security/robots_index_only.conf;
34 # ----------------------------------------------------------------------
35}
36
37# ----------------------------------------------------------------------
38# | Config file for non-secure host |
39# ----------------------------------------------------------------------
40server {
41 listen [::]:80;
42 listen 80;
43 server_name bt.cleberg.net;
44
45 return 301 https://$host$request_uri;
46}
linux/nginx/etc/nginx/conf.d/bw.conf added +39
@@ -0,0 +1,39 @@
1# ----------------------------------------------------------------------
2# | Config file for host |
3# ----------------------------------------------------------------------
4server {
5 listen [::]:443 ssl;
6 listen 443 ssl;
7 http2 on;
8
9 server_name bw.cleberg.net;
10
11 include custom.d/tls/ssl_engine.conf;
12 include custom.d/tls/certificate_files.conf;
13 include custom.d/tls/policy_balanced.conf;
14 include custom.d/basic.conf;
15
16 # ----------------------------------------------------------------------
17 # | Custom rules & config for specific website |
18 # ----------------------------------------------------------------------
19 location / {
20 set $upstream http://127.0.0.1:10416;
21 proxy_pass $upstream;
22
23 include custom.d/reverse_proxy/basic.conf;
24 }
25
26 include custom.d/security/robots_index_only.conf;
27 # ----------------------------------------------------------------------
28}
29
30# ----------------------------------------------------------------------
31# | Config file for non-secure host |
32# ----------------------------------------------------------------------
33server {
34 listen [::]:80;
35 listen 80;
36 server_name bw.cleberg.net;
37
38 return 301 https://$host$request_uri;
39}
linux/nginx/etc/nginx/conf.d/cc.conf added +39
@@ -0,0 +1,39 @@
1# ----------------------------------------------------------------------
2# | Config file for host |
3# ----------------------------------------------------------------------
4server {
5 listen [::]:443 ssl;
6 listen 443 ssl;
7 http2 on;
8
9 server_name cc.cleberg.net;
10
11 include custom.d/tls/ssl_engine.conf;
12 include custom.d/tls/certificate_files.conf;
13 include custom.d/tls/policy_balanced.conf;
14 include custom.d/basic.conf;
15
16 # ----------------------------------------------------------------------
17 # | Custom rules & config for specific website |
18 # ----------------------------------------------------------------------
19 location / {
20 set $upstream http://127.0.0.1:8111;
21 proxy_pass $upstream;
22
23 include custom.d/reverse_proxy/basic.conf;
24 }
25
26 include custom.d/security/robots_index_only.conf;
27 # ----------------------------------------------------------------------
28}
29
30# ----------------------------------------------------------------------
31# | Config file for non-secure host |
32# ----------------------------------------------------------------------
33server {
34 listen [::]:80;
35 listen 80;
36 server_name cc.cleberg.net;
37
38 return 301 https://$host$request_uri;
39}
linux/nginx/etc/nginx/conf.d/cleberg.io added +54
@@ -0,0 +1,54 @@
1# ----------------------------------------------------------------------
2# | Config file for host |
3# ----------------------------------------------------------------------
4server {
5 listen [::]:443 ssl;
6 listen 443 ssl;
7 http2 on;
8
9 server_name www.cleberg.io cleberg.io;
10
11 include custom.d/tls/ssl_engine.conf;
12 include custom.d/tls/policy_balanced.conf;
13# include custom.d/tls/certificate_files.conf;
14 ssl_certificate /etc/letsencrypt/live/cleberg.io/fullchain.pem;
15 ssl_certificate_key /etc/letsencrypt/live/cleberg.io/privkey.pem;
16 ssl_trusted_certificate /etc/letsencrypt/live/cleberg.io/chain.pem;
17
18 return 301 $scheme://cleberg.io$request_uri;
19}
20
21
22server {
23 listen [::]:443 ssl;
24 listen 443 ssl;
25 http2 on;
26
27 server_name cleberg.io;
28
29 include custom.d/tls/ssl_engine.conf;
30 include custom.d/tls/policy_balanced.conf;
31 include custom.d/basic.conf;
32
33# include custom.d/tls/certificate_files.conf;
34 ssl_certificate /etc/letsencrypt/live/cleberg.io/fullchain.pem;
35 ssl_certificate_key /etc/letsencrypt/live/cleberg.io/privkey.pem;
36 ssl_trusted_certificate /etc/letsencrypt/live/cleberg.io/chain.pem;
37
38 # ----------------------------------------------------------------------
39 # | Custom rules & config for specific website |
40 # ----------------------------------------------------------------------
41 return 301 https://cleberg.net;
42 # ----------------------------------------------------------------------
43}
44
45# ----------------------------------------------------------------------
46# | Config file for non-secure host |
47# ----------------------------------------------------------------------
48server {
49 listen [::]:80;
50 listen 80;
51 server_name www.cleberg.io cleberg.io;
52
53 return 301 https://cleberg.io$request_uri;
54}
linux/nginx/etc/nginx/conf.d/cleberg.net.conf added +70
@@ -0,0 +1,70 @@
1# ----------------------------------------------------------------------
2# | Config file for host |
3# ----------------------------------------------------------------------
4server {
5 listen [::]:443 ssl;
6 listen 443 ssl;
7 http2 on;
8
9 server_name www.cleberg.net;
10
11 include custom.d/tls/ssl_engine.conf;
12 include custom.d/tls/certificate_files.conf;
13 include custom.d/tls/policy_balanced.conf;
14
15 return 301 $scheme://cleberg.net$request_uri;
16}
17
18
19server {
20 listen [::]:443 ssl;
21 listen 443 ssl;
22 http2 on;
23
24 server_name cleberg.net;
25
26 include custom.d/tls/ssl_engine.conf;
27 include custom.d/tls/certificate_files.conf;
28 include custom.d/tls/policy_balanced.conf;
29 include custom.d/basic.conf;
30
31 root /var/www/cleberg.net/;
32
33 # ----------------------------------------------------------------------
34 # | Custom rules & config for specific website |
35 # ----------------------------------------------------------------------
36 location / {
37 try_files $uri $uri/ =404;
38 }
39
40 # fix: redirect blog & wiki posts from "/" to ".html"
41 location /blog/ {
42 rewrite ^/blog/((?!index)[^/]+)/(.*)$ /blog/$1.html permanent;
43 }
44
45 location /wiki/ {
46 rewrite ^/wiki/((?!index)[^/]+)/(.*)$ /wiki/$1.html permanent;
47 }
48
49 # fix: redirect atom.xml to feed.xml
50 location /atom.xml {
51 return 301 $scheme://$host/feed.xml;
52 }
53
54 # fix: redirect salary page
55 location /blog/salary-transparency.html {
56 return 301 $scheme://$host/salary/;
57 }
58 # ----------------------------------------------------------------------
59}
60
61# ----------------------------------------------------------------------
62# | Config file for non-secure host |
63# ----------------------------------------------------------------------
64server {
65 listen [::]:80;
66 listen 80;
67 server_name www.cleberg.net cleberg.net;
68
69 return 301 https://cleberg.net$request_uri;
70}
linux/nginx/etc/nginx/conf.d/cv.conf added +37
@@ -0,0 +1,37 @@
1# ----------------------------------------------------------------------
2# | Config file for host |
3# ----------------------------------------------------------------------
4server {
5 listen [::]:443 ssl;
6 listen 443 ssl;
7 http2 on;
8
9 server_name cv.cleberg.net;
10
11 include custom.d/tls/ssl_engine.conf;
12 include custom.d/tls/certificate_files.conf;
13 include custom.d/tls/policy_balanced.conf;
14 include custom.d/basic.conf;
15
16 root /var/www/cv/;
17 autoindex on;
18
19 # ----------------------------------------------------------------------
20 # | Custom rules & config for specific website |
21 # ----------------------------------------------------------------------
22 location / {
23 try_files $uri $uri/ /index.html;
24 }
25 # ----------------------------------------------------------------------
26}
27
28# ----------------------------------------------------------------------
29# | Config file for non-secure host |
30# ----------------------------------------------------------------------
31server {
32 listen [::]:80;
33 listen 80;
34 server_name cv.cleberg.net;
35
36 return 301 https://$host$request_uri;
37}
linux/nginx/etc/nginx/conf.d/ddns.conf added +44
@@ -0,0 +1,44 @@
1# ----------------------------------------------------------------------
2# | Config file for host |
3# ----------------------------------------------------------------------
4server {
5 listen [::]:443 ssl;
6 listen 443 ssl;
7 http2 on;
8
9 server_name ddns.cleberg.net;
10
11 include custom.d/tls/ssl_engine.conf;
12 include custom.d/tls/certificate_files.conf;
13 include custom.d/tls/policy_balanced.conf;
14 include custom.d/basic.conf;
15
16 # ----------------------------------------------------------------------
17 # | Custom rules & config for specific website |
18 # ----------------------------------------------------------------------
19 location /authelia {
20 include custom.d/reverse_proxy/authelia.conf;
21 }
22
23 location / {
24 set $upstream http://127.0.0.1:8097;
25 proxy_pass $upstream;
26
27 include custom.d/reverse_proxy/authelia_request.conf;
28 include custom.d/reverse_proxy/basic.conf;
29 }
30
31 include custom.d/security/robots_index_only.conf;
32 # ----------------------------------------------------------------------
33}
34
35# ----------------------------------------------------------------------
36# | Config file for non-secure host |
37# ----------------------------------------------------------------------
38server {
39 listen [::]:80;
40 listen 80;
41 server_name ddns.cleberg.net;
42
43 return 301 https://$host$request_uri;
44}
linux/nginx/etc/nginx/conf.d/default.conf added +33
@@ -0,0 +1,33 @@
1# ----------------------------------------------------------------------
2# | Default behavior for unknown hosts |
3# ----------------------------------------------------------------------
4#
5# Drop requests for unknown hosts.
6#
7# If no default server is defined, Nginx will use the first found server.
8# To prevent host header attacks, or other potential problems when an unknown
9# server name is used in a request, it's recommended to drop the request
10# returning 444 "No Response".
