Commit 7c3385ccef
Verified · cmc
Layout: unified · split
common/gnupg/.gnupg/gpg-agent.conf added +2
| @@ -0,0 +1,2 @@ | ||
| 1 | pinentry-program /usr/bin/pinentry-curses | |
| 2 | allow-loopback-pinentry | |
linux/nginx/etc/nginx/conf.d/ao.conf added +39
| @@ -0,0 +1,39 @@ | ||
| 1 | # ---------------------------------------------------------------------- | |
| 2 | # | Config file for host | | |
| 3 | # ---------------------------------------------------------------------- | |
| 4 | server { | |
| 5 | listen [::]:443 ssl; | |
| 6 | listen 443 ssl; | |
| 7 | http2 on; | |
| 8 | ||
| 9 | server_name ao.cleberg.net; | |
| 10 | ||
| 11 | include custom.d/tls/ssl_engine.conf; | |
| 12 | include custom.d/tls/certificate_files.conf; | |
| 13 | include custom.d/tls/policy_balanced.conf; | |
| 14 | include custom.d/basic.conf; | |
| 15 | ||
| 16 | # ---------------------------------------------------------------------- | |
| 17 | # | Custom rules & config for specific website | | |
| 18 | # ---------------------------------------------------------------------- | |
| 19 | location / { | |
| 20 | set $upstream http://127.0.0.1:9380; | |
| 21 | proxy_pass $upstream; | |
| 22 | ||
| 23 | include custom.d/reverse_proxy/basic.conf; | |
| 24 | } | |
| 25 | ||
| 26 | include custom.d/security/robots_index_only.conf; | |
| 27 | # ---------------------------------------------------------------------- | |
| 28 | } | |
| 29 | ||
| 30 | # ---------------------------------------------------------------------- | |
| 31 | # | Config file for non-secure host | | |
| 32 | # ---------------------------------------------------------------------- | |
| 33 | server { | |
| 34 | listen [::]:80; | |
| 35 | listen 80; | |
| 36 | server_name ao.cleberg.net; | |
| 37 | ||
| 38 | return 301 https://$host$request_uri; | |
| 39 | } | |
linux/nginx/etc/nginx/conf.d/art.conf added +39
| @@ -0,0 +1,39 @@ | ||
| 1 | # ---------------------------------------------------------------------- | |
| 2 | # | Config file for host | | |
| 3 | # ---------------------------------------------------------------------- | |
| 4 | server { | |
| 5 | listen [::]:443 ssl; | |
| 6 | listen 443 ssl; | |
| 7 | http2 on; | |
| 8 | ||
| 9 | server_name art.cleberg.net; | |
| 10 | ||
| 11 | include custom.d/tls/ssl_engine.conf; | |
| 12 | include custom.d/tls/certificate_files.conf; | |
| 13 | include custom.d/tls/policy_balanced.conf; | |
| 14 | include custom.d/basic.conf; | |
| 15 | ||
| 16 | # ---------------------------------------------------------------------- | |
| 17 | # | Custom rules & config for specific website | | |
| 18 | # ---------------------------------------------------------------------- | |
| 19 | location / { | |
| 20 | set $upstream http://127.0.0.1:3003; | |
| 21 | proxy_pass $upstream; | |
| 22 | ||
| 23 | include custom.d/reverse_proxy/basic.conf; | |
| 24 | } | |
| 25 | ||
| 26 | include custom.d/security/robots_index_only.conf; | |
| 27 | # ---------------------------------------------------------------------- | |
| 28 | } | |
| 29 | ||
| 30 | # ---------------------------------------------------------------------- | |
| 31 | # | Config file for non-secure host | | |
| 32 | # ---------------------------------------------------------------------- | |
| 33 | server { | |
| 34 | listen [::]:80; | |
| 35 | listen 80; | |
| 36 | server_name art.cleberg.net; | |
| 37 | ||
| 38 | return 301 https://$host$request_uri; | |
| 39 | } | |
linux/nginx/etc/nginx/conf.d/auth.conf added +42
| @@ -0,0 +1,42 @@ | ||
| 1 | # ---------------------------------------------------------------------- | |
| 2 | # | Config file for host | | |
| 3 | # ---------------------------------------------------------------------- | |
| 4 | server { | |
| 5 | listen [::]:443 ssl; | |
| 6 | listen 443 ssl; | |
| 7 | http2 on; | |
| 8 | ||
| 9 | server_name auth.cleberg.net; | |
| 10 | ||
| 11 | include custom.d/tls/ssl_engine.conf; | |
| 12 | include custom.d/tls/certificate_files.conf; | |
| 13 | include custom.d/tls/policy_balanced.conf; | |
| 14 | include custom.d/basic.conf; | |
| 15 | ||
| 16 | # ---------------------------------------------------------------------- | |
| 17 | # | Custom rules & config for specific website | | |
| 18 | # ---------------------------------------------------------------------- | |
| 19 | set $upstream http://127.0.0.1:9092; | |
| 20 | ||
| 21 | location / { | |
| 22 | proxy_pass $upstream; | |
| 23 | ||
| 24 | include custom.d/reverse_proxy/basic.conf; | |
| 25 | } | |
| 26 | ||
| 27 | location /api/verify { | |
| 28 | proxy_pass $upstream; | |
| 29 | } | |
| 30 | # ---------------------------------------------------------------------- | |
| 31 | } | |
| 32 | ||
| 33 | # ---------------------------------------------------------------------- | |
| 34 | # | Config file for non-secure host | | |
| 35 | # ---------------------------------------------------------------------- | |
