Commit 7c3385ccef
Verified · cmc
Layout: unified · split
common/gnupg/.gnupg/gpg-agent.conf added +2
| @@ -0,0 +1,2 @@ | |||
| 1 | pinentry-program /usr/bin/pinentry-curses | ||
| 2 | allow-loopback-pinentry | ||
linux/nginx/etc/nginx/conf.d/ao.conf added +39
| @@ -0,0 +1,39 @@ | |||
| 1 | # ---------------------------------------------------------------------- | ||
| 2 | # | Config file for host | | ||
| 3 | # ---------------------------------------------------------------------- | ||
| 4 | server { | ||
| 5 | listen [::]:443 ssl; | ||
| 6 | listen 443 ssl; | ||
| 7 | http2 on; | ||
| 8 | |||
| 9 | server_name ao.cleberg.net; | ||
| 10 | |||
| 11 | include custom.d/tls/ssl_engine.conf; | ||
| 12 | include custom.d/tls/certificate_files.conf; | ||
| 13 | include custom.d/tls/policy_balanced.conf; | ||
| 14 | include custom.d/basic.conf; | ||
| 15 | |||
| 16 | # ---------------------------------------------------------------------- | ||
| 17 | # | Custom rules & config for specific website | | ||
| 18 | # ---------------------------------------------------------------------- | ||
| 19 | location / { | ||
| 20 | set $upstream http://127.0.0.1:9380; | ||
| 21 | proxy_pass $upstream; | ||
| 22 | |||
| 23 | include custom.d/reverse_proxy/basic.conf; | ||
| 24 | } | ||
| 25 | |||
| 26 | include custom.d/security/robots_index_only.conf; | ||
| 27 | # ---------------------------------------------------------------------- | ||
| 28 | } | ||
| 29 | |||
| 30 | # ---------------------------------------------------------------------- | ||
| 31 | # | Config file for non-secure host | | ||
| 32 | # ---------------------------------------------------------------------- | ||
| 33 | server { | ||
| 34 | listen [::]:80; | ||
| 35 | listen 80; | ||
| 36 | server_name ao.cleberg.net; | ||
| 37 | |||
| 38 | return 301 https://$host$request_uri; | ||
| 39 | } | ||
linux/nginx/etc/nginx/conf.d/art.conf added +39
| @@ -0,0 +1,39 @@ | |||
| 1 | # ---------------------------------------------------------------------- | ||
| 2 | # | Config file for host | | ||
| 3 | # ---------------------------------------------------------------------- | ||
| 4 | server { | ||
| 5 | listen [::]:443 ssl; | ||
| 6 | listen 443 ssl; | ||
| 7 | http2 on; | ||
| 8 | |||
| 9 | server_name art.cleberg.net; | ||
| 10 | |||
| 11 | include custom.d/tls/ssl_engine.conf; | ||
| 12 | include custom.d/tls/certificate_files.conf; | ||
| 13 | include custom.d/tls/policy_balanced.conf; | ||
| 14 | include custom.d/basic.conf; | ||
| 15 | |||
| 16 | # ---------------------------------------------------------------------- | ||
| 17 | # | Custom rules & config for specific website | | ||
| 18 | # ---------------------------------------------------------------------- | ||
| 19 | location / { | ||
| 20 | set $upstream http://127.0.0.1:3003; | ||
| 21 | proxy_pass $upstream; | ||
| 22 | |||
| 23 | include custom.d/reverse_proxy/basic.conf; | ||
| 24 | } | ||
| 25 | |||
| 26 | include custom.d/security/robots_index_only.conf; | ||
| 27 | # ---------------------------------------------------------------------- | ||
| 28 | } | ||
| 29 | |||
| 30 | # ---------------------------------------------------------------------- | ||
| 31 | # | Config file for non-secure host | | ||
| 32 | # ---------------------------------------------------------------------- | ||
| 33 | server { | ||
| 34 | listen [::]:80; | ||
| 35 | listen 80; | ||
| 36 | server_name art.cleberg.net; | ||
| 37 | |||
| 38 | return 301 https://$host$request_uri; | ||
| 39 | } | ||
linux/nginx/etc/nginx/conf.d/auth.conf added +42
| @@ -0,0 +1,42 @@ | |||
| 1 | # ---------------------------------------------------------------------- | ||
| 2 | # | Config file for host | | ||
| 3 | # ---------------------------------------------------------------------- | ||
| 4 | server { | ||
| 5 | listen [::]:443 ssl; | ||
| 6 | listen 443 ssl; | ||
| 7 | http2 on; | ||
| 8 | |||
| 9 | server_name auth.cleberg.net; | ||
| 10 | |||
| 11 | include custom.d/tls/ssl_engine.conf; | ||
| 12 | include custom.d/tls/certificate_files.conf; | ||
| 13 | include custom.d/tls/policy_balanced.conf; | ||
| 14 | include custom.d/basic.conf; | ||
| 15 | |||
| 16 | # ---------------------------------------------------------------------- | ||
| 17 | # | Custom rules & config for specific website | | ||
| 18 | # ---------------------------------------------------------------------- | ||
| 19 | set $upstream http://127.0.0.1:9092; | ||
| 20 | |||
| 21 | location / { | ||
| 22 | proxy_pass $upstream; | ||
| 23 | |||
| 24 | include custom.d/reverse_proxy/basic.conf; | ||
| 25 | } | ||
| 26 | |||
| 27 | location /api/verify { | ||
| 28 | proxy_pass $upstream; | ||
| 29 | } | ||
| 30 | # ---------------------------------------------------------------------- | ||
| 31 | } | ||
| 32 | |||
| 33 | # ---------------------------------------------------------------------- | ||
| 34 | # | Config file for non-secure host | | ||
| 35 | # ---------------------------------------------------------------------- | ||
| 36 | server { | ||
| 37 | listen [::]:80; | ||
| 38 | listen 80; | ||
| 39 | server_name auth.cleberg.net; | ||
| 40 | |||
| 41 | return 301 https://$host$request_uri; | ||
| 42 | } | ||
linux/nginx/etc/nginx/conf.d/br.conf added +39
| @@ -0,0 +1,39 @@ | |||
| 1 | # ---------------------------------------------------------------------- | ||
| 2 | # | Config file for host | | ||
| 3 | # ---------------------------------------------------------------------- | ||
| 4 | server { | ||
| 5 | listen [::]:443 ssl; | ||
| 6 | listen 443 ssl; | ||
| 7 | http2 on; | ||
| 8 | |||
| 9 | server_name br.cleberg.net; | ||
| 10 | |||
| 11 | include custom.d/tls/ssl_engine.conf; | ||
| 12 | include custom.d/tls/certificate_files.conf; | ||
| 13 | include custom.d/tls/policy_balanced.conf; | ||
| 14 | include custom.d/basic.conf; | ||
| 15 | |||
| 16 | # ---------------------------------------------------------------------- | ||
| 17 | # | Custom rules & config for specific website | | ||
| 18 | # ---------------------------------------------------------------------- | ||
| 19 | location / { | ||
| 20 | set $upstream http://127.0.0.1:3030; | ||
| 21 | proxy_pass $upstream; | ||
| 22 | |||
| 23 | include custom.d/reverse_proxy/basic.conf; | ||
| 24 | } | ||
| 25 | |||
| 26 | include custom.d/security/robots_index_only.conf; | ||
| 27 | # ---------------------------------------------------------------------- | ||
| 28 | } | ||
| 29 | |||
| 30 | # ---------------------------------------------------------------------- | ||
| 31 | # | Config file for non-secure host | | ||
| 32 | # ---------------------------------------------------------------------- | ||
| 33 | server { | ||
| 34 | listen [::]:80; | ||
| 35 | listen 80; | ||
| 36 | server_name br.cleberg.net; | ||
| 37 | |||
| 38 | return 301 https://$host$request_uri; | ||
| 39 | } | ||
linux/nginx/etc/nginx/conf.d/bt.conf added +46
| @@ -0,0 +1,46 @@ | |||
| 1 | # ---------------------------------------------------------------------- | ||
| 2 | # | Config file for host | | ||
| 3 | # ---------------------------------------------------------------------- | ||
| 4 | server { | ||
| 5 | listen [::]:443 ssl; | ||
| 6 | listen 443 ssl; | ||
| 7 | http2 on; | ||
| 8 | |||
| 9 | server_name bt.cleberg.net; | ||
| 10 | |||
| 11 | include custom.d/tls/ssl_engine.conf; | ||
| 12 | include custom.d/tls/certificate_files.conf; | ||
| 13 | include custom.d/tls/policy_balanced.conf; | ||
| 14 | include custom.d/basic.conf; | ||
| 15 | |||
| 16 | # ---------------------------------------------------------------------- | ||
| 17 | # | Custom rules & config for specific website | | ||
| 18 | # ---------------------------------------------------------------------- | ||
| 19 | set $upstream http://127.0.0.1:9091; | ||
| 20 | |||
| 21 | location /authelia { | ||
| 22 | include custom.d/reverse_proxy/authelia.conf; | ||
| 23 | } | ||
| 24 | |||
| 25 | location / { | ||
| 26 | proxy_pass $upstream; | ||
| 27 | |||
| 28 | include custom.d/reverse_proxy/authelia_request.conf; | ||
| 29 | # include custom.d/reverse_proxy/basic.conf; | ||
| 30 | proxy_pass_header X-bt-Session-Id; | ||
| 31 | } | ||
| 32 | |||
| 33 | include custom.d/security/robots_index_only.conf; | ||
| 34 | # ---------------------------------------------------------------------- | ||
| 35 | } | ||
| 36 | |||
| 37 | # ---------------------------------------------------------------------- | ||
| 38 | # | Config file for non-secure host | | ||
| 39 | # ---------------------------------------------------------------------- | ||
| 40 | server { | ||
| 41 | listen [::]:80; | ||
| 42 | listen 80; | ||
| 43 | server_name bt.cleberg.net; | ||
| 44 | |||
| 45 | return 301 https://$host$request_uri; | ||
| 46 | } | ||
linux/nginx/etc/nginx/conf.d/bw.conf added +39
| @@ -0,0 +1,39 @@ | |||
| 1 | # ---------------------------------------------------------------------- | ||
| 2 | # | Config file for host | | ||
| 3 | # ---------------------------------------------------------------------- | ||
| 4 | server { | ||
| 5 | listen [::]:443 ssl; | ||
| 6 | listen 443 ssl; | ||
| 7 | http2 on; | ||
| 8 | |||
| 9 | server_name bw.cleberg.net; | ||
| 10 | |||
| 11 | include custom.d/tls/ssl_engine.conf; | ||
| 12 | include custom.d/tls/certificate_files.conf; | ||
| 13 | include custom.d/tls/policy_balanced.conf; | ||
| 14 | include custom.d/basic.conf; | ||
| 15 | |||
| 16 | # ---------------------------------------------------------------------- | ||
| 17 | # | Custom rules & config for specific website | | ||
| 18 | # ---------------------------------------------------------------------- | ||
| 19 | location / { | ||
| 20 | set $upstream http://127.0.0.1:10416; | ||
| 21 | proxy_pass $upstream; | ||
| 22 | |||
| 23 | include custom.d/reverse_proxy/basic.conf; | ||
| 24 | } | ||
| 25 | |||
| 26 | include custom.d/security/robots_index_only.conf; | ||
| 27 | # ---------------------------------------------------------------------- | ||
| 28 | } | ||
| 29 | |||
| 30 | # ---------------------------------------------------------------------- | ||
| 31 | # | Config file for non-secure host | | ||
| 32 | # ---------------------------------------------------------------------- | ||
| 33 | server { | ||
| 34 | listen [::]:80; | ||
| 35 | listen 80; | ||
| 36 | server_name bw.cleberg.net; | ||
| 37 | |||
| 38 | return 301 https://$host$request_uri; | ||
| 39 | } | ||
linux/nginx/etc/nginx/conf.d/cc.conf added +39
| @@ -0,0 +1,39 @@ | |||
| 1 | # ---------------------------------------------------------------------- | ||
| 2 | # | Config file for host | | ||
| 3 | # ---------------------------------------------------------------------- | ||
| 4 | server { | ||
| 5 | listen [::]:443 ssl; | ||
| 6 | listen 443 ssl; | ||
| 7 | http2 on; | ||
| 8 | |||
| 9 | server_name cc.cleberg.net; | ||
| 10 | |||
| 11 | include custom.d/tls/ssl_engine.conf; | ||
| 12 | include custom.d/tls/certificate_files.conf; | ||
| 13 | include custom.d/tls/policy_balanced.conf; | ||
| 14 | include custom.d/basic.conf; | ||
| 15 | |||
| 16 | # ---------------------------------------------------------------------- | ||
| 17 | # | Custom rules & config for specific website | | ||
| 18 | # ---------------------------------------------------------------------- | ||
| 19 | location / { | ||
| 20 | set $upstream http://127.0.0.1:8111; | ||
| 21 | proxy_pass $upstream; | ||
| 22 | |||
| 23 | include custom.d/reverse_proxy/basic.conf; | ||
| 24 | } | ||
| 25 | |||
| 26 | include custom.d/security/robots_index_only.conf; | ||
| 27 | # ---------------------------------------------------------------------- | ||
| 28 | } | ||
| 29 | |||
| 30 | # ---------------------------------------------------------------------- | ||
| 31 | # | Config file for non-secure host | | ||
| 32 | # ---------------------------------------------------------------------- | ||
| 33 | server { | ||
| 34 | listen [::]:80; | ||
| 35 | listen 80; | ||
| 36 | server_name cc.cleberg.net; | ||
| 37 | |||
| 38 | return 301 https://$host$request_uri; | ||
| 39 | } | ||
linux/nginx/etc/nginx/conf.d/cleberg.io added +54
| @@ -0,0 +1,54 @@ | |||
| 1 | # ---------------------------------------------------------------------- | ||
| 2 | # | Config file for host | | ||
| 3 | # ---------------------------------------------------------------------- | ||
| 4 | server { | ||
| 5 | listen [::]:443 ssl; | ||
| 6 | listen 443 ssl; | ||
| 7 | http2 on; | ||
| 8 | |||
| 9 | server_name www.cleberg.io cleberg.io; | ||
| 10 | |||
| 11 | include custom.d/tls/ssl_engine.conf; | ||
| 12 | include custom.d/tls/policy_balanced.conf; | ||
| 13 | # include custom.d/tls/certificate_files.conf; | ||
| 14 | ssl_certificate /etc/letsencrypt/live/cleberg.io/fullchain.pem; | ||
| 15 | ssl_certificate_key /etc/letsencrypt/live/cleberg.io/privkey.pem; | ||
| 16 | ssl_trusted_certificate /etc/letsencrypt/live/cleberg.io/chain.pem; | ||
| 17 | |||
| 18 | return 301 $scheme://cleberg.io$request_uri; | ||
| 19 | } | ||
| 20 | |||
| 21 | |||
| 22 | server { | ||
| 23 | listen [::]:443 ssl; | ||
| 24 | listen 443 ssl; | ||
| 25 | http2 on; | ||
| 26 | |||
| 27 | server_name cleberg.io; | ||
| 28 | |||
| 29 | include custom.d/tls/ssl_engine.conf; | ||
| 30 | include custom.d/tls/policy_balanced.conf; | ||
| 31 | include custom.d/basic.conf; | ||
| 32 | |||
| 33 | # include custom.d/tls/certificate_files.conf; | ||
| 34 | ssl_certificate /etc/letsencrypt/live/cleberg.io/fullchain.pem; | ||
| 35 | ssl_certificate_key /etc/letsencrypt/live/cleberg.io/privkey.pem; | ||
| 36 | ssl_trusted_certificate /etc/letsencrypt/live/cleberg.io/chain.pem; | ||
| 37 | |||
| 38 | # ---------------------------------------------------------------------- | ||
| 39 | # | Custom rules & config for specific website | | ||
| 40 | # ---------------------------------------------------------------------- | ||
| 41 | return 301 https://cleberg.net; | ||
| 42 | # ---------------------------------------------------------------------- | ||
| 43 | } | ||
| 44 | |||
| 45 | # ---------------------------------------------------------------------- | ||
| 46 | # | Config file for non-secure host | | ||
| 47 | # ---------------------------------------------------------------------- | ||
| 48 | server { | ||
| 49 | listen [::]:80; | ||
| 50 | listen 80; | ||
| 51 | server_name www.cleberg.io cleberg.io; | ||
| 52 | |||
| 53 | return 301 https://cleberg.io$request_uri; | ||
| 54 | } | ||
linux/nginx/etc/nginx/conf.d/cleberg.net.conf added +70
| @@ -0,0 +1,70 @@ | |||
| 1 | # ---------------------------------------------------------------------- | ||
| 2 | # | Config file for host | | ||
| 3 | # ---------------------------------------------------------------------- | ||
| 4 | server { | ||
| 5 | listen [::]:443 ssl; | ||
| 6 | listen 443 ssl; | ||
| 7 | http2 on; | ||
| 8 | |||
| 9 | server_name www.cleberg.net; | ||
| 10 | |||
| 11 | include custom.d/tls/ssl_engine.conf; | ||
| 12 | include custom.d/tls/certificate_files.conf; | ||
| 13 | include custom.d/tls/policy_balanced.conf; | ||
| 14 | |||
| 15 | return 301 $scheme://cleberg.net$request_uri; | ||
| 16 | } | ||
| 17 | |||
| 18 | |||
| 19 | server { | ||
| 20 | listen [::]:443 ssl; | ||
| 21 | listen 443 ssl; | ||
| 22 | http2 on; | ||
| 23 | |||
| 24 | server_name cleberg.net; | ||
| 25 | |||
| 26 | include custom.d/tls/ssl_engine.conf; | ||
| 27 | include custom.d/tls/certificate_files.conf; | ||
| 28 | include custom.d/tls/policy_balanced.conf; | ||
| 29 | include custom.d/basic.conf; | ||
| 30 | |||
| 31 | root /var/www/cleberg.net/; | ||
| 32 | |||
| 33 | # ---------------------------------------------------------------------- | ||
| 34 | # | Custom rules & config for specific website | | ||
| 35 | # ---------------------------------------------------------------------- | ||
| 36 | location / { | ||
| 37 | try_files $uri $uri/ =404; | ||
| 38 | } | ||
| 39 | |||
| 40 | # fix: redirect blog & wiki posts from "/" to ".html" | ||
| 41 | location /blog/ { | ||
| 42 | rewrite ^/blog/((?!index)[^/]+)/(.*)$ /blog/$1.html permanent; | ||
| 43 | } | ||
| 44 | |||
| 45 | location /wiki/ { | ||
| 46 | rewrite ^/wiki/((?!index)[^/]+)/(.*)$ /wiki/$1.html permanent; | ||
| 47 | } | ||
| 48 | |||
| 49 | # fix: redirect atom.xml to feed.xml | ||
| 50 | location /atom.xml { | ||
| 51 | return 301 $scheme://$host/feed.xml; | ||
| 52 | } | ||
| 53 | |||
| 54 | # fix: redirect salary page | ||
| 55 | location /blog/salary-transparency.html { | ||
| 56 | return 301 $scheme://$host/salary/; | ||
| 57 | } | ||
| 58 | # ---------------------------------------------------------------------- | ||
| 59 | } | ||
| 60 | |||
| 61 | # ---------------------------------------------------------------------- | ||
| 62 | # | Config file for non-secure host | | ||
| 63 | # ---------------------------------------------------------------------- | ||
| 64 | server { | ||
| 65 | listen [::]:80; | ||
| 66 | listen 80; | ||
| 67 | server_name www.cleberg.net cleberg.net; | ||
| 68 | |||
| 69 | return 301 https://cleberg.net$request_uri; | ||
| 70 | } | ||
linux/nginx/etc/nginx/conf.d/cv.conf added +37
| @@ -0,0 +1,37 @@ | |||
| 1 | # ---------------------------------------------------------------------- | ||
| 2 | # | Config file for host | | ||
| 3 | # ---------------------------------------------------------------------- | ||
| 4 | server { | ||
| 5 | listen [::]:443 ssl; | ||
| 6 | listen 443 ssl; | ||
| 7 | http2 on; | ||
| 8 | |||
| 9 | server_name cv.cleberg.net; | ||
| 10 | |||
| 11 | include custom.d/tls/ssl_engine.conf; | ||
| 12 | include custom.d/tls/certificate_files.conf; | ||
| 13 | include custom.d/tls/policy_balanced.conf; | ||
| 14 | include custom.d/basic.conf; | ||
| 15 | |||
| 16 | root /var/www/cv/; | ||
| 17 | autoindex on; | ||
| 18 | |||
| 19 | # ---------------------------------------------------------------------- | ||
| 20 | # | Custom rules & config for specific website | | ||
| 21 | # ---------------------------------------------------------------------- | ||
| 22 | location / { | ||
| 23 | try_files $uri $uri/ /index.html; | ||
| 24 | } | ||
| 25 | # ---------------------------------------------------------------------- | ||
| 26 | } | ||
| 27 | |||
| 28 | # ---------------------------------------------------------------------- | ||