11
12server {
13 listen [::]:443 ssl default_server;
14 listen 443 ssl default_server;
15 http2 on;
16
17 server_name _;
18
19 include custom.d/tls/ssl_engine.conf;
20 include custom.d/tls/certificate_files.conf;
21 include custom.d/tls/policy_balanced.conf;
22
23 return 444;
24}
25
26server {
27 listen [::]:80;
28 listen 80;
29
30 server_name _;
31
32 return 444;
33}
linux/nginx/etc/nginx/conf.d/docker.conf added +44
@@ -0,0 +1,44 @@
1# ----------------------------------------------------------------------
2# | Config file for host |
3# ----------------------------------------------------------------------
4server {
5 listen [::]:443 ssl;
6 listen 443 ssl;
7 http2 on;
8
9 server_name docker.cleberg.net;
10
11 include custom.d/tls/ssl_engine.conf;
12 include custom.d/tls/certificate_files.conf;
13 include custom.d/tls/policy_balanced.conf;
14 include custom.d/basic.conf;
15
16 # ----------------------------------------------------------------------
17 # | Custom rules & config for specific website |
18 # ----------------------------------------------------------------------
19 location /authelia {
20 include custom.d/reverse_proxy/authelia.conf;
21 }
22
23 location / {
24 set $upstream http://127.0.0.1:3777;
25 proxy_pass $upstream;
26
27 include custom.d/reverse_proxy/authelia_request.conf;
28 include custom.d/reverse_proxy/basic.conf;
29 }
30
31 include custom.d/security/robots_index_only.conf;
32 # ----------------------------------------------------------------------
33}
34
35# ----------------------------------------------------------------------
36# | Config file for non-secure host |
37# ----------------------------------------------------------------------
38server {
39 listen [::]:80;
40 listen 80;
41 server_name docker.cleberg.net;
42
43 return 301 https://$host$request_uri;
44}
linux/nginx/etc/nginx/conf.d/files.conf added +40
@@ -0,0 +1,40 @@
1# ----------------------------------------------------------------------
2# | Config file for files.cleberg.net host |
3# ----------------------------------------------------------------------
4server {
5 listen [::]:443 ssl;
6 listen 443 ssl;
7 http2 on;
8
9 # The host name to respond to
10 server_name files.cleberg.net;
11
12 include custom.d/tls/ssl_engine.conf;
13 include custom.d/tls/certificate_files.conf;
14 include custom.d/tls/policy_balanced.conf;
15 include custom.d/basic.conf;
16
17 root /var/www/files/;
18 autoindex on;
19
20 # Include the basic custom.d config set
21
22 # ----------------------------------------------------------------------
23 # | Custom rules & config for specific website |
24 # ----------------------------------------------------------------------
25 location / {
26 try_files $uri $uri/ /index.html;
27 }
28 # ----------------------------------------------------------------------
29}
30
31# ----------------------------------------------------------------------
32# | Config file for non-secure cleberg.net host |
33# ----------------------------------------------------------------------
34server {
35 listen [::]:80;
36 listen 80;
37 server_name files.cleberg.net;
38
39 return 301 https://$host$request_uri;
40}
linux/nginx/etc/nginx/conf.d/gh.conf added +39
@@ -0,0 +1,39 @@
1# ----------------------------------------------------------------------
2# | Config file for host |
3# ----------------------------------------------------------------------
4server {
5 listen [::]:443 ssl;
6 listen 443 ssl;
7 http2 on;
8
9 server_name gh.cleberg.net;
10
11 include custom.d/tls/ssl_engine.conf;
12 include custom.d/tls/certificate_files.conf;
13 include custom.d/tls/policy_balanced.conf;
14 include custom.d/basic.conf;
15
16 # ----------------------------------------------------------------------
17 # | Custom rules & config for specific website |
18 # ----------------------------------------------------------------------
19 location / {
20 set $upstream http://192.168.0.251:3039;
21 proxy_pass $upstream;
22
23 include custom.d/reverse_proxy/basic.conf;
24 }
25
26 include custom.d/security/robots_index_only.conf;
27 # ----------------------------------------------------------------------
28}
29
30# ----------------------------------------------------------------------
31# | Config file for non-secure host |
32# ----------------------------------------------------------------------
33server {
34 listen [::]:80;
35 listen 80;
36 server_name gh.cleberg.net;
37
38 return 301 https://$host$request_uri;
39}
linux/nginx/etc/nginx/conf.d/ha.conf added +46
@@ -0,0 +1,46 @@
1# ----------------------------------------------------------------------
2# | Config file for host |
3# ----------------------------------------------------------------------
4server {
5 listen [::]:443 ssl;
6 listen 443 ssl;
7 http2 on;
8
9 server_name ha.cleberg.net;
10
11 include custom.d/tls/ssl_engine.conf;
12 include custom.d/tls/certificate_files.conf;
13 include custom.d/tls/policy_balanced.conf;
14 include custom.d/basic.conf;
15
16 # ----------------------------------------------------------------------
17 # | Custom rules & config for specific website |
18 # ----------------------------------------------------------------------
19 set $upstream http://192.168.0.214:8123;
20
21 location / {
22 proxy_pass $upstream;
23 proxy_set_header X-Forwarded-For $remote_addr;
24 }
25
26 location /api/websocket {
27 proxy_pass $upstream;
28 proxy_http_version 1.1;
29 proxy_set_header Upgrade $http_upgrade;
30 proxy_set_header Connection "upgrade";
31 }
32
33 include custom.d/security/robots_index_only.conf;
34 # ----------------------------------------------------------------------
35}
36
37# ----------------------------------------------------------------------
38# | Config file for non-secure host |
39# ----------------------------------------------------------------------
40server {
41 listen [::]:80;
42 listen 80;
43 server_name ha.cleberg.net;
44
45 return 301 https://$host$request_uri;
46}
linux/nginx/etc/nginx/conf.d/hat.conf added +39
@@ -0,0 +1,39 @@
1# ----------------------------------------------------------------------
2# | Config file for host |
3# ----------------------------------------------------------------------
4server {
5 listen [::]:443 ssl;
6 listen 443 ssl;
7 http2 on;
8
9 server_name hat.cleberg.net;
10
11 include custom.d/tls/ssl_engine.conf;
12 include custom.d/tls/certificate_files.conf;
13 include custom.d/tls/policy_balanced.conf;
14 include custom.d/basic.conf;
15
16 # ----------------------------------------------------------------------
17 # | Custom rules & config for specific website |
18 # ----------------------------------------------------------------------
19 location / {
20 set $upstream http://192.168.0.251:3991;
21 proxy_pass $upstream;
22
23 include custom.d/reverse_proxy/basic.conf;
24 }
25
26 include custom.d/security/robots_index_only.conf;
27 # ----------------------------------------------------------------------
28}
29
30# ----------------------------------------------------------------------
31# | Config file for non-secure host |
32# ----------------------------------------------------------------------
33server {
34 listen [::]:80;
35 listen 80;
36 server_name hat.cleberg.net;
37
38 return 301 https://$host$request_uri;
39}
linux/nginx/etc/nginx/conf.d/hn.conf added +27
@@ -0,0 +1,27 @@
1server {
2 listen [::]:443 ssl;
3 listen 443 ssl;
4 http2 on;
5
6 server_name hn.cleberg.net r3yfeffyj7ornpikojmw75u3sn2la7tqnmcmwgv2ov7if24sm5czqeid.onion;
7 root /var/www/hn/output/;
8 autoindex on;
9 add_header Onion-Location http://r3yfeffyj7ornpikojmw75u3sn2la7tqnmcmwgv2ov7if24sm5czqeid.onion;
10
11 include custom.d/tls/ssl_engine.conf;
12 include custom.d/tls/certificate_files.conf;
13 include custom.d/tls/policy_balanced.conf;
14 include custom.d/basic.conf;
15
16 location / {
17 try_files $uri $uri/ /index.html;
18 }
19}
20
21server {
22 listen [::]:80;
23 listen 80;
24 server_name hn.cleberg.net;
25
26 return 301 https://$host$request_uri;
27}
linux/nginx/etc/nginx/conf.d/img.conf added +37
@@ -0,0 +1,37 @@
1# ----------------------------------------------------------------------
2# | Config file for host |
3# ----------------------------------------------------------------------
4server {
5 listen [::]:443 ssl;
6 listen 443 ssl;
7 http2 on;
8
9 server_name img.cleberg.net;
10
11 include custom.d/tls/ssl_engine.conf;
12 include custom.d/tls/certificate_files.conf;
13 include custom.d/tls/policy_balanced.conf;
14 include custom.d/basic.conf;
15
16 root /var/www/img/;
17 autoindex on;
18
19 # ----------------------------------------------------------------------
20 # | Custom rules & config for specific website |
21 # ----------------------------------------------------------------------
22 location / {
23 try_files $uri $uri/ =404;
24 }
25 # ----------------------------------------------------------------------
26}
27
28# ----------------------------------------------------------------------
29# | Config file for non-secure host |
30# ----------------------------------------------------------------------
31server {
32 listen [::]:80;
33 listen 80;
34 server_name img.cleberg.net;
35
36 return 301 https://img.cleberg.net$request_uri;
37}
linux/nginx/etc/nginx/conf.d/irc.conf added +44
@@ -0,0 +1,44 @@
1# ----------------------------------------------------------------------
2# | Config file for host |
3# ----------------------------------------------------------------------
4server {
5 listen [::]:443 ssl;
6 listen 443 ssl;
7 http2 on;
8
9 server_name irc.cleberg.net;
10
11 include custom.d/tls/ssl_engine.conf;
12 include custom.d/tls/certificate_files.conf;
13 include custom.d/tls/policy_balanced.conf;
14 include custom.d/basic.conf;
15
16 # ----------------------------------------------------------------------
17 # | Custom rules & config for specific website |
18 # ----------------------------------------------------------------------
19 location /authelia {
20 include custom.d/reverse_proxy/authelia.conf;
21 }
22
23 location / {
24 set $upstream http://192.168.0.251:9900;
25 proxy_pass $upstream;
26
27 include custom.d/reverse_proxy/authelia_request.conf;
28 include custom.d/reverse_proxy/basic.conf;
29 }
30
31 include custom.d/security/robots_index_only.conf;
32 # ----------------------------------------------------------------------
33}
34
35# ----------------------------------------------------------------------
36# | Config file for non-secure host |
37# ----------------------------------------------------------------------
38server {
39 listen [::]:80;
40 listen 80;
41 server_name irc.cleberg.net;
42
43 return 301 https://$host$request_uri;
44}
linux/nginx/etc/nginx/conf.d/ld.conf added +39
@@ -0,0 +1,39 @@
1# ----------------------------------------------------------------------
2# | Config file for host |
3# ----------------------------------------------------------------------
4server {
5 listen [::]:443 ssl;
6 listen 443 ssl;
7 http2 on;
8
9 server_name ld.cleberg.net;
10
11 include custom.d/tls/ssl_engine.conf;
12 include custom.d/tls/certificate_files.conf;
13 include custom.d/tls/policy_balanced.conf;
14 include custom.d/basic.conf;
15
16 # ----------------------------------------------------------------------
17 # | Custom rules & config for specific website |
18 # ----------------------------------------------------------------------
19 location / {
20 set $upstream http://127.0.0.1:3004;
21 proxy_pass $upstream;
22
23 include custom.d/reverse_proxy/basic.conf;
24 }
25
26 include custom.d/security/robots_index_only.conf;
27 # ----------------------------------------------------------------------
28}
29
30# ----------------------------------------------------------------------
31# | Config file for non-secure host |
32# ----------------------------------------------------------------------
33server {
34 listen [::]:80;
35 listen 80;
36 server_name ld.cleberg.net;
37
38 return 301 https://$host$request_uri;
39}
linux/nginx/etc/nginx/conf.d/lemmy.conf added +39
@@ -0,0 +1,39 @@
1# ----------------------------------------------------------------------
2# | Config file for host |
3# ----------------------------------------------------------------------
4server {
5 listen [::]:443 ssl;
6 listen 443 ssl;
7 http2 on;
8
9 server_name lemmy.cleberg.net;
10
11 include custom.d/tls/ssl_engine.conf;
12 include custom.d/tls/certificate_files.conf;
13 include custom.d/tls/policy_balanced.conf;
14 include custom.d/basic.conf;
15
16 # ----------------------------------------------------------------------
17 # | Custom rules & config for specific website |
18 # ----------------------------------------------------------------------
19 location / {
20 set $upstream http://127.0.0.1:10633;
21 proxy_pass $upstream;
22
23 include custom.d/reverse_proxy/basic.conf;
24 }
25
26 include custom.d/security/robots_index_only.conf;
27 # ----------------------------------------------------------------------
28}
29
30# ----------------------------------------------------------------------
31# | Config file for non-secure host |
32# ----------------------------------------------------------------------
33server {
34 listen [::]:80;
35 listen 80;
36 server_name lemmy.cleberg.net;
37
38 return 301 https://$host$request_uri;
39}
linux/nginx/etc/nginx/conf.d/lt.conf added +39
@@ -0,0 +1,39 @@
1# ----------------------------------------------------------------------
2# | Config file for host |
3# ----------------------------------------------------------------------
4server {
5 listen [::]:443 ssl;
6 listen 443 ssl;
7 http2 on;
8
9 server_name lt.cleberg.net;
10
11 include custom.d/tls/ssl_engine.conf;
12 include custom.d/tls/certificate_files.conf;
13 include custom.d/tls/policy_balanced.conf;
14 include custom.d/basic.conf;
15
16 # ----------------------------------------------------------------------
17 # | Custom rules & config for specific website |
18 # ----------------------------------------------------------------------
19 location / {
20 set $upstream http://127.0.0.1:5000;
21 proxy_pass $upstream;
22
23 include custom.d/reverse_proxy/basic.conf;
24 }
25
26 include custom.d/security/robots_index_only.conf;
27 # ----------------------------------------------------------------------
28}
29
30# ----------------------------------------------------------------------
31# | Config file for non-secure host |
32# ----------------------------------------------------------------------
33server {
34 listen [::]:80;
35 listen 80;
36 server_name lt.cleberg.net;
37
38 return 301 https://$host$request_uri;
39}
linux/nginx/etc/nginx/conf.d/mz.conf added +39
@@ -0,0 +1,39 @@
1# ----------------------------------------------------------------------
2# | Config file for host |
3# ----------------------------------------------------------------------
4server {
5 listen [::]:443 ssl;
6 listen 443 ssl;
7 http2 on;
8
9 server_name mz.cleberg.net;
10
11 include custom.d/tls/ssl_engine.conf;
12 include custom.d/tls/certificate_files.conf;
13 include custom.d/tls/policy_balanced.conf;
14 include custom.d/basic.conf;
15
16 # ----------------------------------------------------------------------
17 # | Custom rules & config for specific website |
18 # ----------------------------------------------------------------------
19 location / {
20 set $upstream http://127.0.0.1:3474;
21 proxy_pass $upstream;
22
23 include custom.d/reverse_proxy/basic.conf;
24 }
25
26 include custom.d/security/robots_index_only.conf;
27 # ----------------------------------------------------------------------
28}
29
30# ----------------------------------------------------------------------
31# | Config file for non-secure host |
32# ----------------------------------------------------------------------
33server {
34 listen [::]:80;
35 listen 80;
36 server_name mz.cleberg.net;
37
38 return 301 https://$host$request_uri;
39}
linux/nginx/etc/nginx/conf.d/no-ssl.default.conf added +27
@@ -0,0 +1,27 @@
1# ----------------------------------------------------------------------
2# | Default behavior for unknown hosts |
3# ----------------------------------------------------------------------
4#
5# Drop requests for unknown hosts.
6#
7# If no default server is defined, Nginx will use the first found server.
8# To prevent host header attacks, or other potential problems when an unknown
9# server name is used in a request, it's recommended to drop the request
10# returning 444 "No Response".
11#
12# (1) In production, only secure hosts should be used (all `no-ssl` disabled).
13# If so, redirect first ANY request to a secure connection before handling
14# it, even if the host is unknown.