| 36 | server { | |
| 37 | listen [::]:80; | |
| 38 | listen 80; | |
| 39 | server_name auth.cleberg.net; | |
| 40 | ||
| 41 | return 301 https://$host$request_uri; | |
| 42 | } | |
linux/nginx/etc/nginx/conf.d/br.conf added +39
| @@ -0,0 +1,39 @@ | ||
| 1 | # ---------------------------------------------------------------------- | |
| 2 | # | Config file for host | | |
| 3 | # ---------------------------------------------------------------------- | |
| 4 | server { | |
| 5 | listen [::]:443 ssl; | |
| 6 | listen 443 ssl; | |
| 7 | http2 on; | |
| 8 | ||
| 9 | server_name br.cleberg.net; | |
| 10 | ||
| 11 | include custom.d/tls/ssl_engine.conf; | |
| 12 | include custom.d/tls/certificate_files.conf; | |
| 13 | include custom.d/tls/policy_balanced.conf; | |
| 14 | include custom.d/basic.conf; | |
| 15 | ||
| 16 | # ---------------------------------------------------------------------- | |
| 17 | # | Custom rules & config for specific website | | |
| 18 | # ---------------------------------------------------------------------- | |
| 19 | location / { | |
| 20 | set $upstream http://127.0.0.1:3030; | |
| 21 | proxy_pass $upstream; | |
| 22 | ||
| 23 | include custom.d/reverse_proxy/basic.conf; | |
| 24 | } | |
| 25 | ||
| 26 | include custom.d/security/robots_index_only.conf; | |
| 27 | # ---------------------------------------------------------------------- | |
| 28 | } | |
| 29 | ||
| 30 | # ---------------------------------------------------------------------- | |
| 31 | # | Config file for non-secure host | | |
| 32 | # ---------------------------------------------------------------------- | |
| 33 | server { | |
| 34 | listen [::]:80; | |
| 35 | listen 80; | |
| 36 | server_name br.cleberg.net; | |
| 37 | ||
| 38 | return 301 https://$host$request_uri; | |
| 39 | } | |
linux/nginx/etc/nginx/conf.d/bt.conf added +46
| @@ -0,0 +1,46 @@ | ||
| 1 | # ---------------------------------------------------------------------- | |
| 2 | # | Config file for host | | |
| 3 | # ---------------------------------------------------------------------- | |
| 4 | server { | |
| 5 | listen [::]:443 ssl; | |
| 6 | listen 443 ssl; | |
| 7 | http2 on; | |
| 8 | ||
| 9 | server_name bt.cleberg.net; | |
| 10 | ||
| 11 | include custom.d/tls/ssl_engine.conf; | |
| 12 | include custom.d/tls/certificate_files.conf; | |
| 13 | include custom.d/tls/policy_balanced.conf; | |
| 14 | include custom.d/basic.conf; | |
| 15 | ||
| 16 | # ---------------------------------------------------------------------- | |
| 17 | # | Custom rules & config for specific website | | |
| 18 | # ---------------------------------------------------------------------- | |
| 19 | set $upstream http://127.0.0.1:9091; | |
| 20 | ||
| 21 | location /authelia { | |
| 22 | include custom.d/reverse_proxy/authelia.conf; | |
| 23 | } | |
| 24 | ||
| 25 | location / { | |
| 26 | proxy_pass $upstream; | |
| 27 | ||
| 28 | include custom.d/reverse_proxy/authelia_request.conf; | |
| 29 | # include custom.d/reverse_proxy/basic.conf; | |
| 30 | proxy_pass_header X-bt-Session-Id; | |
| 31 | } | |
| 32 | ||
| 33 | include custom.d/security/robots_index_only.conf; | |
| 34 | # ---------------------------------------------------------------------- | |
| 35 | } | |
| 36 | ||
| 37 | # ---------------------------------------------------------------------- | |
| 38 | # | Config file for non-secure host | | |
| 39 | # ---------------------------------------------------------------------- | |
| 40 | server { | |
| 41 | listen [::]:80; | |
| 42 | listen 80; | |
| 43 | server_name bt.cleberg.net; | |
| 44 | ||
| 45 | return 301 https://$host$request_uri; | |
| 46 | } | |
linux/nginx/etc/nginx/conf.d/bw.conf added +39
| @@ -0,0 +1,39 @@ | ||
| 1 | # ---------------------------------------------------------------------- | |
| 2 | # | Config file for host | | |
| 3 | # ---------------------------------------------------------------------- | |
| 4 | server { | |
| 5 | listen [::]:443 ssl; | |
| 6 | listen 443 ssl; | |
| 7 | http2 on; | |
| 8 | ||
| 9 | server_name bw.cleberg.net; | |
| 10 | ||
| 11 | include custom.d/tls/ssl_engine.conf; | |
| 12 | include custom.d/tls/certificate_files.conf; | |
| 13 | include custom.d/tls/policy_balanced.conf; | |
| 14 | include custom.d/basic.conf; | |
| 15 | ||
| 16 | # ---------------------------------------------------------------------- | |
| 17 | # | Custom rules & config for specific website | | |
| 18 | # ---------------------------------------------------------------------- | |
| 19 | location / { | |
| 20 | set $upstream http://127.0.0.1:10416; | |
| 21 | proxy_pass $upstream; | |
| 22 | ||
| 23 | include custom.d/reverse_proxy/basic.conf; | |
| 24 | } | |
| 25 | ||
| 26 | include custom.d/security/robots_index_only.conf; | |
| 27 | # ---------------------------------------------------------------------- | |
| 28 | } | |
| 29 | ||