| 29 | # | Config file for non-secure host | | ||
| 30 | # ---------------------------------------------------------------------- | ||
| 31 | server { | ||
| 32 | listen [::]:80; | ||
| 33 | listen 80; | ||
| 34 | server_name cv.cleberg.net; | ||
| 35 | |||
| 36 | return 301 https://$host$request_uri; | ||
| 37 | } | ||
linux/nginx/etc/nginx/conf.d/ddns.conf added +44
| @@ -0,0 +1,44 @@ | |||
| 1 | # ---------------------------------------------------------------------- | ||
| 2 | # | Config file for host | | ||
| 3 | # ---------------------------------------------------------------------- | ||
| 4 | server { | ||
| 5 | listen [::]:443 ssl; | ||
| 6 | listen 443 ssl; | ||
| 7 | http2 on; | ||
| 8 | |||
| 9 | server_name ddns.cleberg.net; | ||
| 10 | |||
| 11 | include custom.d/tls/ssl_engine.conf; | ||
| 12 | include custom.d/tls/certificate_files.conf; | ||
| 13 | include custom.d/tls/policy_balanced.conf; | ||
| 14 | include custom.d/basic.conf; | ||
| 15 | |||
| 16 | # ---------------------------------------------------------------------- | ||
| 17 | # | Custom rules & config for specific website | | ||
| 18 | # ---------------------------------------------------------------------- | ||
| 19 | location /authelia { | ||
| 20 | include custom.d/reverse_proxy/authelia.conf; | ||
| 21 | } | ||
| 22 | |||
| 23 | location / { | ||
| 24 | set $upstream http://127.0.0.1:8097; | ||
| 25 | proxy_pass $upstream; | ||
| 26 | |||
| 27 | include custom.d/reverse_proxy/authelia_request.conf; | ||
| 28 | include custom.d/reverse_proxy/basic.conf; | ||
| 29 | } | ||
| 30 | |||
| 31 | include custom.d/security/robots_index_only.conf; | ||
| 32 | # ---------------------------------------------------------------------- | ||
| 33 | } | ||
| 34 | |||
| 35 | # ---------------------------------------------------------------------- | ||
| 36 | # | Config file for non-secure host | | ||
| 37 | # ---------------------------------------------------------------------- | ||
| 38 | server { | ||
| 39 | listen [::]:80; | ||
| 40 | listen 80; | ||
| 41 | server_name ddns.cleberg.net; | ||
| 42 | |||
| 43 | return 301 https://$host$request_uri; | ||
| 44 | } | ||
linux/nginx/etc/nginx/conf.d/default.conf added +33
| @@ -0,0 +1,33 @@ | |||
| 1 | # ---------------------------------------------------------------------- | ||
| 2 | # | Default behavior for unknown hosts | | ||
| 3 | # ---------------------------------------------------------------------- | ||
| 4 | # | ||
| 5 | # Drop requests for unknown hosts. | ||
| 6 | # | ||
| 7 | # If no default server is defined, Nginx will use the first found server. | ||
| 8 | # To prevent host header attacks, or other potential problems when an unknown | ||
| 9 | # server name is used in a request, it's recommended to drop the request | ||
| 10 | # returning 444 "No Response". | ||
| 11 | |||
| 12 | server { | ||
| 13 | listen [::]:443 ssl default_server; | ||
| 14 | listen 443 ssl default_server; | ||
| 15 | http2 on; | ||
| 16 | |||
| 17 | server_name _; | ||
| 18 | |||
| 19 | include custom.d/tls/ssl_engine.conf; | ||
| 20 | include custom.d/tls/certificate_files.conf; | ||
| 21 | include custom.d/tls/policy_balanced.conf; | ||
| 22 | |||
| 23 | return 444; | ||
| 24 | } | ||
| 25 | |||
| 26 | server { | ||
| 27 | listen [::]:80; | ||
| 28 | listen 80; | ||
| 29 | |||
| 30 | server_name _; | ||
| 31 | |||
| 32 | return 444; | ||
| 33 | } | ||
linux/nginx/etc/nginx/conf.d/docker.conf added +44
| @@ -0,0 +1,44 @@ | |||
| 1 | # ---------------------------------------------------------------------- | ||
| 2 | # | Config file for host | | ||
| 3 | # ---------------------------------------------------------------------- | ||
| 4 | server { | ||
| 5 | listen [::]:443 ssl; | ||
| 6 | listen 443 ssl; | ||
| 7 | http2 on; | ||
| 8 | |||
| 9 | server_name docker.cleberg.net; | ||
| 10 | |||
| 11 | include custom.d/tls/ssl_engine.conf; | ||
| 12 | include custom.d/tls/certificate_files.conf; | ||
| 13 | include custom.d/tls/policy_balanced.conf; | ||
| 14 | include custom.d/basic.conf; | ||
| 15 | |||
| 16 | # ---------------------------------------------------------------------- | ||
| 17 | # | Custom rules & config for specific website | | ||
| 18 | # ---------------------------------------------------------------------- | ||
| 19 | location /authelia { | ||
| 20 | include custom.d/reverse_proxy/authelia.conf; | ||
| 21 | } | ||
| 22 | |||
| 23 | location / { | ||
| 24 | set $upstream http://127.0.0.1:3777; | ||
| 25 | proxy_pass $upstream; | ||
| 26 | |||
| 27 | include custom.d/reverse_proxy/authelia_request.conf; | ||
| 28 | include custom.d/reverse_proxy/basic.conf; | ||
| 29 | } | ||
| 30 | |||
| 31 | include custom.d/security/robots_index_only.conf; | ||
| 32 | # ---------------------------------------------------------------------- | ||
| 33 | } | ||
| 34 | |||
| 35 | # ---------------------------------------------------------------------- | ||
| 36 | # | Config file for non-secure host | | ||
| 37 | # ---------------------------------------------------------------------- | ||
| 38 | server { | ||
| 39 | listen [::]:80; | ||
| 40 | listen 80; | ||
| 41 | server_name docker.cleberg.net; | ||
| 42 | |||
| 43 | return 301 https://$host$request_uri; | ||
| 44 | } | ||
linux/nginx/etc/nginx/conf.d/files.conf added +40
| @@ -0,0 +1,40 @@ | |||
| 1 | # ---------------------------------------------------------------------- | ||
| 2 | # | Config file for files.cleberg.net host | | ||
| 3 | # ---------------------------------------------------------------------- | ||
| 4 | server { | ||
| 5 | listen [::]:443 ssl; | ||
| 6 | listen 443 ssl; | ||
| 7 | http2 on; | ||
| 8 | |||
| 9 | # The host name to respond to | ||
| 10 | server_name files.cleberg.net; | ||
| 11 | |||
| 12 | include custom.d/tls/ssl_engine.conf; | ||
| 13 | include custom.d/tls/certificate_files.conf; | ||
| 14 | include custom.d/tls/policy_balanced.conf; | ||
| 15 | include custom.d/basic.conf; | ||
| 16 | |||
| 17 | root /var/www/files/; | ||
| 18 | autoindex on; | ||
| 19 | |||
| 20 | # Include the basic custom.d config set | ||
| 21 | |||
| 22 | # ---------------------------------------------------------------------- | ||
| 23 | # | Custom rules & config for specific website | | ||
| 24 | # ---------------------------------------------------------------------- | ||
| 25 | location / { | ||
| 26 | try_files $uri $uri/ /index.html; | ||
| 27 | } | ||
| 28 | # ---------------------------------------------------------------------- | ||
| 29 | } | ||
| 30 | |||
| 31 | # ---------------------------------------------------------------------- | ||
| 32 | # | Config file for non-secure cleberg.net host | | ||
| 33 | # ---------------------------------------------------------------------- | ||
| 34 | server { | ||
| 35 | listen [::]:80; | ||
| 36 | listen 80; | ||
| 37 | server_name files.cleberg.net; | ||
| 38 | |||
| 39 | return 301 https://$host$request_uri; | ||
| 40 | } | ||
linux/nginx/etc/nginx/conf.d/gh.conf added +39
| @@ -0,0 +1,39 @@ | |||
| 1 | # ---------------------------------------------------------------------- | ||
| 2 | # | Config file for host | | ||
| 3 | # ---------------------------------------------------------------------- | ||
| 4 | server { | ||
| 5 | listen [::]:443 ssl; | ||
| 6 | listen 443 ssl; | ||
| 7 | http2 on; | ||
| 8 | |||
| 9 | server_name gh.cleberg.net; | ||
| 10 | |||
| 11 | include custom.d/tls/ssl_engine.conf; | ||
| 12 | include custom.d/tls/certificate_files.conf; | ||
| 13 | include custom.d/tls/policy_balanced.conf; | ||
| 14 | include custom.d/basic.conf; | ||
| 15 | |||
| 16 | # ---------------------------------------------------------------------- | ||
| 17 | # | Custom rules & config for specific website | | ||
| 18 | # ---------------------------------------------------------------------- | ||
| 19 | location / { | ||
| 20 | set $upstream http://192.168.0.251:3039; | ||
| 21 | proxy_pass $upstream; | ||
| 22 | |||
| 23 | include custom.d/reverse_proxy/basic.conf; | ||
| 24 | } | ||
| 25 | |||
| 26 | include custom.d/security/robots_index_only.conf; | ||
| 27 | # ---------------------------------------------------------------------- | ||
| 28 | } | ||
| 29 | |||
| 30 | # ---------------------------------------------------------------------- | ||
| 31 | # | Config file for non-secure host | | ||
| 32 | # ---------------------------------------------------------------------- | ||
| 33 | server { | ||
| 34 | listen [::]:80; | ||
| 35 | listen 80; | ||
| 36 | server_name gh.cleberg.net; | ||
| 37 | |||
| 38 | return 301 https://$host$request_uri; | ||
| 39 | } | ||
linux/nginx/etc/nginx/conf.d/ha.conf added +46
| @@ -0,0 +1,46 @@ | |||
| 1 | # ---------------------------------------------------------------------- | ||
| 2 | # | Config file for host | | ||
| 3 | # ---------------------------------------------------------------------- | ||
| 4 | server { | ||
| 5 | listen [::]:443 ssl; | ||
| 6 | listen 443 ssl; | ||
| 7 | http2 on; | ||
| 8 | |||
| 9 | server_name ha.cleberg.net; | ||
| 10 | |||
| 11 | include custom.d/tls/ssl_engine.conf; | ||
| 12 | include custom.d/tls/certificate_files.conf; | ||
| 13 | include custom.d/tls/policy_balanced.conf; | ||
| 14 | include custom.d/basic.conf; | ||
| 15 | |||
| 16 | # ---------------------------------------------------------------------- | ||
| 17 | # | Custom rules & config for specific website | | ||
| 18 | # ---------------------------------------------------------------------- | ||
| 19 | set $upstream http://192.168.0.214:8123; | ||
| 20 | |||
| 21 | location / { | ||
| 22 | proxy_pass $upstream; | ||
| 23 | proxy_set_header X-Forwarded-For $remote_addr; | ||
| 24 | } | ||
| 25 | |||
| 26 | location /api/websocket { | ||
| 27 | proxy_pass $upstream; | ||
| 28 | proxy_http_version 1.1; | ||
| 29 | proxy_set_header Upgrade $http_upgrade; | ||
| 30 | proxy_set_header Connection "upgrade"; | ||
| 31 | } | ||
| 32 | |||
| 33 | include custom.d/security/robots_index_only.conf; | ||
| 34 | # ---------------------------------------------------------------------- | ||
| 35 | } | ||
| 36 | |||
| 37 | # ---------------------------------------------------------------------- | ||
| 38 | # | Config file for non-secure host | | ||
| 39 | # ---------------------------------------------------------------------- | ||
| 40 | server { | ||
| 41 | listen [::]:80; | ||
| 42 | listen 80; | ||
| 43 | server_name ha.cleberg.net; | ||
| 44 | |||
| 45 | return 301 https://$host$request_uri; | ||
| 46 | } | ||
linux/nginx/etc/nginx/conf.d/hat.conf added +39
| @@ -0,0 +1,39 @@ | |||
| 1 | # ---------------------------------------------------------------------- | ||
| 2 | # | Config file for host | | ||
| 3 | # ---------------------------------------------------------------------- | ||
| 4 | server { | ||
| 5 | listen [::]:443 ssl; | ||
| 6 | listen 443 ssl; | ||
| 7 | http2 on; | ||
| 8 | |||
| 9 | server_name hat.cleberg.net; | ||
| 10 | |||
| 11 | include custom.d/tls/ssl_engine.conf; | ||
| 12 | include custom.d/tls/certificate_files.conf; | ||
| 13 | include custom.d/tls/policy_balanced.conf; | ||
| 14 | include custom.d/basic.conf; | ||
| 15 | |||
| 16 | # ---------------------------------------------------------------------- | ||
| 17 | # | Custom rules & config for specific website | | ||
| 18 | # ---------------------------------------------------------------------- | ||
| 19 | location / { | ||
| 20 | set $upstream http://192.168.0.251:3991; | ||
| 21 | proxy_pass $upstream; | ||
| 22 | |||
| 23 | include custom.d/reverse_proxy/basic.conf; | ||
| 24 | } | ||
| 25 | |||
| 26 | include custom.d/security/robots_index_only.conf; | ||
| 27 | # ---------------------------------------------------------------------- | ||
| 28 | } | ||
| 29 | |||
| 30 | # ---------------------------------------------------------------------- | ||
| 31 | # | Config file for non-secure host | | ||
| 32 | # ---------------------------------------------------------------------- | ||
| 33 | server { | ||
| 34 | listen [::]:80; | ||
| 35 | listen 80; | ||
| 36 | server_name hat.cleberg.net; | ||
| 37 | |||
| 38 | return 301 https://$host$request_uri; | ||
| 39 | } | ||
linux/nginx/etc/nginx/conf.d/hn.conf added +27
| @@ -0,0 +1,27 @@ | |||
| 1 | server { | ||
| 2 | listen [::]:443 ssl; | ||
| 3 | listen 443 ssl; | ||
| 4 | http2 on; | ||
| 5 | |||
| 6 | server_name hn.cleberg.net r3yfeffyj7ornpikojmw75u3sn2la7tqnmcmwgv2ov7if24sm5czqeid.onion; | ||
| 7 | root /var/www/hn/output/; | ||
| 8 | autoindex on; | ||
| 9 | add_header Onion-Location http://r3yfeffyj7ornpikojmw75u3sn2la7tqnmcmwgv2ov7if24sm5czqeid.onion; | ||
| 10 | |||
| 11 | include custom.d/tls/ssl_engine.conf; | ||
| 12 | include custom.d/tls/certificate_files.conf; | ||
| 13 | include custom.d/tls/policy_balanced.conf; | ||
| 14 | include custom.d/basic.conf; | ||
| 15 | |||
| 16 | location / { | ||
| 17 | try_files $uri $uri/ /index.html; | ||
| 18 | } | ||
| 19 | } | ||
| 20 | |||
| 21 | server { | ||
| 22 | listen [::]:80; | ||
| 23 | listen 80; | ||
| 24 | server_name hn.cleberg.net; | ||
| 25 | |||
| 26 | return 301 https://$host$request_uri; | ||
| 27 | } | ||
linux/nginx/etc/nginx/conf.d/img.conf added +37
| @@ -0,0 +1,37 @@ | |||
| 1 | # ---------------------------------------------------------------------- | ||
| 2 | # | Config file for host | | ||
| 3 | # ---------------------------------------------------------------------- | ||
| 4 | server { | ||
| 5 | listen [::]:443 ssl; | ||
| 6 | listen 443 ssl; | ||
| 7 | http2 on; | ||
| 8 | |||
| 9 | server_name img.cleberg.net; | ||
| 10 | |||
| 11 | include custom.d/tls/ssl_engine.conf; | ||
| 12 | include custom.d/tls/certificate_files.conf; | ||
| 13 | include custom.d/tls/policy_balanced.conf; | ||
| 14 | include custom.d/basic.conf; | ||
| 15 | |||
| 16 | root /var/www/img/; | ||
| 17 | autoindex on; | ||
| 18 | |||
| 19 | # ---------------------------------------------------------------------- | ||
| 20 | # | Custom rules & config for specific website | | ||
| 21 | # ---------------------------------------------------------------------- | ||
| 22 | location / { | ||
| 23 | try_files $uri $uri/ =404; | ||
| 24 | } | ||
| 25 | # ---------------------------------------------------------------------- | ||
| 26 | } | ||
| 27 | |||
| 28 | # ---------------------------------------------------------------------- | ||
| 29 | # | Config file for non-secure host | | ||
| 30 | # ---------------------------------------------------------------------- | ||
| 31 | server { | ||
| 32 | listen [::]:80; | ||
| 33 | listen 80; | ||
| 34 | server_name img.cleberg.net; | ||
| 35 | |||
| 36 | return 301 https://img.cleberg.net$request_uri; | ||
| 37 | } | ||
linux/nginx/etc/nginx/conf.d/irc.conf added +44
| @@ -0,0 +1,44 @@ | |||
| 1 | # ---------------------------------------------------------------------- | ||
| 2 | # | Config file for host | | ||
| 3 | # ---------------------------------------------------------------------- | ||
| 4 | server { | ||
| 5 | listen [::]:443 ssl; | ||
| 6 | listen 443 ssl; | ||
| 7 | http2 on; | ||
| 8 | |||
| 9 | server_name irc.cleberg.net; | ||
| 10 | |||
| 11 | include custom.d/tls/ssl_engine.conf; | ||
| 12 | include custom.d/tls/certificate_files.conf; | ||
| 13 | include custom.d/tls/policy_balanced.conf; | ||
| 14 | include custom.d/basic.conf; | ||
| 15 | |||
| 16 | # ---------------------------------------------------------------------- | ||
| 17 | # | Custom rules & config for specific website | | ||
| 18 | # ---------------------------------------------------------------------- | ||
| 19 | location /authelia { | ||
| 20 | include custom.d/reverse_proxy/authelia.conf; | ||
| 21 | } | ||
| 22 | |||
| 23 | location / { | ||
| 24 | set $upstream http://192.168.0.251:9900; | ||
| 25 | proxy_pass $upstream; | ||
| 26 | |||
| 27 | include custom.d/reverse_proxy/authelia_request.conf; | ||
| 28 | include custom.d/reverse_proxy/basic.conf; | ||
| 29 | } | ||
| 30 | |||
| 31 | include custom.d/security/robots_index_only.conf; | ||
| 32 | # ---------------------------------------------------------------------- | ||
| 33 | } | ||
| 34 | |||
| 35 | # ---------------------------------------------------------------------- | ||
| 36 | # | Config file for non-secure host | | ||
| 37 | # ---------------------------------------------------------------------- | ||
| 38 | server { | ||
| 39 | listen [::]:80; | ||
| 40 | listen 80; | ||
| 41 | server_name irc.cleberg.net; | ||
| 42 | |||
| 43 | return 301 https://$host$request_uri; | ||
| 44 | } | ||
linux/nginx/etc/nginx/conf.d/ld.conf added +39
| @@ -0,0 +1,39 @@ | |||
| 1 | # ---------------------------------------------------------------------- | ||
| 2 | # | Config file for host | | ||
| 3 | # ---------------------------------------------------------------------- | ||
| 4 | server { | ||
| 5 | listen [::]:443 ssl; | ||
| 6 | listen 443 ssl; | ||
| 7 | http2 on; | ||
| 8 | |||
| 9 | server_name ld.cleberg.net; | ||
| 10 | |||
| 11 | include custom.d/tls/ssl_engine.conf; | ||
| 12 | include custom.d/tls/certificate_files.conf; | ||
| 13 | include custom.d/tls/policy_balanced.conf; | ||
| 14 | include custom.d/basic.conf; | ||
| 15 | |||
| 16 | # ---------------------------------------------------------------------- | ||
| 17 | # | Custom rules & config for specific website | | ||
| 18 | # ---------------------------------------------------------------------- | ||
| 19 | location / { | ||
| 20 | set $upstream http://127.0.0.1:3004; | ||
| 21 | proxy_pass $upstream; | ||
| 22 | |||
| 23 | include custom.d/reverse_proxy/basic.conf; | ||
| 24 | } | ||
| 25 | |||
| 26 | include custom.d/security/robots_index_only.conf; | ||
| 27 | # ---------------------------------------------------------------------- | ||
| 28 | } | ||
| 29 | |||
| 30 | # ---------------------------------------------------------------------- | ||
| 31 | # | Config file for non-secure host | | ||
| 32 | # ---------------------------------------------------------------------- | ||
| 33 | server { | ||
| 34 | listen [::]:80; | ||
| 35 | listen 80; | ||
| 36 | server_name ld.cleberg.net; | ||
| 37 | |||
| 38 | return 301 https://$host$request_uri; | ||
| 39 | } | ||
linux/nginx/etc/nginx/conf.d/lemmy.conf added +39
| @@ -0,0 +1,39 @@ | |||