15#
16# https://observatory.mozilla.org/faq/
17
18server {
19 listen [::]:80 default_server deferred;
20 listen 80 default_server deferred;
21
22 server_name _;
23
24 # (1)
25 return 301 https://$host$request_uri;
26 # return 444;
27}
linux/nginx/etc/nginx/conf.d/office.conf added +35
@@ -0,0 +1,35 @@
1# ----------------------------------------------------------------------
2# | Config file for host |
3# ----------------------------------------------------------------------
4server {
5 listen [::]:443 ssl;
6 listen 443 ssl;
7 http2 on;
8
9 server_name office.cleberg.net;
10 root /var/www/office/;
11
12 include custom.d/tls/ssl_engine.conf;
13 include custom.d/tls/certificate_files.conf;
14 include custom.d/tls/policy_balanced.conf;
15 include custom.d/basic.conf;
16
17 # ----------------------------------------------------------------------
18 # | Custom rules & config for specific website |
19 # ----------------------------------------------------------------------
20 location / {
21 try_files $uri $uri/ /index.html;
22 }
23 # ----------------------------------------------------------------------
24}
25
26# ----------------------------------------------------------------------
27# | Config file for non-secure host |
28# ----------------------------------------------------------------------
29server {
30 listen [::]:80;
31 listen 80;
32 server_name office.cleberg.net;
33
34 return 301 https://$host$request_uri;
35}
linux/nginx/etc/nginx/conf.d/org.conf added +35
@@ -0,0 +1,35 @@
1# ----------------------------------------------------------------------
2# | Config file for host |
3# ----------------------------------------------------------------------
4server {
5 listen [::]:443 ssl;
6 listen 443 ssl;
7 http2 on;
8
9 server_name org.cleberg.net;
10 root /var/www/org/;
11
12 include custom.d/tls/ssl_engine.conf;
13 include custom.d/tls/certificate_files.conf;
14 include custom.d/tls/policy_balanced.conf;
15 include custom.d/basic.conf;
16
17 # ----------------------------------------------------------------------
18 # | Custom rules & config for specific website |
19 # ----------------------------------------------------------------------
20 location / {
21 try_files $uri $uri/ /index.html;
22 }
23 # ----------------------------------------------------------------------
24}
25
26# ----------------------------------------------------------------------
27# | Config file for non-secure host |
28# ----------------------------------------------------------------------
29server {
30 listen [::]:80;
31 listen 80;
32 server_name org.cleberg.net;
33
34 return 301 https://$host$request_uri;
35}
linux/nginx/etc/nginx/conf.d/paste.conf added +39
@@ -0,0 +1,39 @@
1# ----------------------------------------------------------------------
2# | Config file for host |
3# ----------------------------------------------------------------------
4server {
5 listen [::]:443 ssl;
6 listen 443 ssl;
7 http2 on;
8
9 server_name paste.cleberg.net;
10
11 include custom.d/tls/ssl_engine.conf;
12 include custom.d/tls/certificate_files.conf;
13 include custom.d/tls/policy_balanced.conf;
14 include custom.d/basic.conf;
15
16 # ----------------------------------------------------------------------
17 # | Custom rules & config for specific website |
18 # ----------------------------------------------------------------------
19 location / {
20 set $upstream http://127.0.0.1:8084;
21 proxy_pass $upstream;
22
23 include custom.d/reverse_proxy/basic.conf;
24 }
25
26 include custom.d/security/robots_index_only.conf;
27 # ----------------------------------------------------------------------
28}
29
30# ----------------------------------------------------------------------
31# | Config file for non-secure host |
32# ----------------------------------------------------------------------
33server {
34 listen [::]:80;
35 listen 80;
36 server_name paste.cleberg.net;
37
38 return 301 https://$host$request_uri;
39}
linux/nginx/etc/nginx/conf.d/pb.conf added +39
@@ -0,0 +1,39 @@
1# ----------------------------------------------------------------------
2# | Config file for host |
3# ----------------------------------------------------------------------
4server {
5 listen [::]:443 ssl;
6 listen 443 ssl;
7 http2 on;
8
9 server_name pb.cleberg.net;
10
11 include custom.d/tls/ssl_engine.conf;
12 include custom.d/tls/certificate_files.conf;
13 include custom.d/tls/policy_balanced.conf;
14 include custom.d/basic.conf;
15
16 # ----------------------------------------------------------------------
17 # | Custom rules & config for specific website |
18 # ----------------------------------------------------------------------
19 location / {
20 set $upstream http://127.0.0.1:8745;
21 proxy_pass $upstream;
22
23 include custom.d/reverse_proxy/basic.conf;
24 }
25
26 # include custom.d/security/robots_index_only.conf;
27 # ----------------------------------------------------------------------
28}
29
30# ----------------------------------------------------------------------
31# | Config file for non-secure host |
32# ----------------------------------------------------------------------
33server {
34 listen [::]:80;
35 listen 80;
36 server_name pb.cleberg.net;
37
38 return 301 https://$host$request_uri;
39}
linux/nginx/etc/nginx/conf.d/pgp.conf added +37
@@ -0,0 +1,37 @@
1# ----------------------------------------------------------------------
2# | Config file for host |
3# ----------------------------------------------------------------------
4server {
5 listen [::]:443 ssl;
6 listen 443 ssl;
7 http2 on;
8
9 server_name pgp.cleberg.net;
10 root /var/www/pgp/;
11
12 include custom.d/tls/ssl_engine.conf;
13 include custom.d/tls/certificate_files.conf;
14 include custom.d/tls/policy_balanced.conf;
15 include custom.d/basic.conf;
16
17 # ----------------------------------------------------------------------
18 # | Custom rules & config for specific website |
19 # ----------------------------------------------------------------------
20 location / {
21 try_files $uri $uri/ /index.html;
22 }
23
24 include custom.d/security/robots_index_only.conf;
25 # ----------------------------------------------------------------------
26}
27
28# ----------------------------------------------------------------------
29# | Config file for non-secure host |
30# ----------------------------------------------------------------------
31server {
32 listen [::]:80;
33 listen 80;
34 server_name pgp.cleberg.net;
35
36 return 301 https://$host$request_uri;
37}
linux/nginx/etc/nginx/conf.d/photos.conf added +54
@@ -0,0 +1,54 @@
1# ----------------------------------------------------------------------
2# | Config file for host |
3# ----------------------------------------------------------------------
4server {
5 listen [::]:443 ssl;
6 listen 443 ssl;
7 http2 on;
8
9 server_name photos.cleberg.net;
10
11 include custom.d/tls/ssl_engine.conf;
12 include custom.d/tls/certificate_files.conf;
13 include custom.d/tls/policy_balanced.conf;
14 include custom.d/basic.conf;
15
16 # ----------------------------------------------------------------------
17 # | Custom rules & config for specific website |
18 # ----------------------------------------------------------------------
19 # allow large file uploads
20 client_max_body_size 50000M;
21
22 # Set headers
23 proxy_set_header Host $host;
24 proxy_set_header X-Real-IP $remote_addr;
25 proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
26 proxy_set_header X-Forwarded-Proto $scheme;
27
28 # enable websockets: http://nginx.org/en/docs/http/websocket.html
29 proxy_http_version 1.1;
30 proxy_set_header Upgrade $http_upgrade;
31 proxy_set_header Connection "upgrade";
32 proxy_redirect off;
33
34 # set timeout
35 proxy_read_timeout 600s;
36 proxy_send_timeout 600s;
37 send_timeout 600s;
38
39 location / {
40 proxy_pass http://127.0.0.1:2283;
41 }
42 # ----------------------------------------------------------------------
43}
44
45# ----------------------------------------------------------------------
46# | Config file for non-secure host |
47# ----------------------------------------------------------------------
48server {
49 listen [::]:80;
50 listen 80;
51 server_name photos.cleberg.net;
52
53 return 301 https://$host$request_uri;
54}
linux/nginx/etc/nginx/conf.d/pin.conf added +39
@@ -0,0 +1,39 @@
1# ----------------------------------------------------------------------
2# | Config file for host |
3# ----------------------------------------------------------------------
4server {
5 listen [::]:443 ssl;
6 listen 443 ssl;
7 http2 on;
8
9 server_name pin.cleberg.net;
10
11 include custom.d/tls/ssl_engine.conf;
12 include custom.d/tls/certificate_files.conf;
13 include custom.d/tls/policy_balanced.conf;
14 include custom.d/basic.conf;
15
16 # ----------------------------------------------------------------------
17 # | Custom rules & config for specific website |
18 # ----------------------------------------------------------------------
19 location / {
20 set $upstream http://127.0.0.1:8086;
21 proxy_pass $upstream;
22
23 include custom.d/reverse_proxy/basic.conf;
24 }
25
26 include custom.d/security/robots_index_only.conf;
27 # ----------------------------------------------------------------------
28}
29
30# ----------------------------------------------------------------------
31# | Config file for non-secure host |
32# ----------------------------------------------------------------------
33server {
34 listen [::]:80;
35 listen 80;
36 server_name pin.cleberg.net;
37
38 return 301 https://$host$request_uri;
39}
linux/nginx/etc/nginx/conf.d/piped.conf added +40
@@ -0,0 +1,40 @@
1# ----------------------------------------------------------------------
2# | Config file for host |
3# ----------------------------------------------------------------------
4server {
5 listen [::]:443 ssl;
6 listen 443 ssl;
7 http2 on;
8
9 server_name piped.cleberg.net pipedapi.cleberg.net pipedproxy.cleberg.net;
10
11 include custom.d/tls/ssl_engine.conf;
12 include custom.d/tls/certificate_files.conf;
13 include custom.d/tls/policy_balanced.conf;
14 include custom.d/basic.conf;
15
16 # ----------------------------------------------------------------------
17 # | Custom rules & config for specific website |
18 # ----------------------------------------------------------------------
19 location / {
20 set $upstream http://127.0.0.1:8077;
21 proxy_pass $upstream;
22
23 proxy_set_header Host $host;
24 # include custom.d/reverse_proxy/basic.conf;
25 }
26
27 include custom.d/security/robots_index_only.conf;
28 # ----------------------------------------------------------------------
29}
30
31# ----------------------------------------------------------------------
32# | Config file for non-secure host |
33# ----------------------------------------------------------------------
34server {
35 listen [::]:80;
36 listen 80;
37 server_name piped.cleberg.net pipedapi.cleberg.net pipedproxy.cleberg.net;
38
39 return 301 https://$host$request_uri;
40}
linux/nginx/etc/nginx/conf.d/projects.conf added +36
@@ -0,0 +1,36 @@
1# ----------------------------------------------------------------------
2# | Config file for host |
3# ----------------------------------------------------------------------
4server {
5 listen [::]:443 ssl;
6 listen 443 ssl;
7 http2 on;
8
9 server_name projects.cleberg.net;
10 root /var/www/projects/;
11 autoindex on;
12
13 include custom.d/tls/ssl_engine.conf;
14 include custom.d/tls/certificate_files.conf;
15 include custom.d/tls/policy_balanced.conf;
16 include custom.d/basic.conf;
17
18 # ----------------------------------------------------------------------
19 # | Custom rules & config for specific website |
20 # ----------------------------------------------------------------------
21 location / {
22 try_files $uri $uri/ /index.html;
23 }
24 # ----------------------------------------------------------------------
25}
26
27# ----------------------------------------------------------------------
28# | Config file for non-secure host |
29# ----------------------------------------------------------------------
30server {
31 listen [::]:80;
32 listen 80;
33 server_name projects.cleberg.net;
34
35 return 301 https://$host$request_uri;
36}
linux/nginx/etc/nginx/conf.d/rd.conf added +39
@@ -0,0 +1,39 @@
1# ----------------------------------------------------------------------
2# | Config file for host |
3# ----------------------------------------------------------------------
4server {
5 listen [::]:443 ssl;
6 listen 443 ssl;
7 http2 on;
8
9 server_name rd.cleberg.net;
10
11 include custom.d/tls/ssl_engine.conf;
12 include custom.d/tls/certificate_files.conf;
13 include custom.d/tls/policy_balanced.conf;
14 include custom.d/basic.conf;
15
16 # ----------------------------------------------------------------------
17 # | Custom rules & config for specific website |
18 # ----------------------------------------------------------------------
19 location / {
20 set $upstream http://127.0.0.1:5758;
21 proxy_pass $upstream;
22
23 include custom.d/reverse_proxy/basic.conf;
24 }
25
26 include custom.d/security/robots_index_only.conf;
27 # ----------------------------------------------------------------------
28}
29
30# ----------------------------------------------------------------------
31# | Config file for non-secure host |
32# ----------------------------------------------------------------------
33server {
34 listen [::]:80;
35 listen 80;
36 server_name rd.cleberg.net;
37
38 return 301 https://$host$request_uri;
39}
linux/nginx/etc/nginx/conf.d/reminiscecleberg.com.conf added +56
@@ -0,0 +1,56 @@
1# ----------------------------------------------------------------------
2# | Config file for host |
3# ----------------------------------------------------------------------
4server {
5 listen [::]:443 ssl;
6 listen 443 ssl;
7 http2 on;
8
9 server_name www.reminiscecleberg.com;
10
11 include custom.d/tls/ssl_engine.conf;
12 include custom.d/tls/policy_balanced.conf;
13 # include custom.d/tls/certificate_files.conf;
14 ssl_certificate /etc/letsencrypt/live/reminiscecleberg.com/fullchain.pem;
15 ssl_certificate_key /etc/letsencrypt/live/reminiscecleberg.com/privkey.pem;
16 ssl_trusted_certificate /etc/letsencrypt/live/reminiscecleberg.com/chain.pem;
17
18 return 301 $scheme://reminiscecleberg.com$request_uri;
19}
20
21
22server {
23 listen [::]:443 ssl;
24 listen 443 ssl;
25 http2 on;
26
27 server_name reminiscecleberg.com;
28 root /var/www/reminiscecleberg.com/;
29
30 include custom.d/tls/ssl_engine.conf;
31 include custom.d/tls/policy_balanced.conf;
32 include custom.d/basic.conf;
33 # include custom.d/tls/certificate_files.conf;
34 ssl_certificate /etc/letsencrypt/live/reminiscecleberg.com/fullchain.pem;
35 ssl_certificate_key /etc/letsencrypt/live/reminiscecleberg.com/privkey.pem;
36 ssl_trusted_certificate /etc/letsencrypt/live/reminiscecleberg.com/chain.pem;
37
38 # ----------------------------------------------------------------------
39 # | Custom rules & config for specific website |
40 # ----------------------------------------------------------------------
41 location / {
42 try_files $uri $uri/ =404;
43 }
44 # ----------------------------------------------------------------------
45}
46
47# ----------------------------------------------------------------------
48# | Config file for non-secure host |