| 30 | # ---------------------------------------------------------------------- | |
| 31 | # | Config file for non-secure host | | |
| 32 | # ---------------------------------------------------------------------- | |
| 33 | server { | |
| 34 | listen [::]:80; | |
| 35 | listen 80; | |
| 36 | server_name bw.cleberg.net; | |
| 37 | ||
| 38 | return 301 https://$host$request_uri; | |
| 39 | } | |
linux/nginx/etc/nginx/conf.d/cc.conf added +39
| @@ -0,0 +1,39 @@ | ||
| 1 | # ---------------------------------------------------------------------- | |
| 2 | # | Config file for host | | |
| 3 | # ---------------------------------------------------------------------- | |
| 4 | server { | |
| 5 | listen [::]:443 ssl; | |
| 6 | listen 443 ssl; | |
| 7 | http2 on; | |
| 8 | ||
| 9 | server_name cc.cleberg.net; | |
| 10 | ||
| 11 | include custom.d/tls/ssl_engine.conf; | |
| 12 | include custom.d/tls/certificate_files.conf; | |
| 13 | include custom.d/tls/policy_balanced.conf; | |
| 14 | include custom.d/basic.conf; | |
| 15 | ||
| 16 | # ---------------------------------------------------------------------- | |
| 17 | # | Custom rules & config for specific website | | |
| 18 | # ---------------------------------------------------------------------- | |
| 19 | location / { | |
| 20 | set $upstream http://127.0.0.1:8111; | |
| 21 | proxy_pass $upstream; | |
| 22 | ||
| 23 | include custom.d/reverse_proxy/basic.conf; | |
| 24 | } | |
| 25 | ||
| 26 | include custom.d/security/robots_index_only.conf; | |
| 27 | # ---------------------------------------------------------------------- | |
| 28 | } | |
| 29 | ||
| 30 | # ---------------------------------------------------------------------- | |
| 31 | # | Config file for non-secure host | | |
| 32 | # ---------------------------------------------------------------------- | |
| 33 | server { | |
| 34 | listen [::]:80; | |
| 35 | listen 80; | |
| 36 | server_name cc.cleberg.net; | |
| 37 | ||
| 38 | return 301 https://$host$request_uri; | |
| 39 | } | |
linux/nginx/etc/nginx/conf.d/cleberg.io added +54
| @@ -0,0 +1,54 @@ | ||
| 1 | # ---------------------------------------------------------------------- | |
| 2 | # | Config file for host | | |
| 3 | # ---------------------------------------------------------------------- | |
| 4 | server { | |
| 5 | listen [::]:443 ssl; | |
| 6 | listen 443 ssl; | |
| 7 | http2 on; | |
| 8 | ||
| 9 | server_name www.cleberg.io cleberg.io; | |
| 10 | ||
| 11 | include custom.d/tls/ssl_engine.conf; | |
| 12 | include custom.d/tls/policy_balanced.conf; | |
| 13 | # include custom.d/tls/certificate_files.conf; | |
| 14 | ssl_certificate /etc/letsencrypt/live/cleberg.io/fullchain.pem; | |
| 15 | ssl_certificate_key /etc/letsencrypt/live/cleberg.io/privkey.pem; | |
| 16 | ssl_trusted_certificate /etc/letsencrypt/live/cleberg.io/chain.pem; | |
| 17 | ||
| 18 | return 301 $scheme://cleberg.io$request_uri; | |
| 19 | } | |
| 20 | ||
| 21 | ||
| 22 | server { | |
| 23 | listen [::]:443 ssl; | |
| 24 | listen 443 ssl; | |
| 25 | http2 on; | |
| 26 | ||
| 27 | server_name cleberg.io; | |
| 28 | ||
| 29 | include custom.d/tls/ssl_engine.conf; | |
| 30 | include custom.d/tls/policy_balanced.conf; | |
| 31 | include custom.d/basic.conf; | |
| 32 | ||
| 33 | # include custom.d/tls/certificate_files.conf; | |
| 34 | ssl_certificate /etc/letsencrypt/live/cleberg.io/fullchain.pem; | |
| 35 | ssl_certificate_key /etc/letsencrypt/live/cleberg.io/privkey.pem; | |
| 36 | ssl_trusted_certificate /etc/letsencrypt/live/cleberg.io/chain.pem; | |
| 37 | ||
| 38 | # ---------------------------------------------------------------------- | |
| 39 | # | Custom rules & config for specific website | | |
| 40 | # ---------------------------------------------------------------------- | |
| 41 | return 301 https://cleberg.net; | |
| 42 | # ---------------------------------------------------------------------- | |
| 43 | } | |
| 44 | ||
| 45 | # ---------------------------------------------------------------------- | |
| 46 | # | Config file for non-secure host | | |
| 47 | # ---------------------------------------------------------------------- | |
| 48 | server { | |
| 49 | listen [::]:80; | |
| 50 | listen 80; | |
| 51 | server_name www.cleberg.io cleberg.io; | |
| 52 | ||
| 53 | return 301 https://cleberg.io$request_uri; | |
| 54 | } | |
linux/nginx/etc/nginx/conf.d/cleberg.net.conf added +70
| @@ -0,0 +1,70 @@ | ||
| 1 | # ---------------------------------------------------------------------- | |
| 2 | # | Config file for host | | |
| 3 | # ---------------------------------------------------------------------- | |
| 4 | server { | |
| 5 | listen [::]:443 ssl; | |
| 6 | listen 443 ssl; | |
| 7 | http2 on; | |
| 8 | ||
| 9 | server_name www.cleberg.net; | |
| 10 | ||
| 11 | include custom.d/tls/ssl_engine.conf; | |
| 12 | include custom.d/tls/certificate_files.conf; | |
| 13 | include custom.d/tls/policy_balanced.conf; | |