| 1 | # ---------------------------------------------------------------------- | ||
| 2 | # | Config file for host | | ||
| 3 | # ---------------------------------------------------------------------- | ||
| 4 | server { | ||
| 5 | listen [::]:443 ssl; | ||
| 6 | listen 443 ssl; | ||
| 7 | http2 on; | ||
| 8 | |||
| 9 | server_name lemmy.cleberg.net; | ||
| 10 | |||
| 11 | include custom.d/tls/ssl_engine.conf; | ||
| 12 | include custom.d/tls/certificate_files.conf; | ||
| 13 | include custom.d/tls/policy_balanced.conf; | ||
| 14 | include custom.d/basic.conf; | ||
| 15 | |||
| 16 | # ---------------------------------------------------------------------- | ||
| 17 | # | Custom rules & config for specific website | | ||
| 18 | # ---------------------------------------------------------------------- | ||
| 19 | location / { | ||
| 20 | set $upstream http://127.0.0.1:10633; | ||
| 21 | proxy_pass $upstream; | ||
| 22 | |||
| 23 | include custom.d/reverse_proxy/basic.conf; | ||
| 24 | } | ||
| 25 | |||
| 26 | include custom.d/security/robots_index_only.conf; | ||
| 27 | # ---------------------------------------------------------------------- | ||
| 28 | } | ||
| 29 | |||
| 30 | # ---------------------------------------------------------------------- | ||
| 31 | # | Config file for non-secure host | | ||
| 32 | # ---------------------------------------------------------------------- | ||
| 33 | server { | ||
| 34 | listen [::]:80; | ||
| 35 | listen 80; | ||
| 36 | server_name lemmy.cleberg.net; | ||
| 37 | |||
| 38 | return 301 https://$host$request_uri; | ||
| 39 | } | ||
linux/nginx/etc/nginx/conf.d/lt.conf added +39
| @@ -0,0 +1,39 @@ | |||
| 1 | # ---------------------------------------------------------------------- | ||
| 2 | # | Config file for host | | ||
| 3 | # ---------------------------------------------------------------------- | ||
| 4 | server { | ||
| 5 | listen [::]:443 ssl; | ||
| 6 | listen 443 ssl; | ||
| 7 | http2 on; | ||
| 8 | |||
| 9 | server_name lt.cleberg.net; | ||
| 10 | |||
| 11 | include custom.d/tls/ssl_engine.conf; | ||
| 12 | include custom.d/tls/certificate_files.conf; | ||
| 13 | include custom.d/tls/policy_balanced.conf; | ||
| 14 | include custom.d/basic.conf; | ||
| 15 | |||
| 16 | # ---------------------------------------------------------------------- | ||
| 17 | # | Custom rules & config for specific website | | ||
| 18 | # ---------------------------------------------------------------------- | ||
| 19 | location / { | ||
| 20 | set $upstream http://127.0.0.1:5000; | ||
| 21 | proxy_pass $upstream; | ||
| 22 | |||
| 23 | include custom.d/reverse_proxy/basic.conf; | ||
| 24 | } | ||
| 25 | |||
| 26 | include custom.d/security/robots_index_only.conf; | ||
| 27 | # ---------------------------------------------------------------------- | ||
| 28 | } | ||
| 29 | |||
| 30 | # ---------------------------------------------------------------------- | ||
| 31 | # | Config file for non-secure host | | ||
| 32 | # ---------------------------------------------------------------------- | ||
| 33 | server { | ||
| 34 | listen [::]:80; | ||
| 35 | listen 80; | ||
| 36 | server_name lt.cleberg.net; | ||
| 37 | |||
| 38 | return 301 https://$host$request_uri; | ||
| 39 | } | ||
linux/nginx/etc/nginx/conf.d/mz.conf added +39
| @@ -0,0 +1,39 @@ | |||
| 1 | # ---------------------------------------------------------------------- | ||
| 2 | # | Config file for host | | ||
| 3 | # ---------------------------------------------------------------------- | ||
| 4 | server { | ||
| 5 | listen [::]:443 ssl; | ||
| 6 | listen 443 ssl; | ||
| 7 | http2 on; | ||
| 8 | |||
| 9 | server_name mz.cleberg.net; | ||
| 10 | |||
| 11 | include custom.d/tls/ssl_engine.conf; | ||
| 12 | include custom.d/tls/certificate_files.conf; | ||
| 13 | include custom.d/tls/policy_balanced.conf; | ||
| 14 | include custom.d/basic.conf; | ||
| 15 | |||
| 16 | # ---------------------------------------------------------------------- | ||
| 17 | # | Custom rules & config for specific website | | ||
| 18 | # ---------------------------------------------------------------------- | ||
| 19 | location / { | ||
| 20 | set $upstream http://127.0.0.1:3474; | ||
| 21 | proxy_pass $upstream; | ||
| 22 | |||
| 23 | include custom.d/reverse_proxy/basic.conf; | ||
| 24 | } | ||
| 25 | |||
| 26 | include custom.d/security/robots_index_only.conf; | ||
| 27 | # ---------------------------------------------------------------------- | ||
| 28 | } | ||
| 29 | |||
| 30 | # ---------------------------------------------------------------------- | ||
| 31 | # | Config file for non-secure host | | ||
| 32 | # ---------------------------------------------------------------------- | ||
| 33 | server { | ||
| 34 | listen [::]:80; | ||
| 35 | listen 80; | ||
| 36 | server_name mz.cleberg.net; | ||
| 37 | |||
| 38 | return 301 https://$host$request_uri; | ||
| 39 | } | ||
linux/nginx/etc/nginx/conf.d/no-ssl.default.conf added +27
| @@ -0,0 +1,27 @@ | |||
| 1 | # ---------------------------------------------------------------------- | ||
| 2 | # | Default behavior for unknown hosts | | ||
| 3 | # ---------------------------------------------------------------------- | ||
| 4 | # | ||
| 5 | # Drop requests for unknown hosts. | ||
| 6 | # | ||
| 7 | # If no default server is defined, Nginx will use the first found server. | ||
| 8 | # To prevent host header attacks, or other potential problems when an unknown | ||
| 9 | # server name is used in a request, it's recommended to drop the request | ||
| 10 | # returning 444 "No Response". | ||
| 11 | # | ||
| 12 | # (1) In production, only secure hosts should be used (all `no-ssl` disabled). | ||
| 13 | # If so, redirect first ANY request to a secure connection before handling | ||
| 14 | # it, even if the host is unknown. | ||
| 15 | # | ||
| 16 | # https://observatory.mozilla.org/faq/ | ||
| 17 | |||
| 18 | server { | ||
| 19 | listen [::]:80 default_server deferred; | ||
| 20 | listen 80 default_server deferred; | ||
| 21 | |||
| 22 | server_name _; | ||
| 23 | |||
| 24 | # (1) | ||
| 25 | return 301 https://$host$request_uri; | ||
| 26 | # return 444; | ||
| 27 | } | ||
linux/nginx/etc/nginx/conf.d/office.conf added +35
| @@ -0,0 +1,35 @@ | |||
| 1 | # ---------------------------------------------------------------------- | ||
| 2 | # | Config file for host | | ||
| 3 | # ---------------------------------------------------------------------- | ||
| 4 | server { | ||
| 5 | listen [::]:443 ssl; | ||
| 6 | listen 443 ssl; | ||
| 7 | http2 on; | ||
| 8 | |||
| 9 | server_name office.cleberg.net; | ||
| 10 | root /var/www/office/; | ||
| 11 | |||
| 12 | include custom.d/tls/ssl_engine.conf; | ||
| 13 | include custom.d/tls/certificate_files.conf; | ||
| 14 | include custom.d/tls/policy_balanced.conf; | ||
| 15 | include custom.d/basic.conf; | ||
| 16 | |||
| 17 | # ---------------------------------------------------------------------- | ||
| 18 | # | Custom rules & config for specific website | | ||
| 19 | # ---------------------------------------------------------------------- | ||
| 20 | location / { | ||
| 21 | try_files $uri $uri/ /index.html; | ||
| 22 | } | ||
| 23 | # ---------------------------------------------------------------------- | ||
| 24 | } | ||
| 25 | |||
| 26 | # ---------------------------------------------------------------------- | ||
| 27 | # | Config file for non-secure host | | ||
| 28 | # ---------------------------------------------------------------------- | ||
| 29 | server { | ||
| 30 | listen [::]:80; | ||
| 31 | listen 80; | ||
| 32 | server_name office.cleberg.net; | ||
| 33 | |||
| 34 | return 301 https://$host$request_uri; | ||
| 35 | } | ||
linux/nginx/etc/nginx/conf.d/org.conf added +35
| @@ -0,0 +1,35 @@ | |||
| 1 | # ---------------------------------------------------------------------- | ||
| 2 | # | Config file for host | | ||
| 3 | # ---------------------------------------------------------------------- | ||
| 4 | server { | ||
| 5 | listen [::]:443 ssl; | ||
| 6 | listen 443 ssl; | ||
| 7 | http2 on; | ||
| 8 | |||
| 9 | server_name org.cleberg.net; | ||
| 10 | root /var/www/org/; | ||
| 11 | |||
| 12 | include custom.d/tls/ssl_engine.conf; | ||
| 13 | include custom.d/tls/certificate_files.conf; | ||
| 14 | include custom.d/tls/policy_balanced.conf; | ||
| 15 | include custom.d/basic.conf; | ||
| 16 | |||
| 17 | # ---------------------------------------------------------------------- | ||
| 18 | # | Custom rules & config for specific website | | ||
| 19 | # ---------------------------------------------------------------------- | ||
| 20 | location / { | ||
| 21 | try_files $uri $uri/ /index.html; | ||
| 22 | } | ||
| 23 | # ---------------------------------------------------------------------- | ||
| 24 | } | ||
| 25 | |||
| 26 | # ---------------------------------------------------------------------- | ||
| 27 | # | Config file for non-secure host | | ||
| 28 | # ---------------------------------------------------------------------- | ||
| 29 | server { | ||
| 30 | listen [::]:80; | ||
| 31 | listen 80; | ||
| 32 | server_name org.cleberg.net; | ||
| 33 | |||
| 34 | return 301 https://$host$request_uri; | ||
| 35 | } | ||
linux/nginx/etc/nginx/conf.d/paste.conf added +39
| @@ -0,0 +1,39 @@ | |||
| 1 | # ---------------------------------------------------------------------- | ||
| 2 | # | Config file for host | | ||
| 3 | # ---------------------------------------------------------------------- | ||
| 4 | server { | ||
| 5 | listen [::]:443 ssl; | ||
| 6 | listen 443 ssl; | ||
| 7 | http2 on; | ||
| 8 | |||
| 9 | server_name paste.cleberg.net; | ||
| 10 | |||
| 11 | include custom.d/tls/ssl_engine.conf; | ||
| 12 | include custom.d/tls/certificate_files.conf; | ||
| 13 | include custom.d/tls/policy_balanced.conf; | ||
| 14 | include custom.d/basic.conf; | ||
| 15 | |||
| 16 | # ---------------------------------------------------------------------- | ||
| 17 | # | Custom rules & config for specific website | | ||
| 18 | # ---------------------------------------------------------------------- | ||
| 19 | location / { | ||
| 20 | set $upstream http://127.0.0.1:8084; | ||
| 21 | proxy_pass $upstream; | ||
| 22 | |||
| 23 | include custom.d/reverse_proxy/basic.conf; | ||
| 24 | } | ||
| 25 | |||
| 26 | include custom.d/security/robots_index_only.conf; | ||
| 27 | # ---------------------------------------------------------------------- | ||
| 28 | } | ||
| 29 | |||
| 30 | # ---------------------------------------------------------------------- | ||
| 31 | # | Config file for non-secure host | | ||
| 32 | # ---------------------------------------------------------------------- | ||
| 33 | server { | ||
| 34 | listen [::]:80; | ||
| 35 | listen 80; | ||
| 36 | server_name paste.cleberg.net; | ||
| 37 | |||
| 38 | return 301 https://$host$request_uri; | ||
| 39 | } | ||
linux/nginx/etc/nginx/conf.d/pb.conf added +39
| @@ -0,0 +1,39 @@ | |||
| 1 | # ---------------------------------------------------------------------- | ||
| 2 | # | Config file for host | | ||
| 3 | # ---------------------------------------------------------------------- | ||
| 4 | server { | ||
| 5 | listen [::]:443 ssl; | ||
| 6 | listen 443 ssl; | ||
| 7 | http2 on; | ||
| 8 | |||
| 9 | server_name pb.cleberg.net; | ||
| 10 | |||
| 11 | include custom.d/tls/ssl_engine.conf; | ||
| 12 | include custom.d/tls/certificate_files.conf; | ||
| 13 | include custom.d/tls/policy_balanced.conf; | ||
| 14 | include custom.d/basic.conf; | ||
| 15 | |||
| 16 | # ---------------------------------------------------------------------- | ||
| 17 | # | Custom rules & config for specific website | | ||
| 18 | # ---------------------------------------------------------------------- | ||
| 19 | location / { | ||
| 20 | set $upstream http://127.0.0.1:8745; | ||
| 21 | proxy_pass $upstream; | ||
| 22 | |||
| 23 | include custom.d/reverse_proxy/basic.conf; | ||
| 24 | } | ||
| 25 | |||
| 26 | # include custom.d/security/robots_index_only.conf; | ||
| 27 | # ---------------------------------------------------------------------- | ||
| 28 | } | ||
| 29 | |||
| 30 | # ---------------------------------------------------------------------- | ||
| 31 | # | Config file for non-secure host | | ||
| 32 | # ---------------------------------------------------------------------- | ||
| 33 | server { | ||
| 34 | listen [::]:80; | ||
| 35 | listen 80; | ||
| 36 | server_name pb.cleberg.net; | ||
| 37 | |||
| 38 | return 301 https://$host$request_uri; | ||
| 39 | } | ||
linux/nginx/etc/nginx/conf.d/pgp.conf added +37
| @@ -0,0 +1,37 @@ | |||
| 1 | # ---------------------------------------------------------------------- | ||
| 2 | # | Config file for host | | ||
| 3 | # ---------------------------------------------------------------------- | ||
| 4 | server { | ||
| 5 | listen [::]:443 ssl; | ||
| 6 | listen 443 ssl; | ||
| 7 | http2 on; | ||
| 8 | |||
| 9 | server_name pgp.cleberg.net; | ||
| 10 | root /var/www/pgp/; | ||
| 11 | |||
| 12 | include custom.d/tls/ssl_engine.conf; | ||
| 13 | include custom.d/tls/certificate_files.conf; | ||
| 14 | include custom.d/tls/policy_balanced.conf; | ||
| 15 | include custom.d/basic.conf; | ||
| 16 | |||
| 17 | # ---------------------------------------------------------------------- | ||
| 18 | # | Custom rules & config for specific website | | ||
| 19 | # ---------------------------------------------------------------------- | ||
| 20 | location / { | ||
| 21 | try_files $uri $uri/ /index.html; | ||
| 22 | } | ||
| 23 | |||
| 24 | include custom.d/security/robots_index_only.conf; | ||
| 25 | # ---------------------------------------------------------------------- | ||
| 26 | } | ||
| 27 | |||
| 28 | # ---------------------------------------------------------------------- | ||
| 29 | # | Config file for non-secure host | | ||
| 30 | # ---------------------------------------------------------------------- | ||
| 31 | server { | ||
| 32 | listen [::]:80; | ||
| 33 | listen 80; | ||
| 34 | server_name pgp.cleberg.net; | ||
| 35 | |||
| 36 | return 301 https://$host$request_uri; | ||
| 37 | } | ||
linux/nginx/etc/nginx/conf.d/photos.conf added +54
| @@ -0,0 +1,54 @@ | |||
| 1 | # ---------------------------------------------------------------------- | ||
| 2 | # | Config file for host | | ||
| 3 | # ---------------------------------------------------------------------- | ||
| 4 | server { | ||
| 5 | listen [::]:443 ssl; | ||
| 6 | listen 443 ssl; | ||
| 7 | http2 on; | ||
| 8 | |||
| 9 | server_name photos.cleberg.net; | ||
| 10 | |||
| 11 | include custom.d/tls/ssl_engine.conf; | ||
| 12 | include custom.d/tls/certificate_files.conf; | ||
| 13 | include custom.d/tls/policy_balanced.conf; | ||
| 14 | include custom.d/basic.conf; | ||
| 15 | |||
| 16 | # ---------------------------------------------------------------------- | ||
| 17 | # | Custom rules & config for specific website | | ||
| 18 | # ---------------------------------------------------------------------- | ||
| 19 | # allow large file uploads | ||
| 20 | client_max_body_size 50000M; | ||
| 21 | |||
| 22 | # Set headers | ||
| 23 | proxy_set_header Host $host; | ||
| 24 | proxy_set_header X-Real-IP $remote_addr; | ||
| 25 | proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; | ||
| 26 | proxy_set_header X-Forwarded-Proto $scheme; | ||
| 27 | |||
| 28 | # enable websockets: http://nginx.org/en/docs/http/websocket.html | ||
| 29 | proxy_http_version 1.1; | ||
| 30 | proxy_set_header Upgrade $http_upgrade; | ||
| 31 | proxy_set_header Connection "upgrade"; | ||
| 32 | proxy_redirect off; | ||
| 33 | |||
| 34 | # set timeout | ||
| 35 | proxy_read_timeout 600s; | ||
| 36 | proxy_send_timeout 600s; | ||
| 37 | send_timeout 600s; | ||
| 38 | |||
| 39 | location / { | ||
| 40 | proxy_pass http://127.0.0.1:2283; | ||
| 41 | } | ||
| 42 | # ---------------------------------------------------------------------- | ||
| 43 | } | ||
| 44 | |||
| 45 | # ---------------------------------------------------------------------- | ||
| 46 | # | Config file for non-secure host | | ||
| 47 | # ---------------------------------------------------------------------- | ||
| 48 | server { | ||
| 49 | listen [::]:80; | ||
| 50 | listen 80; | ||
| 51 | server_name photos.cleberg.net; | ||
| 52 | |||
| 53 | return 301 https://$host$request_uri; | ||
| 54 | } | ||
linux/nginx/etc/nginx/conf.d/pin.conf added +39
| @@ -0,0 +1,39 @@ | |||
| 1 | # ---------------------------------------------------------------------- | ||
| 2 | # | Config file for host | | ||
| 3 | # ---------------------------------------------------------------------- | ||
| 4 | server { | ||
| 5 | listen [::]:443 ssl; | ||
| 6 | listen 443 ssl; | ||
| 7 | http2 on; | ||
| 8 | |||
| 9 | server_name pin.cleberg.net; | ||
| 10 | |||
| 11 | include custom.d/tls/ssl_engine.conf; | ||
| 12 | include custom.d/tls/certificate_files.conf; | ||
| 13 | include custom.d/tls/policy_balanced.conf; | ||
| 14 | include custom.d/basic.conf; | ||
| 15 | |||
| 16 | # ---------------------------------------------------------------------- | ||
| 17 | # | Custom rules & config for specific website | | ||
| 18 | # ---------------------------------------------------------------------- | ||
| 19 | location / { | ||
| 20 | set $upstream http://127.0.0.1:8086; | ||
| 21 | proxy_pass $upstream; | ||
| 22 | |||
| 23 | include custom.d/reverse_proxy/basic.conf; | ||
| 24 | } | ||
| 25 | |||
| 26 | include custom.d/security/robots_index_only.conf; | ||
| 27 | # ---------------------------------------------------------------------- | ||
| 28 | } | ||
| 29 | |||
| 30 | # ---------------------------------------------------------------------- | ||
| 31 | # | Config file for non-secure host | | ||
| 32 | # ---------------------------------------------------------------------- | ||
| 33 | server { | ||
| 34 | listen [::]:80; | ||
| 35 | listen 80; | ||
| 36 | server_name pin.cleberg.net; | ||
| 37 | |||
| 38 | return 301 https://$host$request_uri; | ||
| 39 | } | ||
linux/nginx/etc/nginx/conf.d/piped.conf added +40
| @@ -0,0 +1,40 @@ | |||
| 1 | # ---------------------------------------------------------------------- | ||
| 2 | # | Config file for host | | ||
| 3 | # ---------------------------------------------------------------------- | ||
| 4 | server { | ||