49# ----------------------------------------------------------------------
50server {
51 listen [::]:80;
52 listen 80;
53 server_name www.reminiscecleberg.com reminiscecleberg.com;
54
55 return 301 https://reminiscecleberg.com$request_uri;
56}
linux/nginx/etc/nginx/conf.d/rimgo.conf added +39
@@ -0,0 +1,39 @@
1# ----------------------------------------------------------------------
2# | Config file for host |
3# ----------------------------------------------------------------------
4server {
5 listen [::]:443 ssl;
6 listen 443 ssl;
7 http2 on;
8
9 server_name rimgo.cleberg.net;
10
11 include custom.d/tls/ssl_engine.conf;
12 include custom.d/tls/certificate_files.conf;
13 include custom.d/tls/policy_balanced.conf;
14 include custom.d/basic.conf;
15
16 # ----------------------------------------------------------------------
17 # | Custom rules & config for specific website |
18 # ----------------------------------------------------------------------
19 location / {
20 set $upstream http://127.0.0.1:3869;
21 proxy_pass $upstream;
22
23 include custom.d/reverse_proxy/basic.conf;
24 }
25
26 include custom.d/security/robots_index_only.conf;
27 # ----------------------------------------------------------------------
28}
29
30# ----------------------------------------------------------------------
31# | Config file for non-secure host |
32# ----------------------------------------------------------------------
33server {
34 listen [::]:80;
35 listen 80;
36 server_name rimgo.cleberg.net;
37
38 return 301 https://$host$request_uri;
39}
linux/nginx/etc/nginx/conf.d/rl.conf added +44
@@ -0,0 +1,44 @@
1# ----------------------------------------------------------------------
2# | Config file for host |
3# ----------------------------------------------------------------------
4server {
5 listen [::]:443 ssl;
6 listen 443 ssl;
7 http2 on;
8
9 server_name rl.cleberg.net;
10
11 include custom.d/tls/ssl_engine.conf;
12 include custom.d/tls/certificate_files.conf;
13 include custom.d/tls/policy_balanced.conf;
14 include custom.d/basic.conf;
15
16 # ----------------------------------------------------------------------
17 # | Custom rules & config for specific website |
18 # ----------------------------------------------------------------------
19 location /authelia {
20 include custom.d/reverse_proxy/authelia.conf;
21 }
22
23 location / {
24 set $upstream http://192.168.0.251:8983;
25 proxy_pass $upstream;
26
27 include custom.d/reverse_proxy/authelia_request.conf;
28 include custom.d/reverse_proxy/basic.conf;
29 }
30
31 include custom.d/security/robots_index_only.conf;
32 # ----------------------------------------------------------------------
33}
34
35# ----------------------------------------------------------------------
36# | Config file for non-secure host |
37# ----------------------------------------------------------------------
38server {
39 listen [::]:80;
40 listen 80;
41 server_name rl.cleberg.net;
42
43 return 301 https://$host$request_uri;
44}
linux/nginx/etc/nginx/conf.d/rss.conf added +58
@@ -0,0 +1,58 @@
1# ----------------------------------------------------------------------
2# | Config file for host |
3# ----------------------------------------------------------------------
4upstream freshrss {
5 server 192.168.0.251:8081;
6 keepalive 64;
7}
8
9server {
10 listen [::]:443 ssl;
11 listen 443 ssl;
12 http2 on;
13
14 server_name rss.cleberg.net;
15
16 include custom.d/tls/ssl_engine.conf;
17 include custom.d/tls/certificate_files.conf;
18 include custom.d/tls/policy_balanced.conf;
19 include custom.d/basic.conf;
20
21 # ----------------------------------------------------------------------
22 # | Custom rules & config for specific website |
23 # ----------------------------------------------------------------------
24 location / {
25 proxy_pass http://freshrss/;
26
27 # include custom.d/reverse_proxy/basic.conf;
28
29 add_header X-Frame-Options SAMEORIGIN;
30 add_header X-XSS-Protection "1; mode=block";
31 proxy_redirect off;
32 proxy_buffering off;
33 proxy_set_header Host $host;
34 proxy_set_header X-Real-IP $remote_addr;
35 proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
36 proxy_set_header X-Forwarded-Proto $scheme;
37 proxy_set_header X-Forwarded-Port $server_port;
38 proxy_read_timeout 90;
39
40 # Forward the Authorization header for the Google Reader API.
41 proxy_set_header Authorization $http_authorization;
42 proxy_pass_header Authorization;
43 }
44
45 include custom.d/security/robots_index_only.conf;
46 # ----------------------------------------------------------------------
47}
48
49# ----------------------------------------------------------------------
50# | Config file for non-secure host |
51# ----------------------------------------------------------------------
52server {
53 listen [::]:80;
54 listen 80;
55 server_name rss.cleberg.net;
56
57 return 301 https://$host$request_uri;
58}
linux/nginx/etc/nginx/conf.d/search.conf added +44
@@ -0,0 +1,44 @@
1# ----------------------------------------------------------------------
2# | Config file for host |
3# ----------------------------------------------------------------------
4server {
5 listen [::]:443 ssl;
6 listen 443 ssl;
7 http2 on;
8
9 server_name search.cleberg.net;
10
11 include custom.d/tls/ssl_engine.conf;
12 include custom.d/tls/certificate_files.conf;
13 include custom.d/tls/policy_balanced.conf;
14 include custom.d/basic.conf;
15
16 # ----------------------------------------------------------------------
17 # | Custom rules & config for specific website |
18 # ----------------------------------------------------------------------
19 location / {
20 set $upstream http://127.0.0.1:9191;
21 proxy_pass $upstream;
22
23 # include custom.d/reverse_proxy/basic.conf;
24 proxy_set_header Host $host;
25 proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
26 proxy_set_header Upgrade $http_upgrade;
27 proxy_set_header Connection "upgrade";
28 proxy_http_version 1.1;
29 }
30
31 include custom.d/security/robots_index_only.conf;
32 # ----------------------------------------------------------------------
33}
34
35# ----------------------------------------------------------------------
36# | Config file for non-secure host |
37# ----------------------------------------------------------------------
38server {
39 listen [::]:80;
40 listen 80;
41 server_name search.cleberg.net;
42
43 return 301 https://$host$request_uri;
44}
linux/nginx/etc/nginx/conf.d/send.conf added +39
@@ -0,0 +1,39 @@
1# ----------------------------------------------------------------------
2# | Config file for host |
3# ----------------------------------------------------------------------
4server {
5 listen [::]:443 ssl;
6 listen 443 ssl;
7 http2 on;
8
9 server_name send.cleberg.net;
10
11 include custom.d/tls/ssl_engine.conf;
12 include custom.d/tls/certificate_files.conf;
13 include custom.d/tls/policy_balanced.conf;
14 include custom.d/basic.conf;
15
16 # ----------------------------------------------------------------------
17 # | Custom rules & config for specific website |
18 # ----------------------------------------------------------------------
19 location / {
20 set $upstream http://127.0.0.1:1443;
21 proxy_pass $upstream;
22
23 include custom.d/reverse_proxy/basic.conf;
24 }
25
26 include custom.d/security/robots_index_only.conf;
27 # ----------------------------------------------------------------------
28}
29
30# ----------------------------------------------------------------------
31# | Config file for non-secure host |
32# ----------------------------------------------------------------------
33server {
34 listen [::]:80;
35 listen 80;
36 server_name send.cleberg.net;
37
38 return 301 https://$host$request_uri;
39}
linux/nginx/etc/nginx/conf.d/slash.conf added +39
@@ -0,0 +1,39 @@
1# ----------------------------------------------------------------------
2# | Config file for host |
3# ----------------------------------------------------------------------
4server {
5 listen [::]:443 ssl;
6 listen 443 ssl;
7 http2 on;
8
9 server_name slash.cleberg.net;
10
11 include custom.d/tls/ssl_engine.conf;
12 include custom.d/tls/certificate_files.conf;
13 include custom.d/tls/policy_balanced.conf;
14 include custom.d/basic.conf;
15
16 # ----------------------------------------------------------------------
17 # | Custom rules & config for specific website |
18 # ----------------------------------------------------------------------
19 location / {
20 set $upstream http://192.168.0.251:5231;
21 proxy_pass $upstream;
22
23 include custom.d/reverse_proxy/basic.conf;
24 }
25
26 include custom.d/security/robots_index_only.conf;
27 # ----------------------------------------------------------------------
28}
29
30# ----------------------------------------------------------------------
31# | Config file for non-secure host |
32# ----------------------------------------------------------------------
33server {
34 listen [::]:80;
35 listen 80;
36 server_name slash.cleberg.net;
37
38 return 301 https://$host$request_uri;
39}
linux/nginx/etc/nginx/conf.d/small.conf added +39
@@ -0,0 +1,39 @@
1# ----------------------------------------------------------------------
2# | Config file for host |
3# ----------------------------------------------------------------------
4server {
5 listen [::]:443 ssl;
6 listen 443 ssl;
7 http2 on;
8
9 server_name small.cleberg.net;
10
11 include custom.d/tls/ssl_engine.conf;
12 include custom.d/tls/certificate_files.conf;
13 include custom.d/tls/policy_balanced.conf;
14 include custom.d/basic.conf;
15
16 # ----------------------------------------------------------------------
17 # | Custom rules & config for specific website |
18 # ----------------------------------------------------------------------
19 location / {
20 set $upstream http://127.0.0.1:8002;
21 proxy_pass $upstream;
22
23 include custom.d/reverse_proxy/basic.conf;
24 }
25
26 include custom.d/security/robots_index_only.conf;
27 # ----------------------------------------------------------------------
28}
29
30# ----------------------------------------------------------------------
31# | Config file for non-secure host |
32# ----------------------------------------------------------------------
33server {
34 listen [::]:80;
35 listen 80;
36 server_name small.cleberg.net;
37
38 return 301 https://$host$request_uri;
39}
linux/nginx/etc/nginx/conf.d/ssh.conf added +44
@@ -0,0 +1,44 @@
1# ----------------------------------------------------------------------
2# | Config file for host |
3# ----------------------------------------------------------------------
4server {
5 listen [::]:443 ssl;
6 listen 443 ssl;
7 http2 on;
8
9 server_name ssh.cleberg.net;
10
11 include custom.d/tls/ssl_engine.conf;
12 include custom.d/tls/certificate_files.conf;
13 include custom.d/tls/policy_balanced.conf;
14 include custom.d/basic.conf;
15
16 # ----------------------------------------------------------------------
17 # | Custom rules & config for specific website |
18 # ----------------------------------------------------------------------
19 location /authelia {
20 include custom.d/reverse_proxy/authelia.conf;
21 }
22
23 location / {
24 set $upstream http://127.0.0.1:8169;
25 proxy_pass $upstream;
26
27 include custom.d/reverse_proxy/authelia_request.conf;
28 include custom.d/reverse_proxy/basic.conf;
29 }
30
31 include custom.d/security/robots_index_only.conf;
32 # ----------------------------------------------------------------------
33}
34
35# ----------------------------------------------------------------------
36# | Config file for non-secure host |
37# ----------------------------------------------------------------------
38server {
39 listen [::]:80;
40 listen 80;
41 server_name ssh.cleberg.net;
42
43 return 301 https://$host$request_uri;
44}
linux/nginx/etc/nginx/conf.d/teddit.conf added +44
@@ -0,0 +1,44 @@
1# ----------------------------------------------------------------------
2# | Config file for host |
3# ----------------------------------------------------------------------
4server {
5 listen [::]:443 ssl;
6 listen 443 ssl;
7 http2 on;
8
9 server_name teddit.cleberg.net;
10
11 include custom.d/tls/ssl_engine.conf;
12 include custom.d/tls/certificate_files.conf;
13 include custom.d/tls/policy_balanced.conf;
14 include custom.d/basic.conf;
15
16 # ----------------------------------------------------------------------
17 # | Custom rules & config for specific website |
18 # ----------------------------------------------------------------------
19 location /authelia {
20 include custom.d/reverse_proxy/authelia.conf;
21 }
22
23 location / {
24 set $upstream http://192.168.0.251:8181;
25 proxy_pass $upstream;
26
27 include custom.d/reverse_proxy/authelia_request.conf;
28 include custom.d/reverse_proxy/basic.conf;
29 }
30
31 include custom.d/security/robots_index_only.conf;
32 # ----------------------------------------------------------------------
33}
34
35# ----------------------------------------------------------------------
36# | Config file for non-secure host |
37# ----------------------------------------------------------------------
38server {
39 listen [::]:80;
40 listen 80;
41 server_name teddit.cleberg.net;
42
43 return 301 https://$host$request_uri;
44}
linux/nginx/etc/nginx/conf.d/wyl.conf added +44
@@ -0,0 +1,44 @@
1# ----------------------------------------------------------------------
2# | Config file for host |
3# ----------------------------------------------------------------------
4server {
5 listen [::]:443 ssl;
6 listen 443 ssl;
7 http2 on;
8
9 server_name wyl.cleberg.net;
10
11 include custom.d/tls/ssl_engine.conf;
12 include custom.d/tls/certificate_files.conf;
13 include custom.d/tls/policy_balanced.conf;
14 include custom.d/basic.conf;
15
16 # ----------------------------------------------------------------------
17 # | Custom rules & config for specific website |
18 # ----------------------------------------------------------------------
19 location /authelia {
20 include custom.d/reverse_proxy/authelia.conf;
21 }
22
23 location / {
24 set $upstream http://192.168.0.251:8840;
25 proxy_pass $upstream;
26
27 include custom.d/reverse_proxy/authelia_request.conf;
28 include custom.d/reverse_proxy/basic.conf;
29 }
30
31 include custom.d/security/robots_index_only.conf;
32 # ----------------------------------------------------------------------
33}
34
35# ----------------------------------------------------------------------
36# | Config file for non-secure host |
37# ----------------------------------------------------------------------
38server {
39 listen [::]:80;
40 listen 80;
41 server_name wyl.cleberg.net;
42
43 return 301 https://$host$request_uri;
44}
linux/nginx/etc/nginx/custom.d/basic.conf added +8
@@ -0,0 +1,8 @@
1# Nginx Server Configs | MIT License
2# https://github.com/h5bp/server-configs-nginx
3
4include custom.d/security/referrer-policy.conf;
5include custom.d/security/x-content-type-options.conf;
6include custom.d/security/x-frame-options.conf;
7include custom.d/location/security_file_access.conf;
8#include custom.d/cross-origin/requests.conf;
linux/nginx/etc/nginx/custom.d/cross-origin/requests.conf added +18
@@ -0,0 +1,18 @@
1# ----------------------------------------------------------------------
2# | Cross-origin requests |
3# ----------------------------------------------------------------------
4
5# Allow cross-origin requests.