| 14 | ||
| 15 | return 301 $scheme://cleberg.net$request_uri; | |
| 16 | } | |
| 17 | ||
| 18 | ||
| 19 | server { | |
| 20 | listen [::]:443 ssl; | |
| 21 | listen 443 ssl; | |
| 22 | http2 on; | |
| 23 | ||
| 24 | server_name cleberg.net; | |
| 25 | ||
| 26 | include custom.d/tls/ssl_engine.conf; | |
| 27 | include custom.d/tls/certificate_files.conf; | |
| 28 | include custom.d/tls/policy_balanced.conf; | |
| 29 | include custom.d/basic.conf; | |
| 30 | ||
| 31 | root /var/www/cleberg.net/; | |
| 32 | ||
| 33 | # ---------------------------------------------------------------------- | |
| 34 | # | Custom rules & config for specific website | | |
| 35 | # ---------------------------------------------------------------------- | |
| 36 | location / { | |
| 37 | try_files $uri $uri/ =404; | |
| 38 | } | |
| 39 | ||
| 40 | # fix: redirect blog & wiki posts from "/" to ".html" | |
| 41 | location /blog/ { | |
| 42 | rewrite ^/blog/((?!index)[^/]+)/(.*)$ /blog/$1.html permanent; | |
| 43 | } | |
| 44 | ||
| 45 | location /wiki/ { | |
| 46 | rewrite ^/wiki/((?!index)[^/]+)/(.*)$ /wiki/$1.html permanent; | |
| 47 | } | |
| 48 | ||
| 49 | # fix: redirect atom.xml to feed.xml | |
| 50 | location /atom.xml { | |
| 51 | return 301 $scheme://$host/feed.xml; | |
| 52 | } | |
| 53 | ||
| 54 | # fix: redirect salary page | |
| 55 | location /blog/salary-transparency.html { | |
| 56 | return 301 $scheme://$host/salary/; | |
| 57 | } | |
| 58 | # ---------------------------------------------------------------------- | |
| 59 | } | |
| 60 | ||
| 61 | # ---------------------------------------------------------------------- | |
| 62 | # | Config file for non-secure host | | |
| 63 | # ---------------------------------------------------------------------- | |
| 64 | server { | |
| 65 | listen [::]:80; | |
| 66 | listen 80; | |
| 67 | server_name www.cleberg.net cleberg.net; | |
| 68 | ||
| 69 | return 301 https://cleberg.net$request_uri; | |
| 70 | } | |
linux/nginx/etc/nginx/conf.d/cv.conf added +37
| @@ -0,0 +1,37 @@ | ||
| 1 | # ---------------------------------------------------------------------- | |
| 2 | # | Config file for host | | |
| 3 | # ---------------------------------------------------------------------- | |
| 4 | server { | |
| 5 | listen [::]:443 ssl; | |
| 6 | listen 443 ssl; | |
| 7 | http2 on; | |
| 8 | ||
| 9 | server_name cv.cleberg.net; | |
| 10 | ||
| 11 | include custom.d/tls/ssl_engine.conf; | |
| 12 | include custom.d/tls/certificate_files.conf; | |
| 13 | include custom.d/tls/policy_balanced.conf; | |
| 14 | include custom.d/basic.conf; | |
| 15 | ||
| 16 | root /var/www/cv/; | |
| 17 | autoindex on; | |
| 18 | ||
| 19 | # ---------------------------------------------------------------------- | |
| 20 | # | Custom rules & config for specific website | | |
| 21 | # ---------------------------------------------------------------------- | |
| 22 | location / { | |
| 23 | try_files $uri $uri/ /index.html; | |
| 24 | } | |
| 25 | # ---------------------------------------------------------------------- | |
| 26 | } | |
| 27 | ||
| 28 | # ---------------------------------------------------------------------- | |
| 29 | # | Config file for non-secure host | | |
| 30 | # ---------------------------------------------------------------------- | |
| 31 | server { | |
| 32 | listen [::]:80; | |
| 33 | listen 80; | |
| 34 | server_name cv.cleberg.net; | |
| 35 | ||
| 36 | return 301 https://$host$request_uri; | |
| 37 | } | |
linux/nginx/etc/nginx/conf.d/ddns.conf added +44
| @@ -0,0 +1,44 @@ | ||
| 1 | # ---------------------------------------------------------------------- | |
| 2 | # | Config file for host | | |
| 3 | # ---------------------------------------------------------------------- | |
| 4 | server { | |
| 5 | listen [::]:443 ssl; | |
| 6 | listen 443 ssl; | |
| 7 | http2 on; | |
| 8 | ||
| 9 | server_name ddns.cleberg.net; | |
| 10 | ||
| 11 | include custom.d/tls/ssl_engine.conf; | |
| 12 | include custom.d/tls/certificate_files.conf; | |
| 13 | include custom.d/tls/policy_balanced.conf; | |
| 14 | include custom.d/basic.conf; | |
| 15 | ||
| 16 | # ---------------------------------------------------------------------- | |
| 17 | # | Custom rules & config for specific website | | |
| 18 | # ---------------------------------------------------------------------- | |
| 19 | location /authelia { | |
| 20 | include custom.d/reverse_proxy/authelia.conf; | |
| 21 | } | |
| 22 | ||
| 23 | location / { | |
| 24 | set $upstream http://127.0.0.1:8097; | |
| 25 | proxy_pass $upstream; | |
| 26 | ||
| 27 | include custom.d/reverse_proxy/authelia_request.conf; | |
| 28 | include custom.d/reverse_proxy/basic.conf; | |
| 29 | } | |
| 30 | ||
| 31 | include custom.d/security/robots_index_only.conf; | |
| 32 | # ---------------------------------------------------------------------- | |
| 33 | } | |
| 34 | ||