| 5 | listen [::]:443 ssl; | ||
| 6 | listen 443 ssl; | ||
| 7 | http2 on; | ||
| 8 | |||
| 9 | server_name piped.cleberg.net pipedapi.cleberg.net pipedproxy.cleberg.net; | ||
| 10 | |||
| 11 | include custom.d/tls/ssl_engine.conf; | ||
| 12 | include custom.d/tls/certificate_files.conf; | ||
| 13 | include custom.d/tls/policy_balanced.conf; | ||
| 14 | include custom.d/basic.conf; | ||
| 15 | |||
| 16 | # ---------------------------------------------------------------------- | ||
| 17 | # | Custom rules & config for specific website | | ||
| 18 | # ---------------------------------------------------------------------- | ||
| 19 | location / { | ||
| 20 | set $upstream http://127.0.0.1:8077; | ||
| 21 | proxy_pass $upstream; | ||
| 22 | |||
| 23 | proxy_set_header Host $host; | ||
| 24 | # include custom.d/reverse_proxy/basic.conf; | ||
| 25 | } | ||
| 26 | |||
| 27 | include custom.d/security/robots_index_only.conf; | ||
| 28 | # ---------------------------------------------------------------------- | ||
| 29 | } | ||
| 30 | |||
| 31 | # ---------------------------------------------------------------------- | ||
| 32 | # | Config file for non-secure host | | ||
| 33 | # ---------------------------------------------------------------------- | ||
| 34 | server { | ||
| 35 | listen [::]:80; | ||
| 36 | listen 80; | ||
| 37 | server_name piped.cleberg.net pipedapi.cleberg.net pipedproxy.cleberg.net; | ||
| 38 | |||
| 39 | return 301 https://$host$request_uri; | ||
| 40 | } | ||
linux/nginx/etc/nginx/conf.d/projects.conf added +36
| @@ -0,0 +1,36 @@ | |||
| 1 | # ---------------------------------------------------------------------- | ||
| 2 | # | Config file for host | | ||
| 3 | # ---------------------------------------------------------------------- | ||
| 4 | server { | ||
| 5 | listen [::]:443 ssl; | ||
| 6 | listen 443 ssl; | ||
| 7 | http2 on; | ||
| 8 | |||
| 9 | server_name projects.cleberg.net; | ||
| 10 | root /var/www/projects/; | ||
| 11 | autoindex on; | ||
| 12 | |||
| 13 | include custom.d/tls/ssl_engine.conf; | ||
| 14 | include custom.d/tls/certificate_files.conf; | ||
| 15 | include custom.d/tls/policy_balanced.conf; | ||
| 16 | include custom.d/basic.conf; | ||
| 17 | |||
| 18 | # ---------------------------------------------------------------------- | ||
| 19 | # | Custom rules & config for specific website | | ||
| 20 | # ---------------------------------------------------------------------- | ||
| 21 | location / { | ||
| 22 | try_files $uri $uri/ /index.html; | ||
| 23 | } | ||
| 24 | # ---------------------------------------------------------------------- | ||
| 25 | } | ||
| 26 | |||
| 27 | # ---------------------------------------------------------------------- | ||
| 28 | # | Config file for non-secure host | | ||
| 29 | # ---------------------------------------------------------------------- | ||
| 30 | server { | ||
| 31 | listen [::]:80; | ||
| 32 | listen 80; | ||
| 33 | server_name projects.cleberg.net; | ||
| 34 | |||
| 35 | return 301 https://$host$request_uri; | ||
| 36 | } | ||
linux/nginx/etc/nginx/conf.d/rd.conf added +39
| @@ -0,0 +1,39 @@ | |||
| 1 | # ---------------------------------------------------------------------- | ||
| 2 | # | Config file for host | | ||
| 3 | # ---------------------------------------------------------------------- | ||
| 4 | server { | ||
| 5 | listen [::]:443 ssl; | ||
| 6 | listen 443 ssl; | ||
| 7 | http2 on; | ||
| 8 | |||
| 9 | server_name rd.cleberg.net; | ||
| 10 | |||
| 11 | include custom.d/tls/ssl_engine.conf; | ||
| 12 | include custom.d/tls/certificate_files.conf; | ||
| 13 | include custom.d/tls/policy_balanced.conf; | ||
| 14 | include custom.d/basic.conf; | ||
| 15 | |||
| 16 | # ---------------------------------------------------------------------- | ||
| 17 | # | Custom rules & config for specific website | | ||
| 18 | # ---------------------------------------------------------------------- | ||
| 19 | location / { | ||
| 20 | set $upstream http://127.0.0.1:5758; | ||
| 21 | proxy_pass $upstream; | ||
| 22 | |||
| 23 | include custom.d/reverse_proxy/basic.conf; | ||
| 24 | } | ||
| 25 | |||
| 26 | include custom.d/security/robots_index_only.conf; | ||
| 27 | # ---------------------------------------------------------------------- | ||
| 28 | } | ||
| 29 | |||
| 30 | # ---------------------------------------------------------------------- | ||
| 31 | # | Config file for non-secure host | | ||
| 32 | # ---------------------------------------------------------------------- | ||
| 33 | server { | ||
| 34 | listen [::]:80; | ||
| 35 | listen 80; | ||
| 36 | server_name rd.cleberg.net; | ||
| 37 | |||
| 38 | return 301 https://$host$request_uri; | ||
| 39 | } | ||
linux/nginx/etc/nginx/conf.d/reminiscecleberg.com.conf added +56
| @@ -0,0 +1,56 @@ | |||
| 1 | # ---------------------------------------------------------------------- | ||
| 2 | # | Config file for host | | ||
| 3 | # ---------------------------------------------------------------------- | ||
| 4 | server { | ||
| 5 | listen [::]:443 ssl; | ||
| 6 | listen 443 ssl; | ||
| 7 | http2 on; | ||
| 8 | |||
| 9 | server_name www.reminiscecleberg.com; | ||
| 10 | |||
| 11 | include custom.d/tls/ssl_engine.conf; | ||
| 12 | include custom.d/tls/policy_balanced.conf; | ||
| 13 | # include custom.d/tls/certificate_files.conf; | ||
| 14 | ssl_certificate /etc/letsencrypt/live/reminiscecleberg.com/fullchain.pem; | ||
| 15 | ssl_certificate_key /etc/letsencrypt/live/reminiscecleberg.com/privkey.pem; | ||
| 16 | ssl_trusted_certificate /etc/letsencrypt/live/reminiscecleberg.com/chain.pem; | ||
| 17 | |||
| 18 | return 301 $scheme://reminiscecleberg.com$request_uri; | ||
| 19 | } | ||
| 20 | |||
| 21 | |||
| 22 | server { | ||
| 23 | listen [::]:443 ssl; | ||
| 24 | listen 443 ssl; | ||
| 25 | http2 on; | ||
| 26 | |||
| 27 | server_name reminiscecleberg.com; | ||
| 28 | root /var/www/reminiscecleberg.com/; | ||
| 29 | |||
| 30 | include custom.d/tls/ssl_engine.conf; | ||
| 31 | include custom.d/tls/policy_balanced.conf; | ||
| 32 | include custom.d/basic.conf; | ||
| 33 | # include custom.d/tls/certificate_files.conf; | ||
| 34 | ssl_certificate /etc/letsencrypt/live/reminiscecleberg.com/fullchain.pem; | ||
| 35 | ssl_certificate_key /etc/letsencrypt/live/reminiscecleberg.com/privkey.pem; | ||
| 36 | ssl_trusted_certificate /etc/letsencrypt/live/reminiscecleberg.com/chain.pem; | ||
| 37 | |||
| 38 | # ---------------------------------------------------------------------- | ||
| 39 | # | Custom rules & config for specific website | | ||
| 40 | # ---------------------------------------------------------------------- | ||
| 41 | location / { | ||
| 42 | try_files $uri $uri/ =404; | ||
| 43 | } | ||
| 44 | # ---------------------------------------------------------------------- | ||
| 45 | } | ||
| 46 | |||
| 47 | # ---------------------------------------------------------------------- | ||
| 48 | # | Config file for non-secure host | | ||
| 49 | # ---------------------------------------------------------------------- | ||
| 50 | server { | ||
| 51 | listen [::]:80; | ||
| 52 | listen 80; | ||
| 53 | server_name www.reminiscecleberg.com reminiscecleberg.com; | ||
| 54 | |||
| 55 | return 301 https://reminiscecleberg.com$request_uri; | ||
| 56 | } | ||
linux/nginx/etc/nginx/conf.d/rimgo.conf added +39
| @@ -0,0 +1,39 @@ | |||
| 1 | # ---------------------------------------------------------------------- | ||
| 2 | # | Config file for host | | ||
| 3 | # ---------------------------------------------------------------------- | ||
| 4 | server { | ||
| 5 | listen [::]:443 ssl; | ||
| 6 | listen 443 ssl; | ||
| 7 | http2 on; | ||
| 8 | |||
| 9 | server_name rimgo.cleberg.net; | ||
| 10 | |||
| 11 | include custom.d/tls/ssl_engine.conf; | ||
| 12 | include custom.d/tls/certificate_files.conf; | ||
| 13 | include custom.d/tls/policy_balanced.conf; | ||
| 14 | include custom.d/basic.conf; | ||
| 15 | |||
| 16 | # ---------------------------------------------------------------------- | ||
| 17 | # | Custom rules & config for specific website | | ||
| 18 | # ---------------------------------------------------------------------- | ||
| 19 | location / { | ||
| 20 | set $upstream http://127.0.0.1:3869; | ||
| 21 | proxy_pass $upstream; | ||
| 22 | |||
| 23 | include custom.d/reverse_proxy/basic.conf; | ||
| 24 | } | ||
| 25 | |||
| 26 | include custom.d/security/robots_index_only.conf; | ||
| 27 | # ---------------------------------------------------------------------- | ||
| 28 | } | ||
| 29 | |||
| 30 | # ---------------------------------------------------------------------- | ||
| 31 | # | Config file for non-secure host | | ||
| 32 | # ---------------------------------------------------------------------- | ||
| 33 | server { | ||
| 34 | listen [::]:80; | ||
| 35 | listen 80; | ||
| 36 | server_name rimgo.cleberg.net; | ||
| 37 | |||
| 38 | return 301 https://$host$request_uri; | ||
| 39 | } | ||
linux/nginx/etc/nginx/conf.d/rl.conf added +44
| @@ -0,0 +1,44 @@ | |||
| 1 | # ---------------------------------------------------------------------- | ||
| 2 | # | Config file for host | | ||
| 3 | # ---------------------------------------------------------------------- | ||
| 4 | server { | ||
| 5 | listen [::]:443 ssl; | ||
| 6 | listen 443 ssl; | ||
| 7 | http2 on; | ||
| 8 | |||
| 9 | server_name rl.cleberg.net; | ||
| 10 | |||
| 11 | include custom.d/tls/ssl_engine.conf; | ||
| 12 | include custom.d/tls/certificate_files.conf; | ||
| 13 | include custom.d/tls/policy_balanced.conf; | ||
| 14 | include custom.d/basic.conf; | ||
| 15 | |||
| 16 | # ---------------------------------------------------------------------- | ||
| 17 | # | Custom rules & config for specific website | | ||
| 18 | # ---------------------------------------------------------------------- | ||
| 19 | location /authelia { | ||
| 20 | include custom.d/reverse_proxy/authelia.conf; | ||
| 21 | } | ||
| 22 | |||
| 23 | location / { | ||
| 24 | set $upstream http://192.168.0.251:8983; | ||
| 25 | proxy_pass $upstream; | ||
| 26 | |||
| 27 | include custom.d/reverse_proxy/authelia_request.conf; | ||
| 28 | include custom.d/reverse_proxy/basic.conf; | ||
| 29 | } | ||
| 30 | |||
| 31 | include custom.d/security/robots_index_only.conf; | ||
| 32 | # ---------------------------------------------------------------------- | ||
| 33 | } | ||
| 34 | |||
| 35 | # ---------------------------------------------------------------------- | ||
| 36 | # | Config file for non-secure host | | ||
| 37 | # ---------------------------------------------------------------------- | ||
| 38 | server { | ||
| 39 | listen [::]:80; | ||
| 40 | listen 80; | ||
| 41 | server_name rl.cleberg.net; | ||
| 42 | |||
| 43 | return 301 https://$host$request_uri; | ||
| 44 | } | ||
linux/nginx/etc/nginx/conf.d/rss.conf added +58
| @@ -0,0 +1,58 @@ | |||
| 1 | # ---------------------------------------------------------------------- | ||
| 2 | # | Config file for host | | ||
| 3 | # ---------------------------------------------------------------------- | ||
| 4 | upstream freshrss { | ||
| 5 | server 192.168.0.251:8081; | ||
| 6 | keepalive 64; | ||
| 7 | } | ||
| 8 | |||
| 9 | server { | ||
| 10 | listen [::]:443 ssl; | ||
| 11 | listen 443 ssl; | ||
| 12 | http2 on; | ||
| 13 | |||
| 14 | server_name rss.cleberg.net; | ||
| 15 | |||
| 16 | include custom.d/tls/ssl_engine.conf; | ||
| 17 | include custom.d/tls/certificate_files.conf; | ||
| 18 | include custom.d/tls/policy_balanced.conf; | ||
| 19 | include custom.d/basic.conf; | ||
| 20 | |||
| 21 | # ---------------------------------------------------------------------- | ||
| 22 | # | Custom rules & config for specific website | | ||
| 23 | # ---------------------------------------------------------------------- | ||
| 24 | location / { | ||
| 25 | proxy_pass http://freshrss/; | ||
| 26 | |||
| 27 | # include custom.d/reverse_proxy/basic.conf; | ||
| 28 | |||
| 29 | add_header X-Frame-Options SAMEORIGIN; | ||
| 30 | add_header X-XSS-Protection "1; mode=block"; | ||
| 31 | proxy_redirect off; | ||
| 32 | proxy_buffering off; | ||
| 33 | proxy_set_header Host $host; | ||
| 34 | proxy_set_header X-Real-IP $remote_addr; | ||
| 35 | proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; | ||
| 36 | proxy_set_header X-Forwarded-Proto $scheme; | ||
| 37 | proxy_set_header X-Forwarded-Port $server_port; | ||
| 38 | proxy_read_timeout 90; | ||
| 39 | |||
| 40 | # Forward the Authorization header for the Google Reader API. | ||
| 41 | proxy_set_header Authorization $http_authorization; | ||
| 42 | proxy_pass_header Authorization; | ||
| 43 | } | ||
| 44 | |||
| 45 | include custom.d/security/robots_index_only.conf; | ||
| 46 | # ---------------------------------------------------------------------- | ||
| 47 | } | ||
| 48 | |||
| 49 | # ---------------------------------------------------------------------- | ||
| 50 | # | Config file for non-secure host | | ||
| 51 | # ---------------------------------------------------------------------- | ||
| 52 | server { | ||
| 53 | listen [::]:80; | ||
| 54 | listen 80; | ||
| 55 | server_name rss.cleberg.net; | ||
| 56 | |||
| 57 | return 301 https://$host$request_uri; | ||
| 58 | } | ||
linux/nginx/etc/nginx/conf.d/search.conf added +44
| @@ -0,0 +1,44 @@ | |||
| 1 | # ---------------------------------------------------------------------- | ||
| 2 | # | Config file for host | | ||
| 3 | # ---------------------------------------------------------------------- | ||
| 4 | server { | ||
| 5 | listen [::]:443 ssl; | ||
| 6 | listen 443 ssl; | ||
| 7 | http2 on; | ||
| 8 | |||
| 9 | server_name search.cleberg.net; | ||
| 10 | |||
| 11 | include custom.d/tls/ssl_engine.conf; | ||
| 12 | include custom.d/tls/certificate_files.conf; | ||
| 13 | include custom.d/tls/policy_balanced.conf; | ||
| 14 | include custom.d/basic.conf; | ||
| 15 | |||
| 16 | # ---------------------------------------------------------------------- | ||
| 17 | # | Custom rules & config for specific website | | ||
| 18 | # ---------------------------------------------------------------------- | ||
| 19 | location / { | ||
| 20 | set $upstream http://127.0.0.1:9191; | ||
| 21 | proxy_pass $upstream; | ||
| 22 | |||
| 23 | # include custom.d/reverse_proxy/basic.conf; | ||
| 24 | proxy_set_header Host $host; | ||
| 25 | proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; | ||
| 26 | proxy_set_header Upgrade $http_upgrade; | ||
| 27 | proxy_set_header Connection "upgrade"; | ||
| 28 | proxy_http_version 1.1; | ||
| 29 | } | ||
| 30 | |||
| 31 | include custom.d/security/robots_index_only.conf; | ||
| 32 | # ---------------------------------------------------------------------- | ||
| 33 | } | ||
| 34 | |||
| 35 | # ---------------------------------------------------------------------- | ||
| 36 | # | Config file for non-secure host | | ||
| 37 | # ---------------------------------------------------------------------- | ||
| 38 | server { | ||
| 39 | listen [::]:80; | ||
| 40 | listen 80; | ||
| 41 | server_name search.cleberg.net; | ||
| 42 | |||
| 43 | return 301 https://$host$request_uri; | ||
| 44 | } | ||
linux/nginx/etc/nginx/conf.d/send.conf added +39
| @@ -0,0 +1,39 @@ | |||
| 1 | # ---------------------------------------------------------------------- | ||
| 2 | # | Config file for host | | ||
| 3 | # ---------------------------------------------------------------------- | ||
| 4 | server { | ||
| 5 | listen [::]:443 ssl; | ||
| 6 | listen 443 ssl; | ||
| 7 | http2 on; | ||
| 8 | |||
| 9 | server_name send.cleberg.net; | ||
| 10 | |||
| 11 | include custom.d/tls/ssl_engine.conf; | ||
| 12 | include custom.d/tls/certificate_files.conf; | ||
| 13 | include custom.d/tls/policy_balanced.conf; | ||
| 14 | include custom.d/basic.conf; | ||
| 15 | |||
| 16 | # ---------------------------------------------------------------------- | ||
| 17 | # | Custom rules & config for specific website | | ||
| 18 | # ---------------------------------------------------------------------- | ||
| 19 | location / { | ||
| 20 | set $upstream http://127.0.0.1:1443; | ||
| 21 | proxy_pass $upstream; | ||
| 22 | |||
| 23 | include custom.d/reverse_proxy/basic.conf; | ||
| 24 | } | ||
| 25 | |||
| 26 | include custom.d/security/robots_index_only.conf; | ||
| 27 | # ---------------------------------------------------------------------- | ||
| 28 | } | ||
| 29 | |||
| 30 | # ---------------------------------------------------------------------- | ||
| 31 | # | Config file for non-secure host | | ||
| 32 | # ---------------------------------------------------------------------- | ||
| 33 | server { | ||
| 34 | listen [::]:80; | ||
| 35 | listen 80; | ||
| 36 | server_name send.cleberg.net; | ||
| 37 | |||
| 38 | return 301 https://$host$request_uri; | ||
| 39 | } | ||
linux/nginx/etc/nginx/conf.d/slash.conf added +39
| @@ -0,0 +1,39 @@ | |||
| 1 | # ---------------------------------------------------------------------- | ||
| 2 | # | Config file for host | | ||
| 3 | # ---------------------------------------------------------------------- | ||
| 4 | server { | ||
| 5 | listen [::]:443 ssl; | ||
| 6 | listen 443 ssl; | ||
| 7 | http2 on; | ||
| 8 | |||
| 9 | server_name slash.cleberg.net; | ||
| 10 | |||
| 11 | include custom.d/tls/ssl_engine.conf; | ||
| 12 | include custom.d/tls/certificate_files.conf; | ||
| 13 | include custom.d/tls/policy_balanced.conf; | ||
| 14 | include custom.d/basic.conf; | ||
| 15 | |||
| 16 | # ---------------------------------------------------------------------- | ||
| 17 | # | Custom rules & config for specific website | | ||
| 18 | # ---------------------------------------------------------------------- | ||
| 19 | location / { | ||
| 20 | set $upstream http://192.168.0.251:5231; | ||
| 21 | proxy_pass $upstream; | ||
| 22 | |||
| 23 | include custom.d/reverse_proxy/basic.conf; | ||
| 24 | } | ||
| 25 | |||
| 26 | include custom.d/security/robots_index_only.conf; | ||
| 27 | # ---------------------------------------------------------------------- | ||
| 28 | } | ||
| 29 | |||
| 30 | # ---------------------------------------------------------------------- | ||
| 31 | # | Config file for non-secure host | | ||
| 32 | # ---------------------------------------------------------------------- | ||
| 33 | server { | ||