6#
7# https://developer.mozilla.org/en-US/docs/Web/HTTP/Access_control_CORS
8# https://enable-cors.org/
9# https://www.w3.org/TR/cors/
10
11# (!) Do not use this without understanding the consequences.
12# This will permit access from any other website.
13# Instead of using this file, consider using a specific rule such as
14# allowing access based on (sub)domain:
15#
16# add_header Access-Control-Allow-Origin "subdomain.example.com";
17
18# add_header Access-Control-Allow-Origin $cors;
linux/nginx/etc/nginx/custom.d/cross-origin/resource_timing.conf added +15
@@ -0,0 +1,15 @@
1# ----------------------------------------------------------------------
2# | Cross-origin resource timing |
3# ----------------------------------------------------------------------
4
5# Allow cross-origin access to the timing information for all resources.
6#
7# If a resource isn't served with a `Timing-Allow-Origin` header that would
8# allow its timing information to be shared with the document, some of the
9# attributes of the `PerformanceResourceTiming` object will be set to zero.
10#
11# https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Timing-Allow-Origin
12# https://www.w3.org/TR/resource-timing/
13# https://www.stevesouders.com/blog/2014/08/21/resource-timing-practical-tips/
14
15# add_header Timing-Allow-Origin "*";
linux/nginx/etc/nginx/custom.d/errors/custom_errors.conf added +9
@@ -0,0 +1,9 @@
1# ----------------------------------------------------------------------
2# | Custom error messages/pages |
3# ----------------------------------------------------------------------
4
5# Customize what Nginx returns to the client in case of an error.
6#
7# https://nginx.org/en/docs/http/ngx_http_core_module.html#error_page
8
9# error_page 404 /404.html;
linux/nginx/etc/nginx/custom.d/location/security_file_access.conf added +41
@@ -0,0 +1,41 @@
1# ----------------------------------------------------------------------
2# | File access |
3# ----------------------------------------------------------------------
4
5# Block access to all hidden files and directories except for the
6# visible content from within the `/.well-known/` hidden directory.
7#
8# These types of files usually contain user preferences or the preserved state
9# of a utility, and can include rather private places like, for example, the
10# `.git` or `.svn` directories.
11#
12# The `/.well-known/` directory represents the standard (RFC 5785) path prefix
13# for "well-known locations" (e.g.: `/.well-known/manifest.json`,
14# `/.well-known/keybase.txt`), and therefore, access to its visible content
15# should not be blocked.
16#
17# https://www.mnot.net/blog/2010/04/07/well-known
18# https://tools.ietf.org/html/rfc5785
19
20location ~* /\.(?!well-known\/) {
21 deny all;
22}
23
24# - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
25
26# Block access to files that can expose sensitive information.
27#
28# By default, block access to backup and source files that may be left by some
29# text editors and can pose a security risk when anyone has access to them.
30#
31# https://feross.org/cmsploit/
32#
33# (!) Update the `location` regular expression from below to include any files
34# that might end up on your production server and can expose sensitive
35# information about your website. These files may include: configuration
36# files, files that contain metadata about the project (e.g.: project
37# dependencies, build scripts, etc.).
38
39location ~* (?:#.*#|\.(?:bak|conf|dist|fla|in[ci]|log|orig|psd|sh|sql|sw[op])|~)$ {
40 deny all;
41}
linux/nginx/etc/nginx/custom.d/location/web_performance_filename-based_cache_busting.conf added +14
@@ -0,0 +1,14 @@
1# ----------------------------------------------------------------------
2# | Filename-based cache busting |
3# ----------------------------------------------------------------------
4
5# If you're not using a build process to manage your filename version revving,
6# you might want to consider enabling the following directives.
7#
8# To understand why this is important and even a better solution than using
9# something like `*.css?v231`, please see:
10# https://www.stevesouders.com/blog/2008/08/23/revving-filenames-dont-use-querystring/
11
12location ~* (.+)\.(?:\w+)\.(avifs?|bmp|css|cur|gif|ico|jpe?g|jxl|m?js|a?png|svgz?|webp|webmanifest)$ {
13 try_files $uri $1.$2;
14}
linux/nginx/etc/nginx/custom.d/location/web_performance_svgz-compression.conf added +18
@@ -0,0 +1,18 @@
1# ----------------------------------------------------------------------
2# | SVGZ Compression |
3# ----------------------------------------------------------------------
4
5# SVGZ files are already compressed.
6# Disable gzip function for `.svgz` files.
7
8location ~* \.svgz$ {
9 gzip off;
10 add_header Content-Encoding gzip;
11
12 include custom.d/security/x-content-type-options.conf;
13 include custom.d/security/content-security-policy.conf;
14 include custom.d/security/referrer-policy.conf;
15 include custom.d/security/permissions-policy.conf;
16 include custom.d/security/cross-origin-policy.conf;
17 include custom.d/cross-origin/requests.conf;
18}
linux/nginx/etc/nginx/custom.d/media_types/character_encodings.conf added +32
@@ -0,0 +1,32 @@
1# ----------------------------------------------------------------------
2# | Character encodings |
3# ----------------------------------------------------------------------
4
5# Serve all resources labeled as `text/html` or `text/plain` with the media type
6# `charset` parameter set to `UTF-8`.
7#
8# https://nginx.org/en/docs/http/ngx_http_charset_module.html#charset
9
10charset utf-8;
11
12# - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
13
14# Update charset_types to match updated mime.types.
15# `text/html` is always included by charset module.
16# Default: text/html text/xml text/plain text/vnd.wap.wml application/javascript application/rss+xml
17#
18# https://nginx.org/en/docs/http/ngx_http_charset_module.html#charset_types
19
20charset_types
21 text/css
22 text/plain
23 text/vnd.wap.wml
24 text/javascript
25 text/markdown
26 text/calendar
27 text/x-component
28 text/vcard
29 text/cache-manifest
30 text/vtt
31 application/json
32 application/manifest+json;
linux/nginx/etc/nginx/custom.d/media_types/media_types.conf added +18
@@ -0,0 +1,18 @@
1# ----------------------------------------------------------------------
2# | Media types |
3# ----------------------------------------------------------------------
4
5# Serve resources with the proper media types (f.k.a. MIME types).
6#
7# https://www.iana.org/assignments/media-types/media-types.xhtml
8# https://nginx.org/en/docs/http/ngx_http_core_module.html#types
9
10include mime.types;
11
12# - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
13
14# Default: text/plain
15#
16# https://nginx.org/en/docs/http/ngx_http_core_module.html#default_type
17
18default_type application/octet-stream;
linux/nginx/etc/nginx/custom.d/reverse_proxy/authelia.conf added +28
@@ -0,0 +1,28 @@
1internal;
2set $upstream_authelia http://127.0.0.1:9092/api/verify; #change the IP and Port to match the IP and Port of your Authelia container
3proxy_pass_request_body off;
4proxy_pass $upstream_authelia;
5proxy_set_header Content-Length "";
6
7# Timeout if the real server is dead
8proxy_next_upstream error timeout invalid_header http_500 http_502 http_503;
9client_body_buffer_size 128k;
10proxy_set_header Host $host;
11proxy_set_header X-Original-URL $scheme://$http_host$request_uri;
12proxy_set_header X-Real-IP $remote_addr;
13proxy_set_header X-Forwarded-For $remote_addr;
14proxy_set_header X-Forwarded-Proto $scheme;
15proxy_set_header X-Forwarded-Host $http_host;
16proxy_set_header X-Forwarded-Uri $request_uri;
17proxy_set_header X-Forwarded-Ssl on;
18proxy_redirect http:// $scheme://;
19proxy_http_version 1.1;
20proxy_set_header Connection "";
21proxy_cache_bypass $cookie_session;
22proxy_no_cache $cookie_session;
23proxy_buffers 4 32k;
24
25send_timeout 5m;
26proxy_read_timeout 240;
27proxy_send_timeout 240;
28proxy_connect_timeout 240;
linux/nginx/etc/nginx/custom.d/reverse_proxy/authelia_request.conf added +10
@@ -0,0 +1,10 @@
1auth_request /authelia;
2auth_request_set $target_url https://$http_host$request_uri;
3auth_request_set $user $upstream_http_remote_user;
4auth_request_set $email $upstream_http_remote_email;
5auth_request_set $groups $upstream_http_remote_groups;
6proxy_set_header Remote-User $user;
7proxy_set_header Remote-Email $email;
8proxy_set_header Remote-Groups $groups;
9
10error_page 401 =302 https://auth.cleberg.net/?rd=$target_url;
linux/nginx/etc/nginx/custom.d/reverse_proxy/basic.conf added +16
@@ -0,0 +1,16 @@
1proxy_set_header Host $host;
2proxy_set_header Upgrade $http_upgrade;
3proxy_set_header Connection upgrade;
4proxy_set_header Accept-Encoding gzip;
5proxy_set_header X-Real-IP $remote_addr;
6proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
7proxy_set_header X-Forwarded-Proto $scheme;
8proxy_set_header X-Forwarded-Host $http_host;
9proxy_set_header X-Forwarded-Uri $request_uri;
10proxy_set_header X-Forwarded-Ssl on;
11proxy_redirect http:// $scheme://;
12proxy_http_version 1.1;
13proxy_set_header Connection "";
14proxy_cache_bypass $cookie_session;
15proxy_no_cache $cookie_session;
16proxy_buffers 64 256k;
linux/nginx/etc/nginx/custom.d/security/content-security-policy.conf added +28
@@ -0,0 +1,28 @@
1# ----------------------------------------------------------------------
2# | Content Security Policy (CSP) |
3# ----------------------------------------------------------------------
4
5# Mitigate the risk of cross-site scripting and other content-injection
6# attacks.
7#
8# This can be done by setting a Content Security Policy which permits
9# trusted sources of content for your website.
10#
11# There is no policy that fits all websites, you will have to modify the
12# `Content-Security-Policy` directives in the example depending on your needs.
13#
14# To make your CSP implementation easier, you can use an online CSP header
15# generator such as:
16# https://report-uri.com/home/generate/
17#
18# It is encouraged that you validate your CSP header using a CSP validator
19# such as:
20# https://csp-evaluator.withgoogle.com
21#
22# https://www.w3.org/TR/CSP/
23# https://owasp.org/www-project-secure-headers/#content-security-policy
24# https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy
25# https://developers.google.com/web/fundamentals/security/csp
26# https://content-security-policy.com/
27
28add_header Content-Security-Policy $content_security_policy always;
linux/nginx/etc/nginx/custom.d/security/cross-origin-policy.conf added +44
@@ -0,0 +1,44 @@
1# ----------------------------------------------------------------------
2# | Cross Origin Policy |
3# ----------------------------------------------------------------------
4
5# Set strict a Cross Origin Policy to mitigate information leakage.
6#
7# (1) Cross-Origin-Embedder-Policy prevents a document from loading any
8# cross-origin resources that don’t explicitly grant the document
9# permission.
10# https://html.spec.whatwg.org/multipage/origin.html#coep
11# https://owasp.org/www-project-secure-headers/#cross-origin-embedder-policy
12# https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Cross-Origin-Embedder-Policy
13#
14# (2) Cross-Origin-Opener-Policy allows you to ensure a top-level document does
15# not share a browsing context group with cross-origin documents.
16# https://html.spec.whatwg.org/multipage/origin.html#cross-origin-opener-policies
17# https://owasp.org/www-project-secure-headers/#cross-origin-opener-policy
18# https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Cross-Origin-Opener-Policy
19#
20# (3) Cross-Origin-Resource-Policy allows to define a policy that lets web
21# sites and applications opt in to protection against certain requests from
22# other origins, to mitigate speculative side-channel attacks.
23# https://fetch.spec.whatwg.org/#cross-origin-resource-policy-header
24# https://owasp.org/www-project-secure-headers/#cross-origin-resource-policy
25# https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Cross-Origin-Resource-Policy
26# https://resourcepolicy.fyi/
27#
28# To check your Cross Origin Policy, you can use an online service, such as:
29# https://securityheaders.com/
30# https://observatory.mozilla.org/
31#
32# https://web.dev/coop-coep/
33# https://web.dev/why-coop-coep/
34# https://web.dev/cross-origin-isolation-guide/
35# https://scotthelme.co.uk/coop-and-coep/
36
37# (1)
38add_header Cross-Origin-Embedder-Policy $coep_policy always;
39
40# (2)
41add_header Cross-Origin-Opener-Policy $coop_policy always;
42
43# (3)
44add_header Cross-Origin-Resource-Policy $corp_policy always;
linux/nginx/etc/nginx/custom.d/security/permissions-policy.conf added +24
@@ -0,0 +1,24 @@
1# ----------------------------------------------------------------------
2# | Permissions Policy |
3# ----------------------------------------------------------------------
4
5# Set a strict Permissions Policy to mitigate access to browser features.