| 35 | # ---------------------------------------------------------------------- | |
| 36 | # | Config file for non-secure host | | |
| 37 | # ---------------------------------------------------------------------- | |
| 38 | server { | |
| 39 | listen [::]:80; | |
| 40 | listen 80; | |
| 41 | server_name ddns.cleberg.net; | |
| 42 | ||
| 43 | return 301 https://$host$request_uri; | |
| 44 | } | |
linux/nginx/etc/nginx/conf.d/default.conf added +33
| @@ -0,0 +1,33 @@ | ||
| 1 | # ---------------------------------------------------------------------- | |
| 2 | # | Default behavior for unknown hosts | | |
| 3 | # ---------------------------------------------------------------------- | |
| 4 | # | |
| 5 | # Drop requests for unknown hosts. | |
| 6 | # | |
| 7 | # If no default server is defined, Nginx will use the first found server. | |
| 8 | # To prevent host header attacks, or other potential problems when an unknown | |
| 9 | # server name is used in a request, it's recommended to drop the request | |
| 10 | # returning 444 "No Response". | |
| 11 | ||
| 12 | server { | |
| 13 | listen [::]:443 ssl default_server; | |
| 14 | listen 443 ssl default_server; | |
| 15 | http2 on; | |
| 16 | ||
| 17 | server_name _; | |
| 18 | ||
| 19 | include custom.d/tls/ssl_engine.conf; | |
| 20 | include custom.d/tls/certificate_files.conf; | |
| 21 | include custom.d/tls/policy_balanced.conf; | |
| 22 | ||
| 23 | return 444; | |
| 24 | } | |
| 25 | ||
| 26 | server { | |
| 27 | listen [::]:80; | |
| 28 | listen 80; | |
| 29 | ||
| 30 | server_name _; | |
| 31 | ||
| 32 | return 444; | |
| 33 | } | |
linux/nginx/etc/nginx/conf.d/docker.conf added +44
| @@ -0,0 +1,44 @@ | ||
| 1 | # ---------------------------------------------------------------------- | |
| 2 | # | Config file for host | | |
| 3 | # ---------------------------------------------------------------------- | |
| 4 | server { | |
| 5 | listen [::]:443 ssl; | |
| 6 | listen 443 ssl; | |
| 7 | http2 on; | |
| 8 | ||
| 9 | server_name docker.cleberg.net; | |
| 10 | ||
| 11 | include custom.d/tls/ssl_engine.conf; | |
| 12 | include custom.d/tls/certificate_files.conf; | |
| 13 | include custom.d/tls/policy_balanced.conf; | |
| 14 | include custom.d/basic.conf; | |
| 15 | ||
| 16 | # ---------------------------------------------------------------------- | |
| 17 | # | Custom rules & config for specific website | | |
| 18 | # ---------------------------------------------------------------------- | |
| 19 | location /authelia { | |
| 20 | include custom.d/reverse_proxy/authelia.conf; | |
| 21 | } | |
| 22 | ||
| 23 | location / { | |
| 24 | set $upstream http://127.0.0.1:3777; | |
| 25 | proxy_pass $upstream; | |
| 26 | ||
| 27 | include custom.d/reverse_proxy/authelia_request.conf; | |
| 28 | include custom.d/reverse_proxy/basic.conf; | |
| 29 | } | |
| 30 | ||
| 31 | include custom.d/security/robots_index_only.conf; | |
| 32 | # ---------------------------------------------------------------------- | |
| 33 | } | |
| 34 | ||
| 35 | # ---------------------------------------------------------------------- | |
| 36 | # | Config file for non-secure host | | |
| 37 | # ---------------------------------------------------------------------- | |
| 38 | server { | |
| 39 | listen [::]:80; | |
| 40 | listen 80; | |
| 41 | server_name docker.cleberg.net; | |
| 42 | ||
| 43 | return 301 https://$host$request_uri; | |
| 44 | } | |
linux/nginx/etc/nginx/conf.d/files.conf added +40
| @@ -0,0 +1,40 @@ | ||
| 1 | # ---------------------------------------------------------------------- | |
| 2 | # | Config file for files.cleberg.net host | | |
| 3 | # ---------------------------------------------------------------------- | |
| 4 | server { | |
| 5 | listen [::]:443 ssl; | |
| 6 | listen 443 ssl; | |
| 7 | http2 on; | |
| 8 | ||
| 9 | # The host name to respond to | |
| 10 | server_name files.cleberg.net; | |
| 11 | ||
| 12 | include custom.d/tls/ssl_engine.conf; | |
| 13 | include custom.d/tls/certificate_files.conf; | |
| 14 | include custom.d/tls/policy_balanced.conf; | |
| 15 | include custom.d/basic.conf; | |
| 16 | ||
| 17 | root /var/www/files/; | |
| 18 | autoindex on; | |
| 19 | ||
| 20 | # Include the basic custom.d config set | |
| 21 | ||
| 22 | # ---------------------------------------------------------------------- | |
| 23 | # | Custom rules & config for specific website | | |
| 24 | # ---------------------------------------------------------------------- | |
| 25 | location / { | |
| 26 | try_files $uri $uri/ /index.html; | |
| 27 | } | |
| 28 | # ---------------------------------------------------------------------- | |
| 29 | } | |
| 30 | ||
| 31 | # ---------------------------------------------------------------------- | |
| 32 | # | Config file for non-secure cleberg.net host | | |
| 33 | # ---------------------------------------------------------------------- | |
| 34 | server { | |