| 34 | listen [::]:80; | ||
| 35 | listen 80; | ||
| 36 | server_name slash.cleberg.net; | ||
| 37 | |||
| 38 | return 301 https://$host$request_uri; | ||
| 39 | } | ||
linux/nginx/etc/nginx/conf.d/small.conf added +39
| @@ -0,0 +1,39 @@ | |||
| 1 | # ---------------------------------------------------------------------- | ||
| 2 | # | Config file for host | | ||
| 3 | # ---------------------------------------------------------------------- | ||
| 4 | server { | ||
| 5 | listen [::]:443 ssl; | ||
| 6 | listen 443 ssl; | ||
| 7 | http2 on; | ||
| 8 | |||
| 9 | server_name small.cleberg.net; | ||
| 10 | |||
| 11 | include custom.d/tls/ssl_engine.conf; | ||
| 12 | include custom.d/tls/certificate_files.conf; | ||
| 13 | include custom.d/tls/policy_balanced.conf; | ||
| 14 | include custom.d/basic.conf; | ||
| 15 | |||
| 16 | # ---------------------------------------------------------------------- | ||
| 17 | # | Custom rules & config for specific website | | ||
| 18 | # ---------------------------------------------------------------------- | ||
| 19 | location / { | ||
| 20 | set $upstream http://127.0.0.1:8002; | ||
| 21 | proxy_pass $upstream; | ||
| 22 | |||
| 23 | include custom.d/reverse_proxy/basic.conf; | ||
| 24 | } | ||
| 25 | |||
| 26 | include custom.d/security/robots_index_only.conf; | ||
| 27 | # ---------------------------------------------------------------------- | ||
| 28 | } | ||
| 29 | |||
| 30 | # ---------------------------------------------------------------------- | ||
| 31 | # | Config file for non-secure host | | ||
| 32 | # ---------------------------------------------------------------------- | ||
| 33 | server { | ||
| 34 | listen [::]:80; | ||
| 35 | listen 80; | ||
| 36 | server_name small.cleberg.net; | ||
| 37 | |||
| 38 | return 301 https://$host$request_uri; | ||
| 39 | } | ||
linux/nginx/etc/nginx/conf.d/ssh.conf added +44
| @@ -0,0 +1,44 @@ | |||
| 1 | # ---------------------------------------------------------------------- | ||
| 2 | # | Config file for host | | ||
| 3 | # ---------------------------------------------------------------------- | ||
| 4 | server { | ||
| 5 | listen [::]:443 ssl; | ||
| 6 | listen 443 ssl; | ||
| 7 | http2 on; | ||
| 8 | |||
| 9 | server_name ssh.cleberg.net; | ||
| 10 | |||
| 11 | include custom.d/tls/ssl_engine.conf; | ||
| 12 | include custom.d/tls/certificate_files.conf; | ||
| 13 | include custom.d/tls/policy_balanced.conf; | ||
| 14 | include custom.d/basic.conf; | ||
| 15 | |||
| 16 | # ---------------------------------------------------------------------- | ||
| 17 | # | Custom rules & config for specific website | | ||
| 18 | # ---------------------------------------------------------------------- | ||
| 19 | location /authelia { | ||
| 20 | include custom.d/reverse_proxy/authelia.conf; | ||
| 21 | } | ||
| 22 | |||
| 23 | location / { | ||
| 24 | set $upstream http://127.0.0.1:8169; | ||
| 25 | proxy_pass $upstream; | ||
| 26 | |||
| 27 | include custom.d/reverse_proxy/authelia_request.conf; | ||
| 28 | include custom.d/reverse_proxy/basic.conf; | ||
| 29 | } | ||
| 30 | |||
| 31 | include custom.d/security/robots_index_only.conf; | ||
| 32 | # ---------------------------------------------------------------------- | ||
| 33 | } | ||
| 34 | |||
| 35 | # ---------------------------------------------------------------------- | ||
| 36 | # | Config file for non-secure host | | ||
| 37 | # ---------------------------------------------------------------------- | ||
| 38 | server { | ||
| 39 | listen [::]:80; | ||
| 40 | listen 80; | ||
| 41 | server_name ssh.cleberg.net; | ||
| 42 | |||
| 43 | return 301 https://$host$request_uri; | ||
| 44 | } | ||
linux/nginx/etc/nginx/conf.d/teddit.conf added +44
| @@ -0,0 +1,44 @@ | |||
| 1 | # ---------------------------------------------------------------------- | ||
| 2 | # | Config file for host | | ||
| 3 | # ---------------------------------------------------------------------- | ||
| 4 | server { | ||
| 5 | listen [::]:443 ssl; | ||
| 6 | listen 443 ssl; | ||
| 7 | http2 on; | ||
| 8 | |||
| 9 | server_name teddit.cleberg.net; | ||
| 10 | |||
| 11 | include custom.d/tls/ssl_engine.conf; | ||
| 12 | include custom.d/tls/certificate_files.conf; | ||
| 13 | include custom.d/tls/policy_balanced.conf; | ||
| 14 | include custom.d/basic.conf; | ||
| 15 | |||
| 16 | # ---------------------------------------------------------------------- | ||
| 17 | # | Custom rules & config for specific website | | ||
| 18 | # ---------------------------------------------------------------------- | ||
| 19 | location /authelia { | ||
| 20 | include custom.d/reverse_proxy/authelia.conf; | ||
| 21 | } | ||
| 22 | |||
| 23 | location / { | ||
| 24 | set $upstream http://192.168.0.251:8181; | ||
| 25 | proxy_pass $upstream; | ||
| 26 | |||
| 27 | include custom.d/reverse_proxy/authelia_request.conf; | ||
| 28 | include custom.d/reverse_proxy/basic.conf; | ||
| 29 | } | ||
| 30 | |||
| 31 | include custom.d/security/robots_index_only.conf; | ||
| 32 | # ---------------------------------------------------------------------- | ||
| 33 | } | ||
| 34 | |||
| 35 | # ---------------------------------------------------------------------- | ||
| 36 | # | Config file for non-secure host | | ||
| 37 | # ---------------------------------------------------------------------- | ||
| 38 | server { | ||
| 39 | listen [::]:80; | ||
| 40 | listen 80; | ||
| 41 | server_name teddit.cleberg.net; | ||
| 42 | |||
| 43 | return 301 https://$host$request_uri; | ||
| 44 | } | ||
linux/nginx/etc/nginx/conf.d/wyl.conf added +44
| @@ -0,0 +1,44 @@ | |||
| 1 | # ---------------------------------------------------------------------- | ||
| 2 | # | Config file for host | | ||
| 3 | # ---------------------------------------------------------------------- | ||
| 4 | server { | ||
| 5 | listen [::]:443 ssl; | ||
| 6 | listen 443 ssl; | ||
| 7 | http2 on; | ||
| 8 | |||
| 9 | server_name wyl.cleberg.net; | ||
| 10 | |||
| 11 | include custom.d/tls/ssl_engine.conf; | ||
| 12 | include custom.d/tls/certificate_files.conf; | ||
| 13 | include custom.d/tls/policy_balanced.conf; | ||
| 14 | include custom.d/basic.conf; | ||
| 15 | |||
| 16 | # ---------------------------------------------------------------------- | ||
| 17 | # | Custom rules & config for specific website | | ||
| 18 | # ---------------------------------------------------------------------- | ||
| 19 | location /authelia { | ||
| 20 | include custom.d/reverse_proxy/authelia.conf; | ||
| 21 | } | ||
| 22 | |||
| 23 | location / { | ||
| 24 | set $upstream http://192.168.0.251:8840; | ||
| 25 | proxy_pass $upstream; | ||
| 26 | |||
| 27 | include custom.d/reverse_proxy/authelia_request.conf; | ||
| 28 | include custom.d/reverse_proxy/basic.conf; | ||
| 29 | } | ||
| 30 | |||
| 31 | include custom.d/security/robots_index_only.conf; | ||
| 32 | # ---------------------------------------------------------------------- | ||
| 33 | } | ||
| 34 | |||
| 35 | # ---------------------------------------------------------------------- | ||
| 36 | # | Config file for non-secure host | | ||
| 37 | # ---------------------------------------------------------------------- | ||
| 38 | server { | ||
| 39 | listen [::]:80; | ||
| 40 | listen 80; | ||
| 41 | server_name wyl.cleberg.net; | ||
| 42 | |||
| 43 | return 301 https://$host$request_uri; | ||
| 44 | } | ||
linux/nginx/etc/nginx/custom.d/basic.conf added +8
| @@ -0,0 +1,8 @@ | |||
| 1 | # Nginx Server Configs | MIT License | ||
| 2 | # https://github.com/h5bp/server-configs-nginx | ||
| 3 | |||
| 4 | include custom.d/security/referrer-policy.conf; | ||
| 5 | include custom.d/security/x-content-type-options.conf; | ||
| 6 | include custom.d/security/x-frame-options.conf; | ||
| 7 | include custom.d/location/security_file_access.conf; | ||
| 8 | #include custom.d/cross-origin/requests.conf; | ||
linux/nginx/etc/nginx/custom.d/cross-origin/requests.conf added +18
| @@ -0,0 +1,18 @@ | |||
| 1 | # ---------------------------------------------------------------------- | ||
| 2 | # | Cross-origin requests | | ||
| 3 | # ---------------------------------------------------------------------- | ||
| 4 | |||
| 5 | # Allow cross-origin requests. | ||
| 6 | # | ||
| 7 | # https://developer.mozilla.org/en-US/docs/Web/HTTP/Access_control_CORS | ||
| 8 | # https://enable-cors.org/ | ||
| 9 | # https://www.w3.org/TR/cors/ | ||
| 10 | |||
| 11 | # (!) Do not use this without understanding the consequences. | ||
| 12 | # This will permit access from any other website. | ||
| 13 | # Instead of using this file, consider using a specific rule such as | ||
| 14 | # allowing access based on (sub)domain: | ||
| 15 | # | ||
| 16 | # add_header Access-Control-Allow-Origin "subdomain.example.com"; | ||
| 17 | |||
| 18 | # add_header Access-Control-Allow-Origin $cors; | ||
linux/nginx/etc/nginx/custom.d/cross-origin/resource_timing.conf added +15
| @@ -0,0 +1,15 @@ | |||
| 1 | # ---------------------------------------------------------------------- | ||
| 2 | # | Cross-origin resource timing | | ||
| 3 | # ---------------------------------------------------------------------- | ||
| 4 | |||
| 5 | # Allow cross-origin access to the timing information for all resources. | ||
| 6 | # | ||
| 7 | # If a resource isn't served with a `Timing-Allow-Origin` header that would | ||
| 8 | # allow its timing information to be shared with the document, some of the | ||
| 9 | # attributes of the `PerformanceResourceTiming` object will be set to zero. | ||
| 10 | # | ||
| 11 | # https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Timing-Allow-Origin | ||
| 12 | # https://www.w3.org/TR/resource-timing/ | ||
| 13 | # https://www.stevesouders.com/blog/2014/08/21/resource-timing-practical-tips/ | ||
| 14 | |||
| 15 | # add_header Timing-Allow-Origin "*"; | ||
linux/nginx/etc/nginx/custom.d/errors/custom_errors.conf added +9
| @@ -0,0 +1,9 @@ | |||
| 1 | # ---------------------------------------------------------------------- | ||
| 2 | # | Custom error messages/pages | | ||
| 3 | # ---------------------------------------------------------------------- | ||
| 4 | |||
| 5 | # Customize what Nginx returns to the client in case of an error. | ||
| 6 | # | ||
| 7 | # https://nginx.org/en/docs/http/ngx_http_core_module.html#error_page | ||
| 8 | |||
| 9 | # error_page 404 /404.html; | ||
linux/nginx/etc/nginx/custom.d/location/security_file_access.conf added +41
| @@ -0,0 +1,41 @@ | |||
| 1 | # ---------------------------------------------------------------------- | ||
| 2 | # | File access | | ||
| 3 | # ---------------------------------------------------------------------- | ||
| 4 | |||
| 5 | # Block access to all hidden files and directories except for the | ||
| 6 | # visible content from within the `/.well-known/` hidden directory. | ||
| 7 | # | ||
| 8 | # These types of files usually contain user preferences or the preserved state | ||
| 9 | # of a utility, and can include rather private places like, for example, the | ||
| 10 | # `.git` or `.svn` directories. | ||
| 11 | # | ||
| 12 | # The `/.well-known/` directory represents the standard (RFC 5785) path prefix | ||
| 13 | # for "well-known locations" (e.g.: `/.well-known/manifest.json`, | ||
| 14 | # `/.well-known/keybase.txt`), and therefore, access to its visible content | ||
| 15 | # should not be blocked. | ||
| 16 | # | ||
| 17 | # https://www.mnot.net/blog/2010/04/07/well-known | ||
| 18 | # https://tools.ietf.org/html/rfc5785 | ||
| 19 | |||
| 20 | location ~* /\.(?!well-known\/) { | ||
| 21 | deny all; | ||
| 22 | } | ||
| 23 | |||
| 24 | # - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - | ||
| 25 | |||
| 26 | # Block access to files that can expose sensitive information. | ||
| 27 | # | ||
| 28 | # By default, block access to backup and source files that may be left by some | ||
| 29 | # text editors and can pose a security risk when anyone has access to them. | ||
| 30 | # | ||
| 31 | # https://feross.org/cmsploit/ | ||
| 32 | # | ||
| 33 | # (!) Update the `location` regular expression from below to include any files | ||
| 34 | # that might end up on your production server and can expose sensitive | ||
| 35 | # information about your website. These files may include: configuration | ||
| 36 | # files, files that contain metadata about the project (e.g.: project | ||
| 37 | # dependencies, build scripts, etc.). | ||
| 38 | |||
| 39 | location ~* (?:#.*#|\.(?:bak|conf|dist|fla|in[ci]|log|orig|psd|sh|sql|sw[op])|~)$ { | ||
| 40 | deny all; | ||
| 41 | } | ||
linux/nginx/etc/nginx/custom.d/location/web_performance_filename-based_cache_busting.conf added +14
| @@ -0,0 +1,14 @@ | |||
| 1 | # ---------------------------------------------------------------------- | ||
| 2 | # | Filename-based cache busting | | ||
| 3 | # ---------------------------------------------------------------------- | ||
| 4 | |||
| 5 | # If you're not using a build process to manage your filename version revving, | ||
| 6 | # you might want to consider enabling the following directives. | ||
| 7 | # | ||
| 8 | # To understand why this is important and even a better solution than using | ||
| 9 | # something like `*.css?v231`, please see: | ||
| 10 | # https://www.stevesouders.com/blog/2008/08/23/revving-filenames-dont-use-querystring/ | ||
| 11 | |||
| 12 | location ~* (.+)\.(?:\w+)\.(avifs?|bmp|css|cur|gif|ico|jpe?g|jxl|m?js|a?png|svgz?|webp|webmanifest)$ { | ||
| 13 | try_files $uri $1.$2; | ||
| 14 | } | ||
linux/nginx/etc/nginx/custom.d/location/web_performance_svgz-compression.conf added +18
| @@ -0,0 +1,18 @@ | |||
| 1 | # ---------------------------------------------------------------------- | ||
| 2 | # | SVGZ Compression | | ||
| 3 | # ---------------------------------------------------------------------- | ||
| 4 | |||
| 5 | # SVGZ files are already compressed. | ||
| 6 | # Disable gzip function for `.svgz` files. | ||
| 7 | |||
| 8 | location ~* \.svgz$ { | ||
| 9 | gzip off; | ||
| 10 | add_header Content-Encoding gzip; | ||
| 11 | |||
| 12 | include custom.d/security/x-content-type-options.conf; | ||
| 13 | include custom.d/security/content-security-policy.conf; | ||
| 14 | include custom.d/security/referrer-policy.conf; | ||
| 15 | include custom.d/security/permissions-policy.conf; | ||
| 16 | include custom.d/security/cross-origin-policy.conf; | ||
| 17 | include custom.d/cross-origin/requests.conf; | ||
| 18 | } | ||
linux/nginx/etc/nginx/custom.d/media_types/character_encodings.conf added +32
| @@ -0,0 +1,32 @@ | |||
| 1 | # ---------------------------------------------------------------------- | ||
| 2 | # | Character encodings | | ||
| 3 | # ---------------------------------------------------------------------- | ||
| 4 | |||
| 5 | # Serve all resources labeled as `text/html` or `text/plain` with the media type | ||
| 6 | # `charset` parameter set to `UTF-8`. | ||
| 7 | # | ||
| 8 | # https://nginx.org/en/docs/http/ngx_http_charset_module.html#charset | ||
| 9 | |||
| 10 | charset utf-8; | ||
| 11 | |||
| 12 | # - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - | ||
| 13 | |||
| 14 | # Update charset_types to match updated mime.types. | ||
| 15 | # `text/html` is always included by charset module. | ||
| 16 | # Default: text/html text/xml text/plain text/vnd.wap.wml application/javascript application/rss+xml | ||
| 17 | # | ||
| 18 | # https://nginx.org/en/docs/http/ngx_http_charset_module.html#charset_types | ||
| 19 | |||
| 20 | charset_types | ||
| 21 | text/css | ||
| 22 | text/plain | ||
| 23 | text/vnd.wap.wml | ||
| 24 | text/javascript | ||
| 25 | text/markdown | ||
| 26 | text/calendar | ||
| 27 | text/x-component | ||
| 28 | text/vcard | ||
| 29 | text/cache-manifest | ||
| 30 | text/vtt | ||
| 31 | application/json | ||
| 32 | application/manifest+json; | ||
linux/nginx/etc/nginx/custom.d/media_types/media_types.conf added +18
| @@ -0,0 +1,18 @@ | |||
| 1 | # ---------------------------------------------------------------------- | ||
| 2 | # | Media types | | ||
| 3 | # ---------------------------------------------------------------------- | ||
| 4 | |||
| 5 | # Serve resources with the proper media types (f.k.a. MIME types). | ||
| 6 | # | ||
| 7 | # https://www.iana.org/assignments/media-types/media-types.xhtml | ||
| 8 | # https://nginx.org/en/docs/http/ngx_http_core_module.html#types | ||
| 9 | |||
| 10 | include mime.types; | ||
| 11 | |||
| 12 | # - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - | ||
| 13 | |||
| 14 | # Default: text/plain | ||
| 15 | # | ||
| 16 | # https://nginx.org/en/docs/http/ngx_http_core_module.html#default_type | ||
| 17 | |||
| 18 | default_type application/octet-stream; | ||
linux/nginx/etc/nginx/custom.d/reverse_proxy/authelia.conf added +28
| @@ -0,0 +1,28 @@ | |||
| 1 | internal; | ||
| 2 | set $upstream_authelia http://127.0.0.1:9092/api/verify; #change the IP and Port to match the IP and Port of your Authelia container | ||
| 3 | proxy_pass_request_body off; | ||
| 4 | proxy_pass $upstream_authelia; | ||
| 5 | proxy_set_header Content-Length ""; | ||
| 6 | |||
| 7 | # Timeout if the real server is dead | ||
| 8 | proxy_next_upstream error timeout invalid_header http_500 http_502 http_503; | ||
| 9 | client_body_buffer_size 128k; | ||
| 10 | proxy_set_header Host $host; | ||
| 11 | proxy_set_header X-Original-URL $scheme://$http_host$request_uri; | ||
| 12 | proxy_set_header X-Real-IP $remote_addr; | ||
| 13 | proxy_set_header X-Forwarded-For $remote_addr; | ||
| 14 | proxy_set_header X-Forwarded-Proto $scheme; | ||
| 15 | proxy_set_header X-Forwarded-Host $http_host; | ||
| 16 | proxy_set_header X-Forwarded-Uri $request_uri; | ||
| 17 | proxy_set_header X-Forwarded-Ssl on; | ||
| 18 | proxy_redirect http:// $scheme://; | ||
| 19 | proxy_http_version 1.1; | ||
| 20 | proxy_set_header Connection ""; | ||
| 21 | proxy_cache_bypass $cookie_session; | ||
| 22 | proxy_no_cache $cookie_session; | ||
| 23 | proxy_buffers 4 32k; | ||
| 24 | |||
| 25 | send_timeout 5m; | ||
| 26 | proxy_read_timeout 240; | ||
| 27 | proxy_send_timeout 240; | ||
| 28 | proxy_connect_timeout 240; | ||
linux/nginx/etc/nginx/custom.d/reverse_proxy/authelia_request.conf added +10
| @@ -0,0 +1,10 @@ | |||
| 1 | auth_request /authelia; | ||
| 2 | auth_request_set $target_url https://$http_host$request_uri; | ||