6#
7# The header uses a structured syntax, and allows sites to more tightly
8# restrict which origins can be granted access to features.
9# The list of available features:
10# https://github.com/w3c/webappsec-permissions-policy/blob/main/features.md
11#
12# The example policy below aims to disable all features expect synchronous
13# `XMLHttpRequest` requests on the same origin.
14#
15# To check your Permissions Policy, you can use an online service, such as:
16# https://securityheaders.com/
17# https://observatory.mozilla.org/
18#
19# https://www.w3.org/TR/permissions-policy-1/
20# https://owasp.org/www-project-secure-headers/#permissions-policy
21# https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Feature-Policy
22# https://scotthelme.co.uk/a-new-security-header-feature-policy/
23
24add_header Permissions-Policy $permissions_policy always;
linux/nginx/etc/nginx/custom.d/security/referrer-policy.conf added +25
@@ -0,0 +1,25 @@
1# ----------------------------------------------------------------------
2# | Referrer Policy |
3# ----------------------------------------------------------------------
4
5# Set a strict Referrer Policy to mitigate information leakage.
6#
7# (1) The `Referrer-Policy` header is included in responses for resources
8# that are able to request (or navigate to) other resources.
9#
10# This includes the commonly used resource types:
11# HTML, CSS, XML/SVG, PDF documents, scripts and workers.
12#
13# To prevent referrer leakage entirely, specify the `no-referrer` value
14# instead. Note that the effect could impact analytics metrics negatively.
15#
16# To check your Referrer Policy, you can use an online service, such as:
17# https://securityheaders.com/
18# https://observatory.mozilla.org/
19#
20# https://www.w3.org/TR/referrer-policy/
21# https://owasp.org/www-project-secure-headers/#referrer-policy
22# https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Referrer-Policy
23# https://scotthelme.co.uk/a-new-security-header-referrer-policy/
24
25add_header Referrer-Policy $referrer_policy always;
linux/nginx/etc/nginx/custom.d/security/robots.txt added +3
@@ -0,0 +1,3 @@
1User-agent: *
2Disallow: /
3Allow: /$
linux/nginx/etc/nginx/custom.d/security/robots_index_only.conf added +4
@@ -0,0 +1,4 @@
1location = /robots.txt {
2 default_type text/plain;
3 alias /etc/nginx/custom.d/security/robots.txt;
4}
linux/nginx/etc/nginx/custom.d/security/server_software_information.conf added +9
@@ -0,0 +1,9 @@
1# ----------------------------------------------------------------------
2# | Server software information |
3# ----------------------------------------------------------------------
4
5# Prevent Nginx from sending its version number in the "Server" response header.
6#
7# https://nginx.org/en/docs/http/ngx_http_core_module.html#server_tokens
8
9server_tokens off;
linux/nginx/etc/nginx/custom.d/security/strict-transport-security.conf added +38
@@ -0,0 +1,38 @@
1# ----------------------------------------------------------------------
2# | HTTP Strict Transport Security (HSTS) |
3# ----------------------------------------------------------------------
4
5# Force client-side TLS (Transport Layer Security) redirection.
6#
7# If a user types `example.com` in their browser, even if the server redirects
8# them to the secure version of the website, that still leaves a window of
9# opportunity (the initial HTTP connection) for an attacker to downgrade or
10# redirect the request.
11#
12# The following header ensures that a browser only connects to your server
13# via HTTPS, regardless of what the users type in the browser's address bar.
14#
15# (!) Be aware that Strict Transport Security is not revokable and you
16# must ensure being able to serve the site over HTTPS for the duration
17# you've specified in the `max-age` directive. When you don't have a
18# valid TLS connection anymore (e.g. due to an expired TLS certificate)
19# your visitors will see a nasty error message even when attempting to
20# connect over HTTP.
21#
22# (1) Preloading Strict Transport Security.
23# To submit your site for HSTS preloading, it is required that:
24# * the `includeSubDomains` directive is specified
25# * the `preload` directive is specified
26# * the `max-age` is specified with a value of at least 31536000 seconds
27# (1 year).
28# https://hstspreload.org/#deployment-recommendations
29#
30# https://tools.ietf.org/html/rfc6797#section-6.1
31# https://owasp.org/www-project-secure-headers/#http-strict-transport-security
32# https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Strict-Transport-Security
33# https://www.html5rocks.com/en/tutorials/security/transport-layer-security/
34# https://hstspreload.org/
35
36# add_header Strict-Transport-Security "max-age=16070400; includeSubDomains" always;
37# (1) Enable your site for HSTS preload inclusion.
38add_header Strict-Transport-Security "max-age=31536000; includeSubDomains; preload" always;
linux/nginx/etc/nginx/custom.d/security/x-content-type-options.conf added +17
@@ -0,0 +1,17 @@
1# ----------------------------------------------------------------------
2# | Content Type Options |
3# ----------------------------------------------------------------------
4
5# Prevent some browsers from MIME-sniffing the response.
6#
7# This reduces exposure to drive-by download attacks and cross-origin data
8# leaks, and should be left uncommented, especially if the server is serving
9# user-uploaded content or content that could potentially be treated as
10# executable by the browser.
11#
12# https://owasp.org/www-project-secure-headers/#x-content-type-options
13# https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/X-Content-Type-Options
14# https://blogs.msdn.microsoft.com/ie/2008/07/02/ie8-security-part-v-comprehensive-protection/
15# https://mimesniff.spec.whatwg.org/
16
17add_header X-Content-Type-Options nosniff always;
linux/nginx/etc/nginx/custom.d/security/x-frame-options.conf added +37
@@ -0,0 +1,37 @@
1# ----------------------------------------------------------------------
2# | Frame Options |
3# ----------------------------------------------------------------------
4
5# Protect website against clickjacking.
6#
7# The example below sends the `X-Frame-Options` response header with the value
8# `DENY`, informing browsers not to display the content of the web page in any
9# frame.
10#
11# This might not be the best setting for everyone. You should read about the
12# other two possible values the `X-Frame-Options` header field can have:
13# `SAMEORIGIN` and `ALLOW-FROM`.
14# https://tools.ietf.org/html/rfc7034#section-2.1.
15#
16# Keep in mind that while you could send the `X-Frame-Options` header for all
17# of your website's pages, this has the potential downside that it forbids even
18# non-malicious framing of your content.
19#
20# Nonetheless, you should ensure that you send the `X-Frame-Options` header for
21# all pages that allow a user to make a state-changing operation (e.g: pages
22# that contain one-click purchase links, checkout or bank-transfer confirmation
23# pages, pages that make permanent configuration changes, etc.).
24#
25# Sending the `X-Frame-Options` header can also protect your website against
26# more than just clickjacking attacks.
27# https://cure53.de/xfo-clickjacking.pdf.
28#
29# (!) The `Content-Security-Policy` header has a `frame-ancestors` directive
30# which obsoletes this header for supporting browsers.
31#
32# https://tools.ietf.org/html/rfc7034
33# https://owasp.org/www-project-secure-headers/#x-frame-options
34# https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/X-Frame-Options
35# https://docs.microsoft.com/archive/blogs/ieinternals/combating-clickjacking-with-x-frame-options
36
37add_header X-Frame-Options $x_frame_options always;
linux/nginx/etc/nginx/custom.d/tls/certificate_files.conf added +33
@@ -0,0 +1,33 @@
1# ----------------------------------------------------------------------
2# | Certificate files |
3# ----------------------------------------------------------------------
4
5# This default SSL certificate will be served whenever the client lacks support
6# for SNI (Server Name Indication).
7#
8# (1) Certificate and key files location
9# The certificate file can contain an intermediate certificate.
10#
11# https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_certificate
12#
13# (2) Intermediate certificate location if loaded certificate (1) does not
14# contain intermediate certificate when enabling OCSP stapling.
15#
16# https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_trusted_certificate
17#
18# (3) CA certificate file location for client certificate authentication.
19#
20# https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_client_certificate
21
22# (1)
23# ssl_certificate /etc/nginx/certs/default.crt;
24# ssl_certificate_key /etc/nginx/certs/default.key;
25ssl_certificate /etc/letsencrypt/live/cleberg.net/fullchain.pem;
26ssl_certificate_key /etc/letsencrypt/live/cleberg.net/privkey.pem;
27
28# (2)
29# ssl_trusted_certificate /path/to/ca.crt;
30ssl_trusted_certificate /etc/letsencrypt/live/cleberg.net/chain.pem;
31
32# (3)
33# ssl_client_certificate /etc/nginx/default_ssl.crt;
linux/nginx/etc/nginx/custom.d/tls/ocsp_stapling.conf added +34
@@ -0,0 +1,34 @@
1# ----------------------------------------------------------------------
2# | Online Certificate Status Protocol stapling |
3# ----------------------------------------------------------------------
4
5# OCSP is a lightweight, only one record to help clients verify the validity of
6# the server certificate.
7# OCSP stapling allows the server to send its cached OCSP record during the TLS
8# handshake, without the need of 3rd party OCSP responder.
9#
10# https://wiki.mozilla.org/Security/Server_Side_TLS#OCSP_Stapling
11# https://tools.ietf.org/html/rfc6066#section-8
12# https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_stapling
13#
14# (1) Use Cloudflare 1.1.1.1 DNS resolver
15# https://developers.cloudflare.com/1.1.1.1/setting-up-1.1.1.1/
16#
17# (2) Use Google 8.8.8.8 DNS resolver
18# https://developers.google.com/speed/public-dns/docs/using
19#
20# (3) Use OpenDNS resolver
21# https://use.opendns.com
22
23ssl_stapling on;
24ssl_stapling_verify on;
25
26resolver
27 # (1)
28 1.1.1.1 1.0.0.1 [2606:4700:4700::1111] [2606:4700:4700::1001]
29 # (2)
30 8.8.8.8 8.8.4.4 [2001:4860:4860::8888] [2001:4860:4860::8844]
31 # (3)
32 # 208.67.222.222 208.67.220.220 [2620:119:35::35] [2620:119:53::53]
33 valid=60s;
34resolver_timeout 2s;
linux/nginx/etc/nginx/custom.d/tls/policy_balanced.conf added +20
@@ -0,0 +1,20 @@
1# ----------------------------------------------------------------------
2# | SSL policy - Balanced |
3# ----------------------------------------------------------------------
4
5# For services that need to support a wide range of clients, this configuration
6# is reasonably balanced.
7#
8# (1) The NIST curves (prime256v1, secp384r1, secp521r1) are known to be weak
9# and potentially vulnerable but are required to support Microsoft Edge
10# and Safari.
11# https://safecurves.cr.yp.to/
12#
13# https://wiki.mozilla.org/Security/Server_Side_TLS#Recommended_configurations
14# https://nginx.org/en/docs/http/ngx_http_ssl_module.html
15
16ssl_protocols TLSv1.2;
17ssl_ciphers EECDH+CHACHA20:EECDH+AES;
18
19# (1)
20ssl_ecdh_curve X25519:prime256v1:secp521r1:secp384r1;
linux/nginx/etc/nginx/custom.d/tls/policy_strict.conf added +50
@@ -0,0 +1,50 @@
1# ----------------------------------------------------------------------
2# | SSL policy - Strict |
3# ----------------------------------------------------------------------
4
5# For services that don't need backward compatibility, the parameters below
6# provide the highest level of security and performance.
7#
8# (!) This policy enforces a strong TLS configuration, which may raise
9# errors with old clients.
10# If a more compatible profile is required, use the "balanced" policy.
11#
12# (!) TLSv1.3 and its 0-RTT feature require NGINX >=1.15.4 and OpenSSL >=1.1.1
13# to be installed.
14#
15# (!) Don't enable `ssl_early_data` blindly! Requests sent within early data are
16# subject to replay attacks.
17#
18# (1) The NIST curves (prime256v1, secp384r1, secp521r1) are known to be weak
19# and potentially vulnerable.
20#
21# Add them back to the parameter `ssl_ecdh_curve` below to support
22# Microsoft Edge and Safari.
23#
24# https://safecurves.cr.yp.to/
25#
26# (2) Enables TLS 1.3 0-RTT, allows for faster resumption of TLS sessions.
27#
28# (!) Requests sent within early data are subject to replay attacks.
29# To protect against such attacks at the application layer, the
30# `$ssl_early_data` variable should be used:
31#
32# proxy_set_header Early-Data $ssl_early_data;
33#
34# The application should return response code 425 "Too Early" for anything
35# that could contain user supplied data.
36#
37# https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/425
38#
39# https://github.com/certbot/certbot/issues/6367
40# https://github.com/mozilla/server-side-tls/issues/217
41# https://nginx.org/en/docs/http/ngx_http_ssl_module.html
42
43ssl_protocols TLSv1.2 TLSv1.3;
44ssl_ciphers EECDH+CHACHA20:EECDH+AES;
45
46# (1)
47ssl_ecdh_curve X25519;
48
49# (2)
50#ssl_early_data on;
linux/nginx/etc/nginx/custom.d/tls/ssl_engine.conf added +47
@@ -0,0 +1,47 @@
1# ----------------------------------------------------------------------
2# | SSL engine |
3# ----------------------------------------------------------------------
4
5# (1) Optimize SSL by caching session parameters for 24 hours.
6# This cuts down on the number of expensive SSL handshakes.
7# By enabling a cache, we tell the client to re-use the already
8# negotiated state.
9# Here 10m (10 MB) in ssl_session_cache is size value (not time).
10# 1 MB cache can store about 4000 sessions, so we can store 40000 sessions.
11#
12# (2) Use a higher keepalive timeout to reduce the need for repeated handshakes
13# (!) Shouldn't be done unless you serve primarily HTTPS.