| 35 | listen [::]:80; | |
| 36 | listen 80; | |
| 37 | server_name files.cleberg.net; | |
| 38 | ||
| 39 | return 301 https://$host$request_uri; | |
| 40 | } | |
linux/nginx/etc/nginx/conf.d/gh.conf added +39
| @@ -0,0 +1,39 @@ | ||
| 1 | # ---------------------------------------------------------------------- | |
| 2 | # | Config file for host | | |
| 3 | # ---------------------------------------------------------------------- | |
| 4 | server { | |
| 5 | listen [::]:443 ssl; | |
| 6 | listen 443 ssl; | |
| 7 | http2 on; | |
| 8 | ||
| 9 | server_name gh.cleberg.net; | |
| 10 | ||
| 11 | include custom.d/tls/ssl_engine.conf; | |
| 12 | include custom.d/tls/certificate_files.conf; | |
| 13 | include custom.d/tls/policy_balanced.conf; | |
| 14 | include custom.d/basic.conf; | |
| 15 | ||
| 16 | # ---------------------------------------------------------------------- | |
| 17 | # | Custom rules & config for specific website | | |
| 18 | # ---------------------------------------------------------------------- | |
| 19 | location / { | |
| 20 | set $upstream http://192.168.0.251:3039; | |
| 21 | proxy_pass $upstream; | |
| 22 | ||
| 23 | include custom.d/reverse_proxy/basic.conf; | |
| 24 | } | |
| 25 | ||
| 26 | include custom.d/security/robots_index_only.conf; | |
| 27 | # ---------------------------------------------------------------------- | |
| 28 | } | |
| 29 | ||
| 30 | # ---------------------------------------------------------------------- | |
| 31 | # | Config file for non-secure host | | |
| 32 | # ---------------------------------------------------------------------- | |
| 33 | server { | |
| 34 | listen [::]:80; | |
| 35 | listen 80; | |
| 36 | server_name gh.cleberg.net; | |
| 37 | ||
| 38 | return 301 https://$host$request_uri; | |
| 39 | } | |
linux/nginx/etc/nginx/conf.d/ha.conf added +46
| @@ -0,0 +1,46 @@ | ||
| 1 | # ---------------------------------------------------------------------- | |
| 2 | # | Config file for host | | |
| 3 | # ---------------------------------------------------------------------- | |
| 4 | server { | |
| 5 | listen [::]:443 ssl; | |
| 6 | listen 443 ssl; | |
| 7 | http2 on; | |
| 8 | ||
| 9 | server_name ha.cleberg.net; | |
| 10 | ||
| 11 | include custom.d/tls/ssl_engine.conf; | |
| 12 | include custom.d/tls/certificate_files.conf; | |
| 13 | include custom.d/tls/policy_balanced.conf; | |
| 14 | include custom.d/basic.conf; | |
| 15 | ||
| 16 | # ---------------------------------------------------------------------- | |
| 17 | # | Custom rules & config for specific website | | |
| 18 | # ---------------------------------------------------------------------- | |
| 19 | set $upstream http://192.168.0.214:8123; | |
| 20 | ||
| 21 | location / { | |
| 22 | proxy_pass $upstream; | |
| 23 | proxy_set_header X-Forwarded-For $remote_addr; | |
| 24 | } | |
| 25 | ||
| 26 | location /api/websocket { | |
| 27 | proxy_pass $upstream; | |
| 28 | proxy_http_version 1.1; | |
| 29 | proxy_set_header Upgrade $http_upgrade; | |
| 30 | proxy_set_header Connection "upgrade"; | |
| 31 | } | |
| 32 | ||
| 33 | include custom.d/security/robots_index_only.conf; | |
| 34 | # ---------------------------------------------------------------------- | |
| 35 | } | |
| 36 | ||
| 37 | # ---------------------------------------------------------------------- | |
| 38 | # | Config file for non-secure host | | |
| 39 | # ---------------------------------------------------------------------- | |
| 40 | server { | |
| 41 | listen [::]:80; | |
| 42 | listen 80; | |
| 43 | server_name ha.cleberg.net; | |
| 44 | ||
| 45 | return 301 https://$host$request_uri; | |
| 46 | } | |
linux/nginx/etc/nginx/conf.d/hat.conf added +39
| @@ -0,0 +1,39 @@ | ||
| 1 | # ---------------------------------------------------------------------- | |
| 2 | # | Config file for host | | |
| 3 | # ---------------------------------------------------------------------- | |
| 4 | server { | |
| 5 | listen [::]:443 ssl; | |
| 6 | listen 443 ssl; | |
| 7 | http2 on; | |
| 8 | ||
| 9 | server_name hat.cleberg.net; | |
| 10 | ||
| 11 | include custom.d/tls/ssl_engine.conf; | |
| 12 | include custom.d/tls/certificate_files.conf; | |
| 13 | include custom.d/tls/policy_balanced.conf; | |
| 14 | include custom.d/basic.conf; | |
| 15 | ||
| 16 | # ---------------------------------------------------------------------- | |
| 17 | # | Custom rules & config for specific website | | |
| 18 | # ---------------------------------------------------------------------- | |
| 19 | location / { | |
| 20 | set $upstream http://192.168.0.251:3991; | |
| 21 | proxy_pass $upstream; | |
| 22 | ||
| 23 | include custom.d/reverse_proxy/basic.conf; | |
| 24 | } | |
| 25 | ||
| 26 | include custom.d/security/robots_index_only.conf; | |
| 27 | # ---------------------------------------------------------------------- | |
| 28 | } | |
| 29 | ||
| 30 | # ---------------------------------------------------------------------- | |