| 3 | auth_request_set $user $upstream_http_remote_user; | ||
| 4 | auth_request_set $email $upstream_http_remote_email; | ||
| 5 | auth_request_set $groups $upstream_http_remote_groups; | ||
| 6 | proxy_set_header Remote-User $user; | ||
| 7 | proxy_set_header Remote-Email $email; | ||
| 8 | proxy_set_header Remote-Groups $groups; | ||
| 9 | |||
| 10 | error_page 401 =302 https://auth.cleberg.net/?rd=$target_url; | ||
linux/nginx/etc/nginx/custom.d/reverse_proxy/basic.conf added +16
| @@ -0,0 +1,16 @@ | |||
| 1 | proxy_set_header Host $host; | ||
| 2 | proxy_set_header Upgrade $http_upgrade; | ||
| 3 | proxy_set_header Connection upgrade; | ||
| 4 | proxy_set_header Accept-Encoding gzip; | ||
| 5 | proxy_set_header X-Real-IP $remote_addr; | ||
| 6 | proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; | ||
| 7 | proxy_set_header X-Forwarded-Proto $scheme; | ||
| 8 | proxy_set_header X-Forwarded-Host $http_host; | ||
| 9 | proxy_set_header X-Forwarded-Uri $request_uri; | ||
| 10 | proxy_set_header X-Forwarded-Ssl on; | ||
| 11 | proxy_redirect http:// $scheme://; | ||
| 12 | proxy_http_version 1.1; | ||
| 13 | proxy_set_header Connection ""; | ||
| 14 | proxy_cache_bypass $cookie_session; | ||
| 15 | proxy_no_cache $cookie_session; | ||
| 16 | proxy_buffers 64 256k; | ||
linux/nginx/etc/nginx/custom.d/security/content-security-policy.conf added +28
| @@ -0,0 +1,28 @@ | |||
| 1 | # ---------------------------------------------------------------------- | ||
| 2 | # | Content Security Policy (CSP) | | ||
| 3 | # ---------------------------------------------------------------------- | ||
| 4 | |||
| 5 | # Mitigate the risk of cross-site scripting and other content-injection | ||
| 6 | # attacks. | ||
| 7 | # | ||
| 8 | # This can be done by setting a Content Security Policy which permits | ||
| 9 | # trusted sources of content for your website. | ||
| 10 | # | ||
| 11 | # There is no policy that fits all websites, you will have to modify the | ||
| 12 | # `Content-Security-Policy` directives in the example depending on your needs. | ||
| 13 | # | ||
| 14 | # To make your CSP implementation easier, you can use an online CSP header | ||
| 15 | # generator such as: | ||
| 16 | # https://report-uri.com/home/generate/ | ||
| 17 | # | ||
| 18 | # It is encouraged that you validate your CSP header using a CSP validator | ||
| 19 | # such as: | ||
| 20 | # https://csp-evaluator.withgoogle.com | ||
| 21 | # | ||
| 22 | # https://www.w3.org/TR/CSP/ | ||
| 23 | # https://owasp.org/www-project-secure-headers/#content-security-policy | ||
| 24 | # https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy | ||
| 25 | # https://developers.google.com/web/fundamentals/security/csp | ||
| 26 | # https://content-security-policy.com/ | ||
| 27 | |||
| 28 | add_header Content-Security-Policy $content_security_policy always; | ||
linux/nginx/etc/nginx/custom.d/security/cross-origin-policy.conf added +44
| @@ -0,0 +1,44 @@ | |||
| 1 | # ---------------------------------------------------------------------- | ||
| 2 | # | Cross Origin Policy | | ||
| 3 | # ---------------------------------------------------------------------- | ||
| 4 | |||
| 5 | # Set strict a Cross Origin Policy to mitigate information leakage. | ||
| 6 | # | ||
| 7 | # (1) Cross-Origin-Embedder-Policy prevents a document from loading any | ||
| 8 | # cross-origin resources that don’t explicitly grant the document | ||
| 9 | # permission. | ||
| 10 | # https://html.spec.whatwg.org/multipage/origin.html#coep | ||
| 11 | # https://owasp.org/www-project-secure-headers/#cross-origin-embedder-policy | ||
| 12 | # https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Cross-Origin-Embedder-Policy | ||
| 13 | # | ||
| 14 | # (2) Cross-Origin-Opener-Policy allows you to ensure a top-level document does | ||
| 15 | # not share a browsing context group with cross-origin documents. | ||
| 16 | # https://html.spec.whatwg.org/multipage/origin.html#cross-origin-opener-policies | ||
| 17 | # https://owasp.org/www-project-secure-headers/#cross-origin-opener-policy | ||
| 18 | # https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Cross-Origin-Opener-Policy | ||
| 19 | # | ||
| 20 | # (3) Cross-Origin-Resource-Policy allows to define a policy that lets web | ||
| 21 | # sites and applications opt in to protection against certain requests from | ||
| 22 | # other origins, to mitigate speculative side-channel attacks. | ||
| 23 | # https://fetch.spec.whatwg.org/#cross-origin-resource-policy-header | ||
| 24 | # https://owasp.org/www-project-secure-headers/#cross-origin-resource-policy | ||
| 25 | # https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Cross-Origin-Resource-Policy | ||
| 26 | # https://resourcepolicy.fyi/ | ||
| 27 | # | ||
| 28 | # To check your Cross Origin Policy, you can use an online service, such as: | ||
| 29 | # https://securityheaders.com/ | ||
| 30 | # https://observatory.mozilla.org/ | ||
| 31 | # | ||
| 32 | # https://web.dev/coop-coep/ | ||
| 33 | # https://web.dev/why-coop-coep/ | ||
| 34 | # https://web.dev/cross-origin-isolation-guide/ | ||
| 35 | # https://scotthelme.co.uk/coop-and-coep/ | ||
| 36 | |||
| 37 | # (1) | ||
| 38 | add_header Cross-Origin-Embedder-Policy $coep_policy always; | ||
| 39 | |||
| 40 | # (2) | ||
| 41 | add_header Cross-Origin-Opener-Policy $coop_policy always; | ||
| 42 | |||
| 43 | # (3) | ||
| 44 | add_header Cross-Origin-Resource-Policy $corp_policy always; | ||
linux/nginx/etc/nginx/custom.d/security/permissions-policy.conf added +24
| @@ -0,0 +1,24 @@ | |||
| 1 | # ---------------------------------------------------------------------- | ||
| 2 | # | Permissions Policy | | ||
| 3 | # ---------------------------------------------------------------------- | ||
| 4 | |||
| 5 | # Set a strict Permissions Policy to mitigate access to browser features. | ||
| 6 | # | ||
| 7 | # The header uses a structured syntax, and allows sites to more tightly | ||
| 8 | # restrict which origins can be granted access to features. | ||
| 9 | # The list of available features: | ||
| 10 | # https://github.com/w3c/webappsec-permissions-policy/blob/main/features.md | ||
| 11 | # | ||
| 12 | # The example policy below aims to disable all features expect synchronous | ||
| 13 | # `XMLHttpRequest` requests on the same origin. | ||
| 14 | # | ||
| 15 | # To check your Permissions Policy, you can use an online service, such as: | ||
| 16 | # https://securityheaders.com/ | ||
| 17 | # https://observatory.mozilla.org/ | ||
| 18 | # | ||
| 19 | # https://www.w3.org/TR/permissions-policy-1/ | ||
| 20 | # https://owasp.org/www-project-secure-headers/#permissions-policy | ||
| 21 | # https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Feature-Policy | ||
| 22 | # https://scotthelme.co.uk/a-new-security-header-feature-policy/ | ||
| 23 | |||
| 24 | add_header Permissions-Policy $permissions_policy always; | ||
linux/nginx/etc/nginx/custom.d/security/referrer-policy.conf added +25
| @@ -0,0 +1,25 @@ | |||
| 1 | # ---------------------------------------------------------------------- | ||
| 2 | # | Referrer Policy | | ||
| 3 | # ---------------------------------------------------------------------- | ||
| 4 | |||
| 5 | # Set a strict Referrer Policy to mitigate information leakage. | ||
| 6 | # | ||
| 7 | # (1) The `Referrer-Policy` header is included in responses for resources | ||
| 8 | # that are able to request (or navigate to) other resources. | ||
| 9 | # | ||
| 10 | # This includes the commonly used resource types: | ||
| 11 | # HTML, CSS, XML/SVG, PDF documents, scripts and workers. | ||
| 12 | # | ||
| 13 | # To prevent referrer leakage entirely, specify the `no-referrer` value | ||
| 14 | # instead. Note that the effect could impact analytics metrics negatively. | ||
| 15 | # | ||
| 16 | # To check your Referrer Policy, you can use an online service, such as: | ||
| 17 | # https://securityheaders.com/ | ||
| 18 | # https://observatory.mozilla.org/ | ||
| 19 | # | ||
| 20 | # https://www.w3.org/TR/referrer-policy/ | ||
| 21 | # https://owasp.org/www-project-secure-headers/#referrer-policy | ||
| 22 | # https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Referrer-Policy | ||
| 23 | # https://scotthelme.co.uk/a-new-security-header-referrer-policy/ | ||
| 24 | |||
| 25 | add_header Referrer-Policy $referrer_policy always; | ||
linux/nginx/etc/nginx/custom.d/security/robots.txt added +3
| @@ -0,0 +1,3 @@ | |||
| 1 | User-agent: * | ||
| 2 | Disallow: / | ||
| 3 | Allow: /$ | ||
linux/nginx/etc/nginx/custom.d/security/robots_index_only.conf added +4
| @@ -0,0 +1,4 @@ | |||
| 1 | location = /robots.txt { | ||
| 2 | default_type text/plain; | ||
| 3 | alias /etc/nginx/custom.d/security/robots.txt; | ||
| 4 | } | ||
linux/nginx/etc/nginx/custom.d/security/server_software_information.conf added +9
| @@ -0,0 +1,9 @@ | |||
| 1 | # ---------------------------------------------------------------------- | ||
| 2 | # | Server software information | | ||
| 3 | # ---------------------------------------------------------------------- | ||
| 4 | |||
| 5 | # Prevent Nginx from sending its version number in the "Server" response header. | ||
| 6 | # | ||
| 7 | # https://nginx.org/en/docs/http/ngx_http_core_module.html#server_tokens | ||
| 8 | |||
| 9 | server_tokens off; | ||
linux/nginx/etc/nginx/custom.d/security/strict-transport-security.conf added +38
| @@ -0,0 +1,38 @@ | |||
| 1 | # ---------------------------------------------------------------------- | ||
| 2 | # | HTTP Strict Transport Security (HSTS) | | ||
| 3 | # ---------------------------------------------------------------------- | ||
| 4 | |||
| 5 | # Force client-side TLS (Transport Layer Security) redirection. | ||
| 6 | # | ||
| 7 | # If a user types `example.com` in their browser, even if the server redirects | ||
| 8 | # them to the secure version of the website, that still leaves a window of | ||
| 9 | # opportunity (the initial HTTP connection) for an attacker to downgrade or | ||
| 10 | # redirect the request. | ||
| 11 | # | ||
| 12 | # The following header ensures that a browser only connects to your server | ||
| 13 | # via HTTPS, regardless of what the users type in the browser's address bar. | ||
| 14 | # | ||
| 15 | # (!) Be aware that Strict Transport Security is not revokable and you | ||
| 16 | # must ensure being able to serve the site over HTTPS for the duration | ||
| 17 | # you've specified in the `max-age` directive. When you don't have a | ||
| 18 | # valid TLS connection anymore (e.g. due to an expired TLS certificate) | ||
| 19 | # your visitors will see a nasty error message even when attempting to | ||
| 20 | # connect over HTTP. | ||
| 21 | # | ||
| 22 | # (1) Preloading Strict Transport Security. | ||
| 23 | # To submit your site for HSTS preloading, it is required that: | ||
| 24 | # * the `includeSubDomains` directive is specified | ||
| 25 | # * the `preload` directive is specified | ||
| 26 | # * the `max-age` is specified with a value of at least 31536000 seconds | ||
| 27 | # (1 year). | ||
| 28 | # https://hstspreload.org/#deployment-recommendations | ||
| 29 | # | ||
| 30 | # https://tools.ietf.org/html/rfc6797#section-6.1 | ||
| 31 | # https://owasp.org/www-project-secure-headers/#http-strict-transport-security | ||
| 32 | # https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Strict-Transport-Security | ||
| 33 | # https://www.html5rocks.com/en/tutorials/security/transport-layer-security/ | ||
| 34 | # https://hstspreload.org/ | ||
| 35 | |||
| 36 | # add_header Strict-Transport-Security "max-age=16070400; includeSubDomains" always; | ||
| 37 | # (1) Enable your site for HSTS preload inclusion. | ||
| 38 | add_header Strict-Transport-Security "max-age=31536000; includeSubDomains; preload" always; | ||
linux/nginx/etc/nginx/custom.d/security/x-content-type-options.conf added +17
| @@ -0,0 +1,17 @@ | |||
| 1 | # ---------------------------------------------------------------------- | ||
| 2 | # | Content Type Options | | ||
| 3 | # ---------------------------------------------------------------------- | ||
| 4 | |||
| 5 | # Prevent some browsers from MIME-sniffing the response. | ||
| 6 | # | ||
| 7 | # This reduces exposure to drive-by download attacks and cross-origin data | ||
| 8 | # leaks, and should be left uncommented, especially if the server is serving | ||
| 9 | # user-uploaded content or content that could potentially be treated as | ||
| 10 | # executable by the browser. | ||
| 11 | # | ||
| 12 | # https://owasp.org/www-project-secure-headers/#x-content-type-options | ||
| 13 | # https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/X-Content-Type-Options | ||
| 14 | # https://blogs.msdn.microsoft.com/ie/2008/07/02/ie8-security-part-v-comprehensive-protection/ | ||
| 15 | # https://mimesniff.spec.whatwg.org/ | ||
| 16 | |||
| 17 | add_header X-Content-Type-Options nosniff always; | ||
linux/nginx/etc/nginx/custom.d/security/x-frame-options.conf added +37
| @@ -0,0 +1,37 @@ | |||
| 1 | # ---------------------------------------------------------------------- | ||
| 2 | # | Frame Options | | ||
| 3 | # ---------------------------------------------------------------------- | ||
| 4 | |||
| 5 | # Protect website against clickjacking. | ||
| 6 | # | ||
| 7 | # The example below sends the `X-Frame-Options` response header with the value | ||
| 8 | # `DENY`, informing browsers not to display the content of the web page in any | ||
| 9 | # frame. | ||
| 10 | # | ||
| 11 | # This might not be the best setting for everyone. You should read about the | ||
| 12 | # other two possible values the `X-Frame-Options` header field can have: | ||
| 13 | # `SAMEORIGIN` and `ALLOW-FROM`. | ||
| 14 | # https://tools.ietf.org/html/rfc7034#section-2.1. | ||
| 15 | # | ||
| 16 | # Keep in mind that while you could send the `X-Frame-Options` header for all | ||
| 17 | # of your website's pages, this has the potential downside that it forbids even | ||
| 18 | # non-malicious framing of your content. | ||
| 19 | # | ||
| 20 | # Nonetheless, you should ensure that you send the `X-Frame-Options` header for | ||
| 21 | # all pages that allow a user to make a state-changing operation (e.g: pages | ||
| 22 | # that contain one-click purchase links, checkout or bank-transfer confirmation | ||
| 23 | # pages, pages that make permanent configuration changes, etc.). | ||
| 24 | # | ||
| 25 | # Sending the `X-Frame-Options` header can also protect your website against | ||
| 26 | # more than just clickjacking attacks. | ||
| 27 | # https://cure53.de/xfo-clickjacking.pdf. | ||
| 28 | # | ||
| 29 | # (!) The `Content-Security-Policy` header has a `frame-ancestors` directive | ||
| 30 | # which obsoletes this header for supporting browsers. | ||
| 31 | # | ||
| 32 | # https://tools.ietf.org/html/rfc7034 | ||
| 33 | # https://owasp.org/www-project-secure-headers/#x-frame-options | ||
| 34 | # https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/X-Frame-Options | ||
| 35 | # https://docs.microsoft.com/archive/blogs/ieinternals/combating-clickjacking-with-x-frame-options | ||
| 36 | |||
| 37 | add_header X-Frame-Options $x_frame_options always; | ||
linux/nginx/etc/nginx/custom.d/tls/certificate_files.conf added +33
| @@ -0,0 +1,33 @@ | |||
| 1 | # ---------------------------------------------------------------------- | ||
| 2 | # | Certificate files | | ||
| 3 | # ---------------------------------------------------------------------- | ||
| 4 | |||
| 5 | # This default SSL certificate will be served whenever the client lacks support | ||
| 6 | # for SNI (Server Name Indication). | ||
| 7 | # | ||
| 8 | # (1) Certificate and key files location | ||
| 9 | # The certificate file can contain an intermediate certificate. | ||
| 10 | # | ||
| 11 | # https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_certificate | ||
| 12 | # | ||
| 13 | # (2) Intermediate certificate location if loaded certificate (1) does not | ||
| 14 | # contain intermediate certificate when enabling OCSP stapling. | ||
| 15 | # | ||
| 16 | # https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_trusted_certificate | ||
| 17 | # | ||
| 18 | # (3) CA certificate file location for client certificate authentication. | ||
| 19 | # | ||
| 20 | # https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_client_certificate | ||
| 21 | |||
| 22 | # (1) | ||
| 23 | # ssl_certificate /etc/nginx/certs/default.crt; | ||
| 24 | # ssl_certificate_key /etc/nginx/certs/default.key; | ||
| 25 | ssl_certificate /etc/letsencrypt/live/cleberg.net/fullchain.pem; | ||
| 26 | ssl_certificate_key /etc/letsencrypt/live/cleberg.net/privkey.pem; | ||
| 27 | |||
| 28 | # (2) | ||
| 29 | # ssl_trusted_certificate /path/to/ca.crt; | ||
| 30 | ssl_trusted_certificate /etc/letsencrypt/live/cleberg.net/chain.pem; | ||
| 31 | |||
| 32 | # (3) | ||
| 33 | # ssl_client_certificate /etc/nginx/default_ssl.crt; | ||
linux/nginx/etc/nginx/custom.d/tls/ocsp_stapling.conf added +34
| @@ -0,0 +1,34 @@ | |||
| 1 | # ---------------------------------------------------------------------- | ||
| 2 | # | Online Certificate Status Protocol stapling | | ||
| 3 | # ---------------------------------------------------------------------- | ||
| 4 | |||
| 5 | # OCSP is a lightweight, only one record to help clients verify the validity of | ||
| 6 | # the server certificate. | ||
| 7 | # OCSP stapling allows the server to send its cached OCSP record during the TLS | ||
| 8 | # handshake, without the need of 3rd party OCSP responder. | ||
| 9 | # | ||
| 10 | # https://wiki.mozilla.org/Security/Server_Side_TLS#OCSP_Stapling | ||
| 11 | # https://tools.ietf.org/html/rfc6066#section-8 | ||
| 12 | # https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_stapling | ||
| 13 | # | ||
| 14 | # (1) Use Cloudflare 1.1.1.1 DNS resolver | ||
| 15 | # https://developers.cloudflare.com/1.1.1.1/setting-up-1.1.1.1/ | ||
| 16 | # | ||
| 17 | # (2) Use Google 8.8.8.8 DNS resolver | ||
| 18 | # https://developers.google.com/speed/public-dns/docs/using | ||
| 19 | # | ||
| 20 | # (3) Use OpenDNS resolver | ||
| 21 | # https://use.opendns.com | ||
| 22 | |||
| 23 | ssl_stapling on; | ||
| 24 | ssl_stapling_verify on; | ||
| 25 | |||
| 26 | resolver | ||
| 27 | # (1) | ||
| 28 | 1.1.1.1 1.0.0.1 [2606:4700:4700::1111] [2606:4700:4700::1001] | ||