14# Default is 75s
15#
16# (3) SSL buffer size
17# Set 1400 bytes to fit in one MTU.
18# https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_buffer_size
19#
20# (4) Disable session tickets
21# Session tickets keys are not auto-rotated. Only a HUP / restart will do
22# so and when a restart is performed the previous key is lost, which resets
23# all previous sessions.
24# Only enable session tickets if you set up a manual rotation mechanism.
25# https://trac.nginx.org/nginx/changeset/1356a3b9692441e163b4e78be4e9f5a46c7479e9/nginx
26# https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_session_tickets
27#
28# (5) The TLS 1.2 and 1.3 ciphers in use in current policies are not considered
29# dangerous. This directive let the client choose the one that best fits their needs.
30# https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_prefer_server_ciphers
31# https://wiki.mozilla.org/Security/Server_Side_TLS
32
33# (1)
34ssl_session_timeout 24h;
35ssl_session_cache shared:SSL:10m;
36
37# (2)
38keepalive_timeout 300s;
39
40# (3)
41# ssl_buffer_size 1400;
42
43# (4)
44ssl_session_tickets off;
45
46# (5)
47ssl_prefer_server_ciphers off;
linux/nginx/etc/nginx/custom.d/web_performance/cache-control.conf added +43
@@ -0,0 +1,43 @@
1# ----------------------------------------------------------------------
2# | Cache Control |
3# ----------------------------------------------------------------------
4
5# Serve resources with appropriate cache control directives.
6#
7# The `Cache-Control` header field holds directives (instructions) that control
8# caching in browsers and shared caches (e.g. Proxies, CDNs).
9# Its use targets web performances improvement by specifying the expected
10# client and network caches behaviors.
11#
12# The usable cache directives are listed here:
13# https://www.iana.org/assignments/http-cache-directives/http-cache-directives.xml
14#
15# The cache directives are documented here:
16# https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Cache-Control#response_directives
17#
18# (!) Enable and configure this configuration with care.
19# Default values should embrace conformance for static files and simple
20# apps, but cache control definition at backend level is highly preferred.
21# Incorrect directives can lead to data leaks, or can degrade performances.
22#
23# More specifically, in-depth understanding on `public` vs `private`
24# directives meanings is highly recommended. A resource with `public` will
25# be cached by shared caches like CDN, even if a user session is active.
26#
27# (*) To avoid duplication of the directive `no-cache` on `Cache-Control`,
28# the value is skipped here.
29# The directive `no-cache` is already defined by Nginx `expires` when set
30# to `epoch`. This ensure a correct value enforcement whenever cache
31# control configuration is used or not.
32# Cache expiration configuration `expires` is described in the file
33# custom.d/web_performance/cache_expiration.conf.
34# https://nginx.org/en/docs/http/ngx_http_headers_module.html#expires
35#
36# https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Cache-Control
37# https://www.rfc-editor.org/rfc/rfc9111.html
38# https://www.rfc-editor.org/rfc/rfc8246.html
39# https://www.rfc-editor.org/rfc/rfc5861.html
40# https://www.iana.org/assignments/http-cache-directives/http-cache-directives.xml
41# https://cache-tests.fyi/
42
43add_header Cache-Control $cache_control;
linux/nginx/etc/nginx/custom.d/web_performance/cache-file-descriptors.conf added +34
@@ -0,0 +1,34 @@
1# ----------------------------------------------------------------------
2# | Cache file-descriptors |
3# ----------------------------------------------------------------------
4
5# This tells Nginx to cache open file handles, "Not Found" errors and
6# metadata about files and their permissions.
7#
8# Based on these cached metadata, Nginx can immediately begin sending data when
9# a popular file is requested, and will also know to immediately send a 404 if a
10# file is missing on disk, and so on.
11#
12# (!) It also means that the server won't react immediately to changes on disk,
13# which may be undesirable.
14# As only metadata are cached, edited files may be truncated until the cache
15# is refreshed.
16# https://github.com/h5bp/server-configs-nginx/issues/203
17#
18# In the below configuration, inactive files are released from the cache after
19# 20 seconds, whereas active (recently requested) files are re-validated every
20# 30 seconds.
21# Descriptors will not be cached unless they are used at least 2 times within
22# 20 seconds (the inactive time).
23# A maximum of the 1000 most recently used file descriptors can be cached at
24# any time.
25#
26# Production servers with stable file collections will definitely want to enable
27# the cache.
28#
29# https://nginx.org/en/docs/http/ngx_http_core_module.html#open_file_cache
30
31open_file_cache max=1000 inactive=20s;
32open_file_cache_valid 30s;
33open_file_cache_min_uses 2;
34open_file_cache_errors on;
linux/nginx/etc/nginx/custom.d/web_performance/cache_expiration.conf added +63
@@ -0,0 +1,63 @@
1# ----------------------------------------------------------------------
2# | Cache expiration |
3# ----------------------------------------------------------------------
4
5# Serve resources with a far-future expiration date.
6#
7# (!) If you don't control versioning with filename-based cache busting, you
8# should consider lowering the cache times to something like one week.
9#
10# https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Cache-Control
11# https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Expires
12# https://nginx.org/en/docs/http/ngx_http_headers_module.html#expires
13
14map $sent_http_content_type $expires {
15 # Default: Fallback
16 default 1y;
17
18 # Default: No content
19 "" off;
20
21 # Specific: Assets
22 ~*image/svg\+xml 1y;
23 ~*image/vnd.microsoft.icon 1w;
24 ~*image/x-icon 1w;
25
26 # Specific: Manifests
27 ~*application/manifest\+json 1w;
28 ~*text/cache-manifest epoch;
29
30 # Specific: Data interchange
31 ~*application/atom\+xml 1h;
32 ~*application/rdf\+xml 1h;
33 ~*application/rss\+xml 1h;
34
35 # Specific: Documents
36 ~*text/html epoch;
37 ~*text/markdown epoch;
38 ~*text/calendar epoch;
39
40 # Specific: Other
41 ~*text/x-cross-domain-policy 1w;
42
43 # Generic: Data
44 ~*json epoch;
45 ~*xml epoch;
46
47 # Generic: WebAssembly
48 # ~*application/wasm 1y; # default
49
50 # Generic: Assets
51 # ~*application/javascript 1y; # default
52 # ~*application/x-javascript 1y; # default
53 # ~*text/javascript 1y; # default
54 # ~*text/css 1y; # default
55
56 # Generic: Medias
57 # ~*audio/ 1y; # default
58 # ~*image/ 1y; # default
59 # ~*video/ 1y; # default
60 # ~*font/ 1y; # default
61}
62
63expires $expires;
linux/nginx/etc/nginx/custom.d/web_performance/compression.conf added +71
@@ -0,0 +1,71 @@
1# ----------------------------------------------------------------------
2# | Compression |
3# ----------------------------------------------------------------------
4
5# https://nginx.org/en/docs/http/ngx_http_gzip_module.html
6
7# Enable gzip compression.
8# Default: off
9gzip on;
10
11# Compression level (1-9).
12# 5 is a perfect compromise between size and CPU usage, offering about 75%
13# reduction for most ASCII files (almost identical to level 9).
14# Default: 1
15gzip_comp_level 5;
16
17# Don't compress anything that's already small and unlikely to shrink much if at
18# all (the default is 20 bytes, which is bad as that usually leads to larger
19# files after gzipping).
20# Default: 20
21gzip_min_length 256;
22
23# Compress data even for clients that are connecting to us via proxies,
24# identified by the "Via" header (required for CloudFront).
25# Default: off
26gzip_proxied any;
27
28# Tell proxies to cache both the gzipped and regular version of a resource
29# whenever the client's Accept-Encoding capabilities header varies;
30# Avoids the issue where a non-gzip capable client (which is extremely rare
31# today) would display gibberish if their proxy gave them the gzipped version.
32# Default: off
33gzip_vary on;
34
35# Compress all output labeled with one of the following MIME-types.
36# `text/html` is always compressed by gzip module.
37# Default: text/html
38gzip_types
39 application/atom+xml
40 application/geo+json
41 application/javascript
42 application/x-javascript
43 application/json
44 application/ld+json
45 application/manifest+json
46 application/rdf+xml
47 application/rss+xml
48 application/vnd.ms-fontobject
49 application/wasm
50 application/x-web-app-manifest+json
51 application/xhtml+xml
52 application/xml
53 font/eot
54 font/otf
55 font/ttf
56 image/bmp
57 image/svg+xml
58 image/vnd.microsoft.icon
59 image/x-icon
60 text/cache-manifest
61 text/calendar
62 text/css
63 text/javascript
64 text/markdown
65 text/plain
66 text/xml
67 text/vcard
68 text/vnd.rim.location.xloc
69 text/vtt
70 text/x-component
71 text/x-cross-domain-policy;
linux/nginx/etc/nginx/custom.d/web_performance/content_transformation.conf added +30
@@ -0,0 +1,30 @@
1# ----------------------------------------------------------------------
2# | Content transformation |
3# ----------------------------------------------------------------------
4
5# Prevent intermediate caches or proxies (such as those used by mobile
6# network providers) and browsers data-saving features from modifying
7# the website's content using the `no-transform` directive for
8# `Cache-Control` header.
9#
10# https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Cache-Control
11# https://tools.ietf.org/html/rfc7234#section-5.2.2.4
12#
13# (!) Carefully consider the impact on your visitors before disabling
14# content transformation. These transformations are performed to
15# improve the experience for data- and cost-constrained users
16# (e.g. users on a 2G connection).
17#
18# You can test the effects of content transformation applied by
19# Google's Lite Mode by visiting: https://googleweblight.com/i?u=https://www.example.com
20#
21# https://support.google.com/webmasters/answer/6211428
22#
23# (!) If you are using `ngx_pagespeed`, note that disabling this will
24# prevent `PageSpeed` from rewriting HTML files, and, if the
25# `pagespeed DisableRewriteOnNoTransform` directive isn't set to
26# `off`, also from rewriting other resources.
27#
28# https://developers.google.com/speed/pagespeed/module/configuration#notransform
29
30add_header Cache-Control "no-transform";
linux/nginx/etc/nginx/custom.d/web_performance/pre-compressed_content_brotli.conf added +17
@@ -0,0 +1,17 @@
1# ----------------------------------------------------------------------
2# | Brotli pre-compressed content |
3# ----------------------------------------------------------------------
4
5# Serve brotli compressed CSS, JS, HTML, SVG, ICS and JSON files if they exist
6# and if the client accepts br encoding.
7#
8# (!) To make this part relevant, you need to generate encoded files by your
9# own. Enabling this part will not auto-generate brotlied files.
10#
11# Note that some clients (e.g. browsers) require a secure connection to request
12# brotli-compressed resources.
13# https://www.chromestatus.com/feature/5420797577396224
14#
15# https://github.com/eustas/ngx_brotli/#brotli_static
16
17brotli_static on;
linux/nginx/etc/nginx/custom.d/web_performance/pre-compressed_content_gzip.conf added +13
@@ -0,0 +1,13 @@
1# ----------------------------------------------------------------------
2# | GZip pre-compressed content |
3# ----------------------------------------------------------------------
4
5# Serve gzip compressed CSS, JS, HTML, SVG, ICS, and JSON files if they exist
6# and if the client accepts gzip encoding.
7#
8# (!) To make this part relevant, you need to generate encoded files by your
9# own. Enabling this part will not auto-generate gziped files.
10#
11# https://nginx.org/en/docs/http/ngx_http_gzip_static_module.html
12
13gzip_static on;
linux/nginx/etc/nginx/fastcgi_params added +25
@@ -0,0 +1,25 @@
1
2fastcgi_param QUERY_STRING $query_string;
3fastcgi_param REQUEST_METHOD $request_method;
4fastcgi_param CONTENT_TYPE $content_type;
5fastcgi_param CONTENT_LENGTH $content_length;
6
7fastcgi_param SCRIPT_NAME $fastcgi_script_name;
8fastcgi_param REQUEST_URI $request_uri;
9fastcgi_param DOCUMENT_URI $document_uri;
10fastcgi_param DOCUMENT_ROOT $document_root;
11fastcgi_param SERVER_PROTOCOL $server_protocol;
12fastcgi_param REQUEST_SCHEME $scheme;
13fastcgi_param HTTPS $https if_not_empty;
14
15fastcgi_param GATEWAY_INTERFACE CGI/1.1;
16fastcgi_param SERVER_SOFTWARE nginx/$nginx_version;
17
18fastcgi_param REMOTE_ADDR $remote_addr;
19fastcgi_param REMOTE_PORT $remote_port;
20fastcgi_param SERVER_ADDR $server_addr;
21fastcgi_param SERVER_PORT $server_port;
22fastcgi_param SERVER_NAME $server_name;
23
24# PHP only, required if PHP was built with --enable-force-cgi-redirect
25fastcgi_param REDIRECT_STATUS 200;
linux/nginx/etc/nginx/mime.types added +138
@@ -0,0 +1,138 @@
1types {
2
3 # Data interchange
4
5 application/atom+xml atom;
6 application/json json map topojson;
7 application/ld+json jsonld;
8 application/rss+xml rss;
9 # Normalize to standard type.
10 # https://tools.ietf.org/html/rfc7946#section-12
11 application/geo+json geojson;
12 application/xml xml;
13 # Normalize to standard type.
14 # https://tools.ietf.org/html/rfc3870#section-2
15 application/rdf+xml rdf;
16
17
18 # JavaScript
19
20 # Servers should use text/javascript for JavaScript resources.