| 31 | # | Config file for non-secure host | | |
| 32 | # ---------------------------------------------------------------------- | |
| 33 | server { | |
| 34 | listen [::]:80; | |
| 35 | listen 80; | |
| 36 | server_name hat.cleberg.net; | |
| 37 | ||
| 38 | return 301 https://$host$request_uri; | |
| 39 | } | |
linux/nginx/etc/nginx/conf.d/hn.conf added +27
| @@ -0,0 +1,27 @@ | ||
| 1 | server { | |
| 2 | listen [::]:443 ssl; | |
| 3 | listen 443 ssl; | |
| 4 | http2 on; | |
| 5 | ||
| 6 | server_name hn.cleberg.net r3yfeffyj7ornpikojmw75u3sn2la7tqnmcmwgv2ov7if24sm5czqeid.onion; | |
| 7 | root /var/www/hn/output/; | |
| 8 | autoindex on; | |
| 9 | add_header Onion-Location http://r3yfeffyj7ornpikojmw75u3sn2la7tqnmcmwgv2ov7if24sm5czqeid.onion; | |
| 10 | ||
| 11 | include custom.d/tls/ssl_engine.conf; | |
| 12 | include custom.d/tls/certificate_files.conf; | |
| 13 | include custom.d/tls/policy_balanced.conf; | |
| 14 | include custom.d/basic.conf; | |
| 15 | ||
| 16 | location / { | |
| 17 | try_files $uri $uri/ /index.html; | |
| 18 | } | |
| 19 | } | |
| 20 | ||
| 21 | server { | |
| 22 | listen [::]:80; | |
| 23 | listen 80; | |
| 24 | server_name hn.cleberg.net; | |
| 25 | ||
| 26 | return 301 https://$host$request_uri; | |
| 27 | } | |
linux/nginx/etc/nginx/conf.d/img.conf added +37
| @@ -0,0 +1,37 @@ | ||
| 1 | # ---------------------------------------------------------------------- | |
| 2 | # | Config file for host | | |
| 3 | # ---------------------------------------------------------------------- | |
| 4 | server { | |
| 5 | listen [::]:443 ssl; | |
| 6 | listen 443 ssl; | |
| 7 | http2 on; | |
| 8 | ||
| 9 | server_name img.cleberg.net; | |
| 10 | ||
| 11 | include custom.d/tls/ssl_engine.conf; | |
| 12 | include custom.d/tls/certificate_files.conf; | |
| 13 | include custom.d/tls/policy_balanced.conf; | |
| 14 | include custom.d/basic.conf; | |
| 15 | ||
| 16 | root /var/www/img/; | |
| 17 | autoindex on; | |
| 18 | ||
| 19 | # ---------------------------------------------------------------------- | |
| 20 | # | Custom rules & config for specific website | | |
| 21 | # ---------------------------------------------------------------------- | |
| 22 | location / { | |
| 23 | try_files $uri $uri/ =404; | |
| 24 | } | |
| 25 | # ---------------------------------------------------------------------- | |
| 26 | } | |
| 27 | ||
| 28 | # ---------------------------------------------------------------------- | |
| 29 | # | Config file for non-secure host | | |
| 30 | # ---------------------------------------------------------------------- | |
| 31 | server { | |
| 32 | listen [::]:80; | |
| 33 | listen 80; | |
| 34 | server_name img.cleberg.net; | |
| 35 | ||
| 36 | return 301 https://img.cleberg.net$request_uri; | |
| 37 | } | |
linux/nginx/etc/nginx/conf.d/irc.conf added +44
| @@ -0,0 +1,44 @@ | ||
| 1 | # ---------------------------------------------------------------------- | |
| 2 | # | Config file for host | | |
| 3 | # ---------------------------------------------------------------------- | |
| 4 | server { | |
| 5 | listen [::]:443 ssl; | |
| 6 | listen 443 ssl; | |
| 7 | http2 on; | |
| 8 | ||
| 9 | server_name irc.cleberg.net; | |
| 10 | ||
| 11 | include custom.d/tls/ssl_engine.conf; | |
| 12 | include custom.d/tls/certificate_files.conf; | |
| 13 | include custom.d/tls/policy_balanced.conf; | |
| 14 | include custom.d/basic.conf; | |
| 15 | ||
| 16 | # ---------------------------------------------------------------------- | |
| 17 | # | Custom rules & config for specific website | | |
| 18 | # ---------------------------------------------------------------------- | |
| 19 | location /authelia { | |
| 20 | include custom.d/reverse_proxy/authelia.conf; | |
| 21 | } | |
| 22 | ||
| 23 | location / { | |
| 24 | set $upstream http://192.168.0.251:9900; | |
| 25 | proxy_pass $upstream; | |
| 26 | ||
| 27 | include custom.d/reverse_proxy/authelia_request.conf; | |
| 28 | include custom.d/reverse_proxy/basic.conf; | |
| 29 | } | |
| 30 | ||
| 31 | include custom.d/security/robots_index_only.conf; | |
| 32 | # ---------------------------------------------------------------------- | |
| 33 | } | |
| 34 | ||
| 35 | # ---------------------------------------------------------------------- | |
| 36 | # | Config file for non-secure host | | |
| 37 | # ---------------------------------------------------------------------- | |
| 38 | server { | |
| 39 | listen [::]:80; | |
| 40 | listen 80; | |
| 41 | server_name irc.cleberg.net; | |
| 42 | ||
| 43 | return 301 https://$host$request_uri; | |
| 44 | } | |
linux/nginx/etc/nginx/conf.d/ld.conf added +39
| @@ -0,0 +1,39 @@ | ||
| 1 | # ---------------------------------------------------------------------- | |
| 2 | # | Config file for host | | |
| 3 | # ---------------------------------------------------------------------- | |
| 4 | server { | |
| 5 | listen [::]:443 ssl; | |
| 6 | listen 443 ssl; | |
| 7 | http2 on; | |
| 8 | ||
| 9 | server_name ld.cleberg.net; | |
| 10 | ||
| 11 | include custom.d/tls/ssl_engine.conf; | |
| 12 | include custom.d/tls/certificate_files.conf; | |
| 13 | include custom.d/tls/policy_balanced.conf; | |
| 14 | include custom.d/basic.conf; | |
| 15 | ||
| 16 | # ---------------------------------------------------------------------- | |
| 17 | # | Custom rules & config for specific website | | |
| 18 | # ---------------------------------------------------------------------- | |
| 19 | location / { | |
| 20 | set $upstream http://127.0.0.1:3004; | |
| 21 | proxy_pass $upstream; | |
| 22 | ||
| 23 | include custom.d/reverse_proxy/basic.conf; | |
| 24 | } | |
| 25 | ||
| 26 | include custom.d/security/robots_index_only.conf; | |
| 27 | # ---------------------------------------------------------------------- | |
| 28 | } | |
| 29 | ||
| 30 | # ---------------------------------------------------------------------- | |
| 31 | # | Config file for non-secure host | | |
| 32 | # ---------------------------------------------------------------------- | |
| 33 | server { | |
| 34 | listen [::]:80; | |
| 35 | listen 80; | |
| 36 | server_name ld.cleberg.net; | |
| 37 | ||
| 38 | return 301 https://$host$request_uri; | |
| 39 | } | |
linux/nginx/etc/nginx/conf.d/lemmy.conf added +39
| @@ -0,0 +1,39 @@ | ||
| 1 | # ---------------------------------------------------------------------- | |
| 2 | # | Config file for host | | |
| 3 | # ---------------------------------------------------------------------- | |
| 4 | server { | |
| 5 | listen [::]:443 ssl; | |
| 6 | listen 443 ssl; | |
| 7 | http2 on; | |
| 8 | ||
| 9 | server_name lemmy.cleberg.net; | |
| 10 | ||
| 11 | include custom.d/tls/ssl_engine.conf; | |
| 12 | include custom.d/tls/certificate_files.conf; | |
| 13 | include custom.d/tls/policy_balanced.conf; | |
| 14 | include custom.d/basic.conf; | |
| 15 | ||
| 16 | # ---------------------------------------------------------------------- | |
| 17 | # | Custom rules & config for specific website | | |
| 18 | # ---------------------------------------------------------------------- | |
| 19 | location / { | |
| 20 | set $upstream http://127.0.0.1:10633; | |
| 21 | proxy_pass $upstream; | |
| 22 | ||
| 23 | include custom.d/reverse_proxy/basic.conf; | |
| 24 | } | |
| 25 | ||
| 26 | include custom.d/security/robots_index_only.conf; | |
| 27 | # ---------------------------------------------------------------------- | |
| 28 | } | |
| 29 | ||
| 30 | # ---------------------------------------------------------------------- | |
| 31 | # | Config file for non-secure host | | |
| 32 | # ---------------------------------------------------------------------- | |
| 33 | server { | |
| 34 | listen [::]:80; | |
| 35 | listen 80; | |
| 36 | server_name lemmy.cleberg.net; | |
| 37 | ||
| 38 | return 301 https://$host$request_uri; | |
| 39 | } | |
linux/nginx/etc/nginx/conf.d/lt.conf added +39
| @@ -0,0 +1,39 @@ | ||
| 1 | # ---------------------------------------------------------------------- | |
| 2 | # | Config file for host | | |
| 3 | # ---------------------------------------------------------------------- | |
| 4 | server { | |
| 5 | listen [::]:443 ssl; | |
| 6 | listen 443 ssl; | |
| 7 | http2 on; | |
| 8 | ||
| 9 | server_name lt.cleberg.net; | |
| 10 | ||
| 11 | include custom.d/tls/ssl_engine.conf; | |
| 12 | include custom.d/tls/certificate_files.conf; | |
| 13 | include custom.d/tls/policy_balanced.conf; | |
| 14 | include custom.d/basic.conf; | |
| 15 | ||
| 16 | # ---------------------------------------------------------------------- | |
| 17 | # | Custom rules & config for specific website | | |
| 18 | # ---------------------------------------------------------------------- | |
| 19 | location / { | |
| 20 | set $upstream http://127.0.0.1:5000; | |
| 21 | proxy_pass $upstream; | |
| 22 | ||
| 23 | include custom.d/reverse_proxy/basic.conf; | |
| 24 | } | |
| 25 | ||
| 26 | include custom.d/security/robots_index_only.conf; | |
| 27 | # ---------------------------------------------------------------------- | |
| 28 | } | |
| 29 | ||
| 30 | # ---------------------------------------------------------------------- | |
| 31 | # | Config file for non-secure host | | |
| 32 | # ---------------------------------------------------------------------- | |
| 33 | server { | |
| 34 | listen [::]:80; | |
| 35 | listen 80; | |
| 36 | server_name lt.cleberg.net; | |
| 37 | ||
| 38 | return 301 https://$host$request_uri; | |
| 39 | } | |
linux/nginx/etc/nginx/conf.d/mz.conf added +39
| @@ -0,0 +1,39 @@ | ||
| 1 | # ---------------------------------------------------------------------- | |
| 2 | # | Config file for host | | |
| 3 | # ---------------------------------------------------------------------- | |
| 4 | server { | |
| 5 | listen [::]:443 ssl; | |