| 29 | # (2) | ||
| 30 | 8.8.8.8 8.8.4.4 [2001:4860:4860::8888] [2001:4860:4860::8844] | ||
| 31 | # (3) | ||
| 32 | # 208.67.222.222 208.67.220.220 [2620:119:35::35] [2620:119:53::53] | ||
| 33 | valid=60s; | ||
| 34 | resolver_timeout 2s; | ||
linux/nginx/etc/nginx/custom.d/tls/policy_balanced.conf added +20
| @@ -0,0 +1,20 @@ | |||
| 1 | # ---------------------------------------------------------------------- | ||
| 2 | # | SSL policy - Balanced | | ||
| 3 | # ---------------------------------------------------------------------- | ||
| 4 | |||
| 5 | # For services that need to support a wide range of clients, this configuration | ||
| 6 | # is reasonably balanced. | ||
| 7 | # | ||
| 8 | # (1) The NIST curves (prime256v1, secp384r1, secp521r1) are known to be weak | ||
| 9 | # and potentially vulnerable but are required to support Microsoft Edge | ||
| 10 | # and Safari. | ||
| 11 | # https://safecurves.cr.yp.to/ | ||
| 12 | # | ||
| 13 | # https://wiki.mozilla.org/Security/Server_Side_TLS#Recommended_configurations | ||
| 14 | # https://nginx.org/en/docs/http/ngx_http_ssl_module.html | ||
| 15 | |||
| 16 | ssl_protocols TLSv1.2; | ||
| 17 | ssl_ciphers EECDH+CHACHA20:EECDH+AES; | ||
| 18 | |||
| 19 | # (1) | ||
| 20 | ssl_ecdh_curve X25519:prime256v1:secp521r1:secp384r1; | ||
linux/nginx/etc/nginx/custom.d/tls/policy_strict.conf added +50
| @@ -0,0 +1,50 @@ | |||
| 1 | # ---------------------------------------------------------------------- | ||
| 2 | # | SSL policy - Strict | | ||
| 3 | # ---------------------------------------------------------------------- | ||
| 4 | |||
| 5 | # For services that don't need backward compatibility, the parameters below | ||
| 6 | # provide the highest level of security and performance. | ||
| 7 | # | ||
| 8 | # (!) This policy enforces a strong TLS configuration, which may raise | ||
| 9 | # errors with old clients. | ||
| 10 | # If a more compatible profile is required, use the "balanced" policy. | ||
| 11 | # | ||
| 12 | # (!) TLSv1.3 and its 0-RTT feature require NGINX >=1.15.4 and OpenSSL >=1.1.1 | ||
| 13 | # to be installed. | ||
| 14 | # | ||
| 15 | # (!) Don't enable `ssl_early_data` blindly! Requests sent within early data are | ||
| 16 | # subject to replay attacks. | ||
| 17 | # | ||
| 18 | # (1) The NIST curves (prime256v1, secp384r1, secp521r1) are known to be weak | ||
| 19 | # and potentially vulnerable. | ||
| 20 | # | ||
| 21 | # Add them back to the parameter `ssl_ecdh_curve` below to support | ||
| 22 | # Microsoft Edge and Safari. | ||
| 23 | # | ||
| 24 | # https://safecurves.cr.yp.to/ | ||
| 25 | # | ||
| 26 | # (2) Enables TLS 1.3 0-RTT, allows for faster resumption of TLS sessions. | ||
| 27 | # | ||
| 28 | # (!) Requests sent within early data are subject to replay attacks. | ||
| 29 | # To protect against such attacks at the application layer, the | ||
| 30 | # `$ssl_early_data` variable should be used: | ||
| 31 | # | ||
| 32 | # proxy_set_header Early-Data $ssl_early_data; | ||
| 33 | # | ||
| 34 | # The application should return response code 425 "Too Early" for anything | ||
| 35 | # that could contain user supplied data. | ||
| 36 | # | ||
| 37 | # https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/425 | ||
| 38 | # | ||
| 39 | # https://github.com/certbot/certbot/issues/6367 | ||
| 40 | # https://github.com/mozilla/server-side-tls/issues/217 | ||
| 41 | # https://nginx.org/en/docs/http/ngx_http_ssl_module.html | ||
| 42 | |||
| 43 | ssl_protocols TLSv1.2 TLSv1.3; | ||
| 44 | ssl_ciphers EECDH+CHACHA20:EECDH+AES; | ||
| 45 | |||
| 46 | # (1) | ||
| 47 | ssl_ecdh_curve X25519; | ||
| 48 | |||
| 49 | # (2) | ||
| 50 | #ssl_early_data on; | ||
linux/nginx/etc/nginx/custom.d/tls/ssl_engine.conf added +47
| @@ -0,0 +1,47 @@ | |||
| 1 | # ---------------------------------------------------------------------- | ||
| 2 | # | SSL engine | | ||
| 3 | # ---------------------------------------------------------------------- | ||
| 4 | |||
| 5 | # (1) Optimize SSL by caching session parameters for 24 hours. | ||
| 6 | # This cuts down on the number of expensive SSL handshakes. | ||
| 7 | # By enabling a cache, we tell the client to re-use the already | ||
| 8 | # negotiated state. | ||
| 9 | # Here 10m (10 MB) in ssl_session_cache is size value (not time). | ||
| 10 | # 1 MB cache can store about 4000 sessions, so we can store 40000 sessions. | ||
| 11 | # | ||
| 12 | # (2) Use a higher keepalive timeout to reduce the need for repeated handshakes | ||
| 13 | # (!) Shouldn't be done unless you serve primarily HTTPS. | ||
| 14 | # Default is 75s | ||
| 15 | # | ||
| 16 | # (3) SSL buffer size | ||
| 17 | # Set 1400 bytes to fit in one MTU. | ||
| 18 | # https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_buffer_size | ||
| 19 | # | ||
| 20 | # (4) Disable session tickets | ||
| 21 | # Session tickets keys are not auto-rotated. Only a HUP / restart will do | ||
| 22 | # so and when a restart is performed the previous key is lost, which resets | ||
| 23 | # all previous sessions. | ||
| 24 | # Only enable session tickets if you set up a manual rotation mechanism. | ||
| 25 | # https://trac.nginx.org/nginx/changeset/1356a3b9692441e163b4e78be4e9f5a46c7479e9/nginx | ||
| 26 | # https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_session_tickets | ||
| 27 | # | ||
| 28 | # (5) The TLS 1.2 and 1.3 ciphers in use in current policies are not considered | ||
| 29 | # dangerous. This directive let the client choose the one that best fits their needs. | ||
| 30 | # https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_prefer_server_ciphers | ||
| 31 | # https://wiki.mozilla.org/Security/Server_Side_TLS | ||
| 32 | |||
| 33 | # (1) | ||
| 34 | ssl_session_timeout 24h; | ||
| 35 | ssl_session_cache shared:SSL:10m; | ||
| 36 | |||
| 37 | # (2) | ||
| 38 | keepalive_timeout 300s; | ||
| 39 | |||
| 40 | # (3) | ||
| 41 | # ssl_buffer_size 1400; | ||
| 42 | |||
| 43 | # (4) | ||
| 44 | ssl_session_tickets off; | ||
| 45 | |||
| 46 | # (5) | ||
| 47 | ssl_prefer_server_ciphers off; | ||
linux/nginx/etc/nginx/custom.d/web_performance/cache-control.conf added +43
| @@ -0,0 +1,43 @@ | |||
| 1 | # ---------------------------------------------------------------------- | ||
| 2 | # | Cache Control | | ||
| 3 | # ---------------------------------------------------------------------- | ||
| 4 | |||
| 5 | # Serve resources with appropriate cache control directives. | ||
| 6 | # | ||
| 7 | # The `Cache-Control` header field holds directives (instructions) that control | ||
| 8 | # caching in browsers and shared caches (e.g. Proxies, CDNs). | ||
| 9 | # Its use targets web performances improvement by specifying the expected | ||
| 10 | # client and network caches behaviors. | ||
| 11 | # | ||
| 12 | # The usable cache directives are listed here: | ||
| 13 | # https://www.iana.org/assignments/http-cache-directives/http-cache-directives.xml | ||
| 14 | # | ||
| 15 | # The cache directives are documented here: | ||
| 16 | # https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Cache-Control#response_directives | ||
| 17 | # | ||
| 18 | # (!) Enable and configure this configuration with care. | ||
| 19 | # Default values should embrace conformance for static files and simple | ||
| 20 | # apps, but cache control definition at backend level is highly preferred. | ||
| 21 | # Incorrect directives can lead to data leaks, or can degrade performances. | ||
| 22 | # | ||
| 23 | # More specifically, in-depth understanding on `public` vs `private` | ||
| 24 | # directives meanings is highly recommended. A resource with `public` will | ||
| 25 | # be cached by shared caches like CDN, even if a user session is active. | ||
| 26 | # | ||
| 27 | # (*) To avoid duplication of the directive `no-cache` on `Cache-Control`, | ||
| 28 | # the value is skipped here. | ||
| 29 | # The directive `no-cache` is already defined by Nginx `expires` when set | ||
| 30 | # to `epoch`. This ensure a correct value enforcement whenever cache | ||
| 31 | # control configuration is used or not. | ||
| 32 | # Cache expiration configuration `expires` is described in the file | ||
| 33 | # custom.d/web_performance/cache_expiration.conf. | ||
| 34 | # https://nginx.org/en/docs/http/ngx_http_headers_module.html#expires | ||
| 35 | # | ||
| 36 | # https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Cache-Control | ||
| 37 | # https://www.rfc-editor.org/rfc/rfc9111.html | ||
| 38 | # https://www.rfc-editor.org/rfc/rfc8246.html | ||
| 39 | # https://www.rfc-editor.org/rfc/rfc5861.html | ||
| 40 | # https://www.iana.org/assignments/http-cache-directives/http-cache-directives.xml | ||
| 41 | # https://cache-tests.fyi/ | ||
| 42 | |||
| 43 | add_header Cache-Control $cache_control; | ||
linux/nginx/etc/nginx/custom.d/web_performance/cache-file-descriptors.conf added +34
| @@ -0,0 +1,34 @@ | |||
| 1 | # ---------------------------------------------------------------------- | ||
| 2 | # | Cache file-descriptors | | ||
| 3 | # ---------------------------------------------------------------------- | ||
| 4 | |||
| 5 | # This tells Nginx to cache open file handles, "Not Found" errors and | ||
| 6 | # metadata about files and their permissions. | ||
| 7 | # | ||
| 8 | # Based on these cached metadata, Nginx can immediately begin sending data when | ||
| 9 | # a popular file is requested, and will also know to immediately send a 404 if a | ||
| 10 | # file is missing on disk, and so on. | ||
| 11 | # | ||
| 12 | # (!) It also means that the server won't react immediately to changes on disk, | ||
| 13 | # which may be undesirable. | ||
| 14 | # As only metadata are cached, edited files may be truncated until the cache | ||
| 15 | # is refreshed. | ||
| 16 | # https://github.com/h5bp/server-configs-nginx/issues/203 | ||
| 17 | # | ||
| 18 | # In the below configuration, inactive files are released from the cache after | ||
| 19 | # 20 seconds, whereas active (recently requested) files are re-validated every | ||
| 20 | # 30 seconds. | ||
| 21 | # Descriptors will not be cached unless they are used at least 2 times within | ||
| 22 | # 20 seconds (the inactive time). | ||
| 23 | # A maximum of the 1000 most recently used file descriptors can be cached at | ||
| 24 | # any time. | ||
| 25 | # | ||
| 26 | # Production servers with stable file collections will definitely want to enable | ||
| 27 | # the cache. | ||
| 28 | # | ||
| 29 | # https://nginx.org/en/docs/http/ngx_http_core_module.html#open_file_cache | ||
| 30 | |||
| 31 | open_file_cache max=1000 inactive=20s; | ||
| 32 | open_file_cache_valid 30s; | ||
| 33 | open_file_cache_min_uses 2; | ||
| 34 | open_file_cache_errors on; | ||
linux/nginx/etc/nginx/custom.d/web_performance/cache_expiration.conf added +63
| @@ -0,0 +1,63 @@ | |||
| 1 | # ---------------------------------------------------------------------- | ||
| 2 | # | Cache expiration | | ||
| 3 | # ---------------------------------------------------------------------- | ||
| 4 | |||
| 5 | # Serve resources with a far-future expiration date. | ||
| 6 | # | ||
| 7 | # (!) If you don't control versioning with filename-based cache busting, you | ||
| 8 | # should consider lowering the cache times to something like one week. | ||
| 9 | # | ||
| 10 | # https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Cache-Control | ||
| 11 | # https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Expires | ||
| 12 | # https://nginx.org/en/docs/http/ngx_http_headers_module.html#expires | ||
| 13 | |||
| 14 | map $sent_http_content_type $expires { | ||
| 15 | # Default: Fallback | ||
| 16 | default 1y; | ||
| 17 | |||
| 18 | # Default: No content | ||
| 19 | "" off; | ||
| 20 | |||
| 21 | # Specific: Assets | ||
| 22 | ~*image/svg\+xml 1y; | ||
| 23 | ~*image/vnd.microsoft.icon 1w; | ||
| 24 | ~*image/x-icon 1w; | ||
| 25 | |||
| 26 | # Specific: Manifests | ||
| 27 | ~*application/manifest\+json 1w; | ||
| 28 | ~*text/cache-manifest epoch; | ||
| 29 | |||
| 30 | # Specific: Data interchange | ||
| 31 | ~*application/atom\+xml 1h; | ||
| 32 | ~*application/rdf\+xml 1h; | ||
| 33 | ~*application/rss\+xml 1h; | ||
| 34 | |||
| 35 | # Specific: Documents | ||
| 36 | ~*text/html epoch; | ||
| 37 | ~*text/markdown epoch; | ||
| 38 | ~*text/calendar epoch; | ||
| 39 | |||
| 40 | # Specific: Other | ||
| 41 | ~*text/x-cross-domain-policy 1w; | ||
| 42 | |||
| 43 | # Generic: Data | ||
| 44 | ~*json epoch; | ||
| 45 | ~*xml epoch; | ||
| 46 | |||
| 47 | # Generic: WebAssembly | ||
| 48 | # ~*application/wasm 1y; # default | ||
| 49 | |||
| 50 | # Generic: Assets | ||
| 51 | # ~*application/javascript 1y; # default | ||
| 52 | # ~*application/x-javascript 1y; # default | ||
| 53 | # ~*text/javascript 1y; # default | ||
| 54 | # ~*text/css 1y; # default | ||
| 55 | |||
| 56 | # Generic: Medias | ||
| 57 | # ~*audio/ 1y; # default | ||
| 58 | # ~*image/ 1y; # default | ||
| 59 | # ~*video/ 1y; # default | ||
| 60 | # ~*font/ 1y; # default | ||
| 61 | } | ||
| 62 | |||
| 63 | expires $expires; | ||
linux/nginx/etc/nginx/custom.d/web_performance/compression.conf added +71
| @@ -0,0 +1,71 @@ | |||
| 1 | # ---------------------------------------------------------------------- | ||
| 2 | # | Compression | | ||
| 3 | # ---------------------------------------------------------------------- | ||
| 4 | |||
| 5 | # https://nginx.org/en/docs/http/ngx_http_gzip_module.html | ||
| 6 | |||
| 7 | # Enable gzip compression. | ||
| 8 | # Default: off | ||
| 9 | gzip on; | ||
| 10 | |||
| 11 | # Compression level (1-9). | ||
| 12 | # 5 is a perfect compromise between size and CPU usage, offering about 75% | ||
| 13 | # reduction for most ASCII files (almost identical to level 9). | ||
| 14 | # Default: 1 | ||
| 15 | gzip_comp_level 5; | ||
| 16 | |||
| 17 | # Don't compress anything that's already small and unlikely to shrink much if at | ||
| 18 | # all (the default is 20 bytes, which is bad as that usually leads to larger | ||
| 19 | # files after gzipping). | ||
| 20 | # Default: 20 | ||
| 21 | gzip_min_length 256; | ||
| 22 | |||
| 23 | # Compress data even for clients that are connecting to us via proxies, | ||
| 24 | # identified by the "Via" header (required for CloudFront). | ||
| 25 | # Default: off | ||
| 26 | gzip_proxied any; | ||
| 27 | |||
| 28 | # Tell proxies to cache both the gzipped and regular version of a resource | ||
| 29 | # whenever the client's Accept-Encoding capabilities header varies; | ||
| 30 | # Avoids the issue where a non-gzip capable client (which is extremely rare | ||
| 31 | # today) would display gibberish if their proxy gave them the gzipped version. | ||
| 32 | # Default: off | ||
| 33 | gzip_vary on; | ||
| 34 | |||
| 35 | # Compress all output labeled with one of the following MIME-types. | ||
| 36 | # `text/html` is always compressed by gzip module. | ||
| 37 | # Default: text/html | ||
| 38 | gzip_types | ||
| 39 | application/atom+xml | ||
| 40 | application/geo+json | ||
| 41 | application/javascript | ||
| 42 | application/x-javascript | ||
| 43 | application/json | ||
| 44 | application/ld+json | ||
| 45 | application/manifest+json | ||
| 46 | application/rdf+xml | ||
| 47 | application/rss+xml | ||
| 48 | application/vnd.ms-fontobject | ||
| 49 | application/wasm | ||
| 50 | application/x-web-app-manifest+json | ||
| 51 | application/xhtml+xml | ||
| 52 | application/xml | ||
| 53 | font/eot | ||
| 54 | font/otf | ||
| 55 | font/ttf | ||
| 56 | image/bmp | ||
| 57 | image/svg+xml | ||
| 58 | image/vnd.microsoft.icon | ||
| 59 | image/x-icon | ||
| 60 | text/cache-manifest | ||
| 61 | text/calendar | ||
| 62 | text/css | ||
| 63 | text/javascript | ||
| 64 | text/markdown | ||
| 65 | text/plain | ||
| 66 | text/xml | ||
| 67 | text/vcard | ||
| 68 | text/vnd.rim.location.xloc | ||
| 69 | text/vtt | ||
| 70 | text/x-component | ||
| 71 | text/x-cross-domain-policy; | ||
linux/nginx/etc/nginx/custom.d/web_performance/content_transformation.conf added +30
| @@ -0,0 +1,30 @@ | |||
| 1 | # ---------------------------------------------------------------------- | ||
| 2 | # | Content transformation | | ||
| 3 | # ---------------------------------------------------------------------- | ||
| 4 | |||
| 5 | # Prevent intermediate caches or proxies (such as those used by mobile | ||
| 6 | # network providers) and browsers data-saving features from modifying | ||
| 7 | # the website's content using the `no-transform` directive for | ||
| 8 | # `Cache-Control` header. | ||
| 9 | # | ||
| 10 | # https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Cache-Control | ||
| 11 | # https://tools.ietf.org/html/rfc7234#section-5.2.2.4 | ||
| 12 | # | ||
| 13 | # (!) Carefully consider the impact on your visitors before disabling | ||
| 14 | # content transformation. These transformations are performed to | ||
| 15 | # improve the experience for data- and cost-constrained users | ||
| 16 | # (e.g. users on a 2G connection). | ||
| 17 | # | ||
| 18 | # You can test the effects of content transformation applied by | ||
| 19 | # Google's Lite Mode by visiting: https://googleweblight.com/i?u=https://www.example.com | ||
| 20 | # | ||
| 21 | # https://support.google.com/webmasters/answer/6211428 | ||
| 22 | # | ||
| 23 | # (!) If you are using `ngx_pagespeed`, note that disabling this will | ||
| 24 | # prevent `PageSpeed` from rewriting HTML files, and, if the | ||
| 25 | # `pagespeed DisableRewriteOnNoTransform` directive isn't set to | ||
| 26 | # `off`, also from rewriting other resources. | ||
| 27 | # | ||
| 28 | # https://developers.google.com/speed/pagespeed/module/configuration#notransform | ||
| 29 | |||
| 30 | add_header Cache-Control "no-transform"; | ||
linux/nginx/etc/nginx/custom.d/web_performance/pre-compressed_content_brotli.conf added +17
| @@ -0,0 +1,17 @@ | |||
| 1 | # ---------------------------------------------------------------------- | ||
| 2 | # | Brotli pre-compressed content | | ||
| 3 | # ---------------------------------------------------------------------- | ||
| 4 | |||
| 5 | # Serve brotli compressed CSS, JS, HTML, SVG, ICS and JSON files if they exist | ||
| 6 | # and if the client accepts br encoding. | ||
| 7 | # | ||
| 8 | # (!) To make this part relevant, you need to generate encoded files by your | ||
| 9 | # own. Enabling this part will not auto-generate brotlied files. | ||
| 10 | # | ||
| 11 | # Note that some clients (e.g. browsers) require a secure connection to request | ||
| 12 | # brotli-compressed resources. | ||
| 13 | # https://www.chromestatus.com/feature/5420797577396224 | ||
| 14 | # | ||
| 15 | # https://github.com/eustas/ngx_brotli/#brotli_static | ||
| 16 | |||
| 17 | brotli_static on; | ||
linux/nginx/etc/nginx/custom.d/web_performance/pre-compressed_content_gzip.conf added +13
| @@ -0,0 +1,13 @@ | |||
| 1 | # ---------------------------------------------------------------------- | ||
| 2 | # | GZip pre-compressed content | | ||
| 3 | # ---------------------------------------------------------------------- | ||
| 4 | |||
| 5 | # Serve gzip compressed CSS, JS, HTML, SVG, ICS, and JSON files if they exist | ||
| 6 | # and if the client accepts gzip encoding. | ||
| 7 | # | ||
| 8 | # (!) To make this part relevant, you need to generate encoded files by your | ||
| 9 | # own. Enabling this part will not auto-generate gziped files. | ||
| 10 | # | ||
| 11 | # https://nginx.org/en/docs/http/ngx_http_gzip_static_module.html | ||
| 12 | |||
| 13 | gzip_static on; | ||
linux/nginx/etc/nginx/fastcgi_params added +25
| @@ -0,0 +1,25 @@ | |||
| 1 | |||
| 2 | fastcgi_param QUERY_STRING $query_string; | ||
| 3 | fastcgi_param REQUEST_METHOD $request_method; | ||
| 4 | fastcgi_param CONTENT_TYPE $content_type; | ||
| 5 | fastcgi_param CONTENT_LENGTH $content_length; | ||
| 6 | |||
| 7 | fastcgi_param SCRIPT_NAME $fastcgi_script_name; | ||
| 8 | fastcgi_param REQUEST_URI $request_uri; | ||
| 9 | fastcgi_param DOCUMENT_URI $document_uri; | ||
| 10 | fastcgi_param DOCUMENT_ROOT $document_root; | ||
| 11 | fastcgi_param SERVER_PROTOCOL $server_protocol; | ||
| 12 | fastcgi_param REQUEST_SCHEME $scheme; | ||
| 13 | fastcgi_param HTTPS $https if_not_empty; | ||
| 14 | |||
| 15 | fastcgi_param GATEWAY_INTERFACE CGI/1.1; | ||
| 16 | fastcgi_param SERVER_SOFTWARE nginx/$nginx_version; | ||
| 17 | |||
| 18 | fastcgi_param REMOTE_ADDR $remote_addr; | ||
| 19 | fastcgi_param REMOTE_PORT $remote_port; | ||
| 20 | fastcgi_param SERVER_ADDR $server_addr; | ||
| 21 | fastcgi_param SERVER_PORT $server_port; | ||
| 22 | fastcgi_param SERVER_NAME $server_name; | ||
| 23 | |||
| 24 | # PHP only, required if PHP was built with --enable-force-cgi-redirect | ||
| 25 | fastcgi_param REDIRECT_STATUS 200; | ||
linux/nginx/etc/nginx/mime.types added +138
| @@ -0,0 +1,138 @@ | |||
| 1 | types { | ||
| 2 | |||
| 3 | # Data interchange | ||
| 4 | |||
| 5 | application/atom+xml atom; | ||
| 6 | application/json json map topojson; | ||
| 7 | application/ld+json jsonld; | ||
| 8 | application/rss+xml rss; | ||
| 9 | # Normalize to standard type. | ||
| 10 | # https://tools.ietf.org/html/rfc7946#section-12 | ||
| 11 | application/geo+json geojson; | ||
| 12 | application/xml xml; | ||
| 13 | # Normalize to standard type. | ||
| 14 | # https://tools.ietf.org/html/rfc3870#section-2 | ||
| 15 | application/rdf+xml rdf; | ||
| 16 | |||
| 17 | |||
| 18 | # JavaScript | ||
| 19 | |||
| 20 | # Servers should use text/javascript for JavaScript resources. | ||
| 21 | # https://html.spec.whatwg.org/multipage/scripting.html#scriptingLanguages | ||
| 22 | text/javascript js mjs; | ||
| 23 | application/wasm wasm; | ||
| 24 | |||
| 25 | # Manifest files | ||
| 26 | |||
| 27 | application/manifest+json webmanifest; | ||
| 28 | application/x-web-app-manifest+json webapp; | ||
| 29 | text/cache-manifest appcache; | ||
| 30 | |||
| 31 | |||
| 32 | # Media files | ||
| 33 | |||
| 34 | audio/midi mid midi kar; | ||
| 35 | audio/mp4 aac f4a f4b m4a; | ||
| 36 | audio/mpeg mp3; | ||
| 37 | audio/ogg oga ogg opus; | ||
| 38 | audio/x-realaudio ra; | ||
| 39 | audio/x-wav wav; | ||
| 40 | image/apng apng; | ||
| 41 | image/avif avif avifs; | ||
| 42 | image/bmp bmp; | ||
| 43 | image/gif gif; | ||
| 44 | image/jpeg jpeg jpg; | ||
| 45 | image/jxl jxl; | ||
| 46 | image/jxr jxr hdp wdp; | ||
| 47 | image/png png; | ||
| 48 | image/svg+xml svg svgz; | ||
| 49 | image/tiff tif tiff; | ||
| 50 | image/vnd.wap.wbmp wbmp; | ||
| 51 | image/webp webp; | ||
| 52 | image/x-jng jng; | ||
| 53 | video/3gpp 3gp 3gpp; | ||
| 54 | video/mp4 f4p f4v m4v mp4; | ||
| 55 | video/mpeg mpeg mpg; | ||
| 56 | video/ogg ogv; | ||
| 57 | video/quicktime mov; | ||
| 58 | video/webm webm; | ||
| 59 | video/x-flv flv; | ||
| 60 | video/x-mng mng; | ||
| 61 | video/x-ms-asf asf asx; | ||
| 62 | video/x-msvideo avi; | ||
| 63 | |||
| 64 | # Serving `.ico` image files with a different media type | ||
| 65 | # prevents Internet Explorer from displaying then as images: | ||
| 66 | # https://github.com/h5bp/html5-boilerplate/commit/37b5fec090d00f38de64b591bcddcb205aadf8ee | ||
| 67 | |||
| 68 | image/x-icon cur ico; | ||
| 69 | |||
| 70 | |||
| 71 | # Microsoft Office | ||
| 72 | |||
| 73 | application/msword doc; | ||
| 74 | application/vnd.ms-excel xls; | ||
| 75 | application/vnd.ms-powerpoint ppt; | ||
| 76 | application/vnd.openxmlformats-officedocument.wordprocessingml.document docx; | ||
| 77 | application/vnd.openxmlformats-officedocument.spreadsheetml.sheet xlsx; | ||
| 78 | application/vnd.openxmlformats-officedocument.presentationml.presentation pptx; | ||
| 79 | |||
| 80 | |||
| 81 | # Web fonts | ||
| 82 | |||
| 83 | font/woff woff; | ||
| 84 | font/woff2 woff2; | ||
| 85 | application/vnd.ms-fontobject eot; | ||
| 86 | font/ttf ttf; | ||
| 87 | font/collection ttc; | ||
| 88 | font/otf otf; | ||
| 89 | |||
| 90 | |||
| 91 | # Other | ||
| 92 | |||
| 93 | application/java-archive ear jar war; | ||
| 94 | application/mac-binhex40 hqx; | ||
| 95 | application/octet-stream bin deb dll dmg exe img iso msi msm msp safariextz; | ||
| 96 | application/pdf pdf; | ||
| 97 | application/postscript ai eps ps; | ||
| 98 | application/rtf rtf; | ||
| 99 | application/vnd.google-earth.kml+xml kml; | ||
| 100 | application/vnd.google-earth.kmz kmz; | ||
| 101 | application/vnd.wap.wmlc wmlc; | ||
| 102 | application/x-7z-compressed 7z; | ||
| 103 | application/x-bb-appworld bbaw; | ||
| 104 | application/x-bittorrent torrent; | ||
| 105 | application/x-chrome-extension crx; | ||
| 106 | application/x-cocoa cco; | ||
| 107 | application/x-java-archive-diff jardiff; | ||
| 108 | application/x-java-jnlp-file jnlp; | ||
| 109 | application/x-makeself run; | ||
| 110 | application/x-opera-extension oex; | ||
| 111 | application/x-perl pl pm; | ||
| 112 | application/x-pilot pdb prc; | ||
| 113 | application/x-rar-compressed rar; | ||
| 114 | application/x-redhat-package-manager rpm; | ||
| 115 | application/x-sea sea; | ||
| 116 | application/x-shockwave-flash swf; | ||
| 117 | application/x-stuffit sit; | ||
| 118 | application/x-tcl tcl tk; | ||
| 119 | application/x-x509-ca-cert crt der pem; | ||
| 120 | application/x-xpinstall xpi; | ||
| 121 | application/xhtml+xml xhtml; | ||
| 122 | application/xslt+xml xsl; | ||
| 123 | application/zip zip; | ||
| 124 | text/calendar ics; | ||
| 125 | text/css css; | ||
| 126 | text/csv csv; | ||
| 127 | text/html htm html shtml; | ||
| 128 | text/markdown md markdown; | ||
| 129 | text/mathml mml; | ||
| 130 | text/plain txt; | ||
| 131 | text/vcard vcard vcf; | ||
| 132 | text/vnd.rim.location.xloc xloc; | ||
| 133 | text/vnd.sun.j2me.app-descriptor jad; | ||
| 134 | text/vnd.wap.wml wml; | ||
| 135 | text/vtt vtt; | ||
| 136 | text/x-component htc; | ||
| 137 | |||
| 138 | } | ||
linux/nginx/etc/nginx/nginx.conf added +198
| @@ -0,0 +1,198 @@ | |||
| 1 | # Configuration File - Nginx Server Configs | ||
| 2 | # https://nginx.org/en/docs/ | ||
| 3 | |||
| 4 | # Run as a unique, less privileged user for security reasons. | ||
| 5 | # Default: nobody nobody | ||
| 6 | # https://nginx.org/en/docs/ngx_core_module.html#user | ||
| 7 | # https://en.wikipedia.org/wiki/Principle_of_least_privilege | ||
| 8 | # user www-data; | ||
| 9 | user nginx; | ||
| 10 | |||
| 11 | # Sets the worker threads to the number of CPU cores available in the system for | ||
| 12 | # best performance. Should be > the number of CPU cores. | ||
| 13 | # Maximum number of connections = worker_processes * worker_connections | ||
| 14 | # Default: 1 | ||
| 15 | # https://nginx.org/en/docs/ngx_core_module.html#worker_processes | ||
| 16 | worker_processes auto; | ||
| 17 | |||
| 18 | # Maximum number of open files per worker process. | ||
| 19 | # Should be > worker_connections. | ||
| 20 | # Default: no limit | ||
| 21 | # https://nginx.org/en/docs/ngx_core_module.html#worker_rlimit_nofile | ||
| 22 | worker_rlimit_nofile 8192; | ||
| 23 | |||
| 24 | # Provides the configuration file context in which the directives that affect | ||
| 25 | # connection processing are specified. | ||
| 26 | # https://nginx.org/en/docs/ngx_core_module.html#events | ||
| 27 | events { | ||
| 28 | |||
| 29 | # If you need more connections than this, you start optimizing your OS. | ||
| 30 | # That's probably the point at which you hire people who are smarter than you | ||
| 31 | # as this is *a lot* of requests. | ||
| 32 | # Should be < worker_rlimit_nofile. | ||
| 33 | # Default: 512 | ||
| 34 | # https://nginx.org/en/docs/ngx_core_module.html#worker_connections | ||
| 35 | worker_connections 8000; | ||
| 36 | |||
| 37 | } | ||
| 38 | |||
| 39 | # Log errors and warnings to this file | ||
| 40 | # This is only used when you don't override it on a `server` level | ||
| 41 | # Default: logs/error.log error | ||
| 42 | # https://nginx.org/en/docs/ngx_core_module.html#error_log | ||
| 43 | # error_log /var/log/nginx/error.log warn; | ||
| 44 | error_log /dev/null emerg; | ||
| 45 | |||
| 46 | # The file storing the process ID of the main process | ||
| 47 | # Default: logs/nginx.pid | ||
| 48 | # https://nginx.org/en/docs/ngx_core_module.html#pid | ||
| 49 | pid /var/run/nginx.pid; | ||
| 50 | |||
| 51 | # Include files in the custom.d folder. | ||
| 52 | # Custom configuration and value files should be placed in the custom.d | ||
| 53 | # folder. | ||
| 54 | # The configurations should be disabled by prefixing files with a dot. | ||
| 55 | # include custom.d/*.conf; | ||
| 56 | |||
| 57 | http { | ||
| 58 | |||
| 59 | # Hide Nginx version information. | ||
| 60 | include custom.d/security/server_software_information.conf; | ||
| 61 | |||
| 62 | # Specify media (MIME) types for files. | ||
| 63 | include custom.d/media_types/media_types.conf; | ||
| 64 | |||
| 65 | # Set character encodings. | ||
| 66 | include custom.d/media_types/character_encodings.conf; | ||
| 67 | |||
| 68 | # Include $http_x_forwarded_for within default format used in log files | ||
| 69 | # https://nginx.org/en/docs/http/ngx_http_log_module.html#log_format | ||
| 70 | log_format main '$remote_addr - $remote_user [$time_local] "$request" ' | ||
| 71 | '$status $body_bytes_sent "$http_referer" ' | ||
| 72 | '"$http_user_agent" "$http_x_forwarded_for" "$host"'; | ||
| 73 | |||
| 74 | # Log access to this file | ||
| 75 | # This is only used when you don't override it on a `server` level | ||
| 76 | # Default: logs/access.log combined | ||
| 77 | # https://nginx.org/en/docs/http/ngx_http_log_module.html#access_log | ||
| 78 | # access_log /var/log/nginx/access.log main; | ||
| 79 | access_log off; | ||
| 80 | |||
| 81 | # How long to allow each connection to stay idle. | ||
| 82 | # Longer values are better for each individual client, particularly for SSL, | ||
| 83 | # but means that worker connections are tied up longer. | ||
| 84 | # Default: 75s | ||
| 85 | # https://nginx.org/en/docs/http/ngx_http_core_module.html#keepalive_timeout | ||
| 86 | # keepalive_timeout 20s; | ||
| 87 | keepalive_timeout 75s; | ||
| 88 | |||
| 89 | # Speed up file transfers by using `sendfile()` to copy directly between | ||
| 90 | # descriptors rather than using `read()`/`write()``. | ||
| 91 | # For performance reasons, on FreeBSD systems w/ ZFS this option should be | ||
| 92 | # disabled as ZFS's ARC caches frequently used files in RAM by default. | ||
| 93 | # Default: off | ||
| 94 | # https://nginx.org/en/docs/http/ngx_http_core_module.html#sendfile | ||
| 95 | sendfile on; | ||
| 96 | |||
| 97 | # Don't send out partial frames; this increases throughput since TCP frames | ||
| 98 | # are filled up before being sent out. | ||
| 99 | # Default: off | ||
| 100 | # https://nginx.org/en/docs/http/ngx_http_core_module.html#tcp_nopush | ||
| 101 | tcp_nopush on; | ||
| 102 | |||
| 103 | # Enable gzip compression. | ||
| 104 | include custom.d/web_performance/compression.conf; | ||
| 105 | |||
| 106 | # Specify file cache expiration. | ||
| 107 | include custom.d/web_performance/cache_expiration.conf; | ||
| 108 | |||
| 109 | # Add Cache-Control. | ||
| 110 | # custom.d/web_performance/cache-control.conf | ||
| 111 | map $sent_http_content_type $cache_control { | ||
| 112 | default "public, immutable, stale-while-revalidate"; | ||
| 113 | |||
| 114 | # No content | ||
| 115 | "" "no-store"; | ||
| 116 | |||
| 117 | # Manifest files | ||
| 118 | ~*application/manifest\+json "public"; | ||
| 119 | ~*text/cache-manifest ""; # `no-cache` (*) | ||
| 120 | |||
| 121 | # Assets | ||
| 122 | ~*image/svg\+xml "public, immutable, stale-while-revalidate"; | ||
| 123 | |||
| 124 | # Data interchange | ||
| 125 | ~*application/(atom|rdf|rss)\+xml "public, stale-while-revalidate"; | ||
| 126 | |||
| 127 | # Documents | ||
| 128 | ~*text/html "private, must-revalidate"; | ||
| 129 | ~*text/markdown "private, must-revalidate"; | ||
| 130 | ~*text/calendar "private, must-revalidate"; | ||
| 131 | |||
| 132 | # Data | ||
| 133 | ~*json ""; # `no-cache` (*) | ||
| 134 | ~*xml ""; # `no-cache` (*) | ||
| 135 | } | ||
| 136 | |||
| 137 | # Add X-Frame-Options for HTML documents. | ||
| 138 | # custom.d/security/x-frame-options.conf | ||
| 139 | map $sent_http_content_type $x_frame_options { | ||
| 140 | ~*text/html DENY; | ||
| 141 | } | ||
| 142 | |||
| 143 | # Add Content-Security-Policy for HTML documents. | ||
| 144 | # custom.d/security/content-security-policy.conf | ||
| 145 | map $sent_http_content_type $content_security_policy { | ||
| 146 | ~*text/(html|javascript)|application/pdf|xml "default-src 'self'; base-uri 'none'; form-action 'self'; frame-ancestors 'none'; object-src 'none'; upgrade-insecure-requests"; | ||
| 147 | } | ||
| 148 | |||
| 149 | # Add Permissions-Policy for HTML documents. | ||
| 150 | # custom.d/security/permissions-policy.conf | ||
| 151 | map $sent_http_content_type $permissions_policy { | ||
| 152 | ~*text/(html|javascript)|application/pdf|xml "accelerometer=(),autoplay=(),browsing-topics=(),camera=(),display-capture=(),document-domain=(),encrypted-media=(),fullscreen=(),geolocation=(),gyroscope=(),magnetometer=(),microphone=(),midi=(),payment=(),picture-in-picture=(),publickey-credentials-get=(),screen-wake-lock=(),sync-xhr=(self),usb=(),web-share=(),xr-spatial-tracking=()"; | ||
| 153 | } | ||
| 154 | |||
| 155 | # Add Referrer-Policy for HTML documents. | ||
| 156 | # custom.d/security/referrer-policy.conf | ||
| 157 | map $sent_http_content_type $referrer_policy { | ||
| 158 | ~*text/(css|html|javascript)|application\/pdf|xml "strict-origin-when-cross-origin"; | ||
| 159 | } | ||
| 160 | |||
| 161 | # Add Cross-Origin-Policies for HTML documents. | ||
| 162 | # custom.d/security/cross-origin-policy.conf | ||
| 163 | # Cross-Origin-Embedder-Policy | ||
| 164 | map $sent_http_content_type $coep_policy { | ||
| 165 | ~*text/(html|javascript)|application/pdf|xml "require-corp"; | ||
| 166 | } | ||
| 167 | # Cross-Origin-Opener-Policy | ||
| 168 | map $sent_http_content_type $coop_policy { | ||
| 169 | ~*text/(html|javascript)|application/pdf|xml "same-origin"; | ||
| 170 | } | ||
| 171 | # Cross-Origin-Resource-Policy | ||
| 172 | map $sent_http_content_type $corp_policy { | ||
| 173 | ~*text/(html|javascript)|application/pdf|xml "same-origin"; | ||
| 174 | } | ||
| 175 | |||
| 176 | # Add Access-Control-Allow-Origin. | ||
| 177 | # custom.d/cross-origin/requests.conf | ||
| 178 | map $sent_http_content_type $cors { | ||
| 179 | # Images | ||
| 180 | ~*image/ "*"; | ||
| 181 | |||
| 182 | # Web fonts | ||
| 183 | ~*font/ "*"; | ||
| 184 | ~*application/vnd.ms-fontobject "*"; | ||
| 185 | ~*application/x-font-ttf "*"; | ||
| 186 | ~*application/font-woff "*"; | ||
| 187 | ~*application/x-font-woff "*"; | ||
| 188 | ~*application/font-woff2 "*"; | ||
| 189 | } | ||
| 190 | |||
| 191 | # Fix for onion links | ||
| 192 | server_names_hash_bucket_size 128; | ||
| 193 | |||
| 194 | # Include files in the conf.d folder. | ||
| 195 | # `server` configuration files should be placed in the conf.d folder. | ||
| 196 | # The configurations should be disabled by prefixing files with a dot. | ||
| 197 | include conf.d/*.conf; | ||
| 198 | } | ||
linux/nginx/etc/nginx/scgi_params added +17
| @@ -0,0 +1,17 @@ | |||
| 1 | |||
| 2 | scgi_param REQUEST_METHOD $request_method; | ||
| 3 | scgi_param REQUEST_URI $request_uri; | ||
| 4 | scgi_param QUERY_STRING $query_string; | ||
| 5 | scgi_param CONTENT_TYPE $content_type; | ||
| 6 | |||
| 7 | scgi_param DOCUMENT_URI $document_uri; | ||
| 8 | scgi_param DOCUMENT_ROOT $document_root; | ||
| 9 | scgi_param SCGI 1; | ||
| 10 | scgi_param SERVER_PROTOCOL $server_protocol; | ||
| 11 | scgi_param REQUEST_SCHEME $scheme; | ||
| 12 | scgi_param HTTPS $https if_not_empty; | ||
| 13 | |||
| 14 | scgi_param REMOTE_ADDR $remote_addr; | ||
| 15 | scgi_param REMOTE_PORT $remote_port; | ||
| 16 | scgi_param SERVER_PORT $server_port; | ||
| 17 | scgi_param SERVER_NAME $server_name; | ||
linux/nginx/etc/nginx/uwsgi_params added +17
| @@ -0,0 +1,17 @@ | |||
| 1 | |||
| 2 | uwsgi_param QUERY_STRING $query_string; | ||
| 3 | uwsgi_param REQUEST_METHOD $request_method; | ||
| 4 | uwsgi_param CONTENT_TYPE $content_type; | ||
| 5 | uwsgi_param CONTENT_LENGTH $content_length; | ||
| 6 | |||
| 7 | uwsgi_param REQUEST_URI $request_uri; | ||
| 8 | uwsgi_param PATH_INFO $document_uri; | ||
| 9 | uwsgi_param DOCUMENT_ROOT $document_root; | ||
| 10 | uwsgi_param SERVER_PROTOCOL $server_protocol; | ||
| 11 | uwsgi_param REQUEST_SCHEME $scheme; | ||
| 12 | uwsgi_param HTTPS $https if_not_empty; | ||
| 13 | |||
| 14 | uwsgi_param REMOTE_ADDR $remote_addr; | ||
| 15 | uwsgi_param REMOTE_PORT $remote_port; | ||
| 16 | uwsgi_param SERVER_PORT $server_port; | ||
| 17 | uwsgi_param SERVER_NAME $server_name; | ||