21 # https://html.spec.whatwg.org/multipage/scripting.html#scriptingLanguages
22 text/javascript js mjs;
23 application/wasm wasm;
24
25 # Manifest files
26
27 application/manifest+json webmanifest;
28 application/x-web-app-manifest+json webapp;
29 text/cache-manifest appcache;
30
31
32 # Media files
33
34 audio/midi mid midi kar;
35 audio/mp4 aac f4a f4b m4a;
36 audio/mpeg mp3;
37 audio/ogg oga ogg opus;
38 audio/x-realaudio ra;
39 audio/x-wav wav;
40 image/apng apng;
41 image/avif avif avifs;
42 image/bmp bmp;
43 image/gif gif;
44 image/jpeg jpeg jpg;
45 image/jxl jxl;
46 image/jxr jxr hdp wdp;
47 image/png png;
48 image/svg+xml svg svgz;
49 image/tiff tif tiff;
50 image/vnd.wap.wbmp wbmp;
51 image/webp webp;
52 image/x-jng jng;
53 video/3gpp 3gp 3gpp;
54 video/mp4 f4p f4v m4v mp4;
55 video/mpeg mpeg mpg;
56 video/ogg ogv;
57 video/quicktime mov;
58 video/webm webm;
59 video/x-flv flv;
60 video/x-mng mng;
61 video/x-ms-asf asf asx;
62 video/x-msvideo avi;
63
64 # Serving `.ico` image files with a different media type
65 # prevents Internet Explorer from displaying then as images:
66 # https://github.com/h5bp/html5-boilerplate/commit/37b5fec090d00f38de64b591bcddcb205aadf8ee
67
68 image/x-icon cur ico;
69
70
71 # Microsoft Office
72
73 application/msword doc;
74 application/vnd.ms-excel xls;
75 application/vnd.ms-powerpoint ppt;
76 application/vnd.openxmlformats-officedocument.wordprocessingml.document docx;
77 application/vnd.openxmlformats-officedocument.spreadsheetml.sheet xlsx;
78 application/vnd.openxmlformats-officedocument.presentationml.presentation pptx;
79
80
81 # Web fonts
82
83 font/woff woff;
84 font/woff2 woff2;
85 application/vnd.ms-fontobject eot;
86 font/ttf ttf;
87 font/collection ttc;
88 font/otf otf;
89
90
91 # Other
92
93 application/java-archive ear jar war;
94 application/mac-binhex40 hqx;
95 application/octet-stream bin deb dll dmg exe img iso msi msm msp safariextz;
96 application/pdf pdf;
97 application/postscript ai eps ps;
98 application/rtf rtf;
99 application/vnd.google-earth.kml+xml kml;
100 application/vnd.google-earth.kmz kmz;
101 application/vnd.wap.wmlc wmlc;
102 application/x-7z-compressed 7z;
103 application/x-bb-appworld bbaw;
104 application/x-bittorrent torrent;
105 application/x-chrome-extension crx;
106 application/x-cocoa cco;
107 application/x-java-archive-diff jardiff;
108 application/x-java-jnlp-file jnlp;
109 application/x-makeself run;
110 application/x-opera-extension oex;
111 application/x-perl pl pm;
112 application/x-pilot pdb prc;
113 application/x-rar-compressed rar;
114 application/x-redhat-package-manager rpm;
115 application/x-sea sea;
116 application/x-shockwave-flash swf;
117 application/x-stuffit sit;
118 application/x-tcl tcl tk;
119 application/x-x509-ca-cert crt der pem;
120 application/x-xpinstall xpi;
121 application/xhtml+xml xhtml;
122 application/xslt+xml xsl;
123 application/zip zip;
124 text/calendar ics;
125 text/css css;
126 text/csv csv;
127 text/html htm html shtml;
128 text/markdown md markdown;
129 text/mathml mml;
130 text/plain txt;
131 text/vcard vcard vcf;
132 text/vnd.rim.location.xloc xloc;
133 text/vnd.sun.j2me.app-descriptor jad;
134 text/vnd.wap.wml wml;
135 text/vtt vtt;
136 text/x-component htc;
137
138}
linux/nginx/etc/nginx/nginx.conf added +198
@@ -0,0 +1,198 @@
1# Configuration File - Nginx Server Configs
2# https://nginx.org/en/docs/
3
4# Run as a unique, less privileged user for security reasons.
5# Default: nobody nobody
6# https://nginx.org/en/docs/ngx_core_module.html#user
7# https://en.wikipedia.org/wiki/Principle_of_least_privilege
8# user www-data;
9user nginx;
10
11# Sets the worker threads to the number of CPU cores available in the system for
12# best performance. Should be > the number of CPU cores.
13# Maximum number of connections = worker_processes * worker_connections
14# Default: 1
15# https://nginx.org/en/docs/ngx_core_module.html#worker_processes
16worker_processes auto;
17
18# Maximum number of open files per worker process.
19# Should be > worker_connections.
20# Default: no limit
21# https://nginx.org/en/docs/ngx_core_module.html#worker_rlimit_nofile
22worker_rlimit_nofile 8192;
23
24# Provides the configuration file context in which the directives that affect
25# connection processing are specified.
26# https://nginx.org/en/docs/ngx_core_module.html#events
27events {
28
29 # If you need more connections than this, you start optimizing your OS.
30 # That's probably the point at which you hire people who are smarter than you
31 # as this is *a lot* of requests.
32 # Should be < worker_rlimit_nofile.
33 # Default: 512
34 # https://nginx.org/en/docs/ngx_core_module.html#worker_connections
35 worker_connections 8000;
36
37}
38
39# Log errors and warnings to this file
40# This is only used when you don't override it on a `server` level
41# Default: logs/error.log error
42# https://nginx.org/en/docs/ngx_core_module.html#error_log
43# error_log /var/log/nginx/error.log warn;
44error_log /dev/null emerg;
45
46# The file storing the process ID of the main process
47# Default: logs/nginx.pid
48# https://nginx.org/en/docs/ngx_core_module.html#pid
49pid /var/run/nginx.pid;
50
51# Include files in the custom.d folder.
52# Custom configuration and value files should be placed in the custom.d
53# folder.
54# The configurations should be disabled by prefixing files with a dot.
55# include custom.d/*.conf;
56
57http {
58
59 # Hide Nginx version information.
60 include custom.d/security/server_software_information.conf;
61
62 # Specify media (MIME) types for files.
63 include custom.d/media_types/media_types.conf;
64
65 # Set character encodings.
66 include custom.d/media_types/character_encodings.conf;
67
68 # Include $http_x_forwarded_for within default format used in log files
69 # https://nginx.org/en/docs/http/ngx_http_log_module.html#log_format
70 log_format main '$remote_addr - $remote_user [$time_local] "$request" '
71 '$status $body_bytes_sent "$http_referer" '
72 '"$http_user_agent" "$http_x_forwarded_for" "$host"';
73
74 # Log access to this file
75 # This is only used when you don't override it on a `server` level
76 # Default: logs/access.log combined
77 # https://nginx.org/en/docs/http/ngx_http_log_module.html#access_log
78 # access_log /var/log/nginx/access.log main;
79 access_log off;
80
81 # How long to allow each connection to stay idle.
82 # Longer values are better for each individual client, particularly for SSL,
83 # but means that worker connections are tied up longer.
84 # Default: 75s
85 # https://nginx.org/en/docs/http/ngx_http_core_module.html#keepalive_timeout
86 # keepalive_timeout 20s;
87 keepalive_timeout 75s;
88
89 # Speed up file transfers by using `sendfile()` to copy directly between
90 # descriptors rather than using `read()`/`write()``.
91 # For performance reasons, on FreeBSD systems w/ ZFS this option should be
92 # disabled as ZFS's ARC caches frequently used files in RAM by default.
93 # Default: off
94 # https://nginx.org/en/docs/http/ngx_http_core_module.html#sendfile
95 sendfile on;
96
97 # Don't send out partial frames; this increases throughput since TCP frames
98 # are filled up before being sent out.
99 # Default: off
100 # https://nginx.org/en/docs/http/ngx_http_core_module.html#tcp_nopush
101 tcp_nopush on;
102
103 # Enable gzip compression.
104 include custom.d/web_performance/compression.conf;
105
106 # Specify file cache expiration.
107 include custom.d/web_performance/cache_expiration.conf;
108
109 # Add Cache-Control.
110 # custom.d/web_performance/cache-control.conf
111 map $sent_http_content_type $cache_control {
112 default "public, immutable, stale-while-revalidate";
113
114 # No content
115 "" "no-store";
116
117 # Manifest files
118 ~*application/manifest\+json "public";
119 ~*text/cache-manifest ""; # `no-cache` (*)
120
121 # Assets
122 ~*image/svg\+xml "public, immutable, stale-while-revalidate";
123
124 # Data interchange
125 ~*application/(atom|rdf|rss)\+xml "public, stale-while-revalidate";
126
127 # Documents
128 ~*text/html "private, must-revalidate";
129 ~*text/markdown "private, must-revalidate";
130 ~*text/calendar "private, must-revalidate";
131
132 # Data
133 ~*json ""; # `no-cache` (*)
134 ~*xml ""; # `no-cache` (*)
135 }
136
137 # Add X-Frame-Options for HTML documents.
138 # custom.d/security/x-frame-options.conf
139 map $sent_http_content_type $x_frame_options {
140 ~*text/html DENY;
141 }
142
143 # Add Content-Security-Policy for HTML documents.
144 # custom.d/security/content-security-policy.conf
145 map $sent_http_content_type $content_security_policy {
146 ~*text/(html|javascript)|application/pdf|xml "default-src 'self'; base-uri 'none'; form-action 'self'; frame-ancestors 'none'; object-src 'none'; upgrade-insecure-requests";
147 }
148
149 # Add Permissions-Policy for HTML documents.
150 # custom.d/security/permissions-policy.conf
151 map $sent_http_content_type $permissions_policy {
152 ~*text/(html|javascript)|application/pdf|xml "accelerometer=(),autoplay=(),browsing-topics=(),camera=(),display-capture=(),document-domain=(),encrypted-media=(),fullscreen=(),geolocation=(),gyroscope=(),magnetometer=(),microphone=(),midi=(),payment=(),picture-in-picture=(),publickey-credentials-get=(),screen-wake-lock=(),sync-xhr=(self),usb=(),web-share=(),xr-spatial-tracking=()";
153 }
154
155 # Add Referrer-Policy for HTML documents.
156 # custom.d/security/referrer-policy.conf
157 map $sent_http_content_type $referrer_policy {
158 ~*text/(css|html|javascript)|application\/pdf|xml "strict-origin-when-cross-origin";
159 }
160
161 # Add Cross-Origin-Policies for HTML documents.
162 # custom.d/security/cross-origin-policy.conf
163 # Cross-Origin-Embedder-Policy
164 map $sent_http_content_type $coep_policy {
165 ~*text/(html|javascript)|application/pdf|xml "require-corp";
166 }
167 # Cross-Origin-Opener-Policy
168 map $sent_http_content_type $coop_policy {
169 ~*text/(html|javascript)|application/pdf|xml "same-origin";
170 }
171 # Cross-Origin-Resource-Policy
172 map $sent_http_content_type $corp_policy {
173 ~*text/(html|javascript)|application/pdf|xml "same-origin";
174 }
175
176 # Add Access-Control-Allow-Origin.
177 # custom.d/cross-origin/requests.conf
178 map $sent_http_content_type $cors {
179 # Images
180 ~*image/ "*";
181
182 # Web fonts
183 ~*font/ "*";
184 ~*application/vnd.ms-fontobject "*";
185 ~*application/x-font-ttf "*";
186 ~*application/font-woff "*";
187 ~*application/x-font-woff "*";
188 ~*application/font-woff2 "*";
189 }
190
191 # Fix for onion links
192 server_names_hash_bucket_size 128;
193
194 # Include files in the conf.d folder.
195 # `server` configuration files should be placed in the conf.d folder.
196 # The configurations should be disabled by prefixing files with a dot.
197 include conf.d/*.conf;
198}
linux/nginx/etc/nginx/scgi_params added +17
@@ -0,0 +1,17 @@
1
2scgi_param REQUEST_METHOD $request_method;
3scgi_param REQUEST_URI $request_uri;
4scgi_param QUERY_STRING $query_string;
5scgi_param CONTENT_TYPE $content_type;
6
7scgi_param DOCUMENT_URI $document_uri;
8scgi_param DOCUMENT_ROOT $document_root;
9scgi_param SCGI 1;
10scgi_param SERVER_PROTOCOL $server_protocol;
11scgi_param REQUEST_SCHEME $scheme;
12scgi_param HTTPS $https if_not_empty;
13
14scgi_param REMOTE_ADDR $remote_addr;
15scgi_param REMOTE_PORT $remote_port;
16scgi_param SERVER_PORT $server_port;
17scgi_param SERVER_NAME $server_name;
linux/nginx/etc/nginx/uwsgi_params added +17
@@ -0,0 +1,17 @@
1
2uwsgi_param QUERY_STRING $query_string;
3uwsgi_param REQUEST_METHOD $request_method;
4uwsgi_param CONTENT_TYPE $content_type;
5uwsgi_param CONTENT_LENGTH $content_length;
6
7uwsgi_param REQUEST_URI $request_uri;
8uwsgi_param PATH_INFO $document_uri;
9uwsgi_param DOCUMENT_ROOT $document_root;
10uwsgi_param SERVER_PROTOCOL $server_protocol;
11uwsgi_param REQUEST_SCHEME $scheme;
12uwsgi_param HTTPS $https if_not_empty;
13
14uwsgi_param REMOTE_ADDR $remote_addr;
15uwsgi_param REMOTE_PORT $remote_port;
16uwsgi_param SERVER_PORT $server_port;
17uwsgi_param SERVER_NAME $server_name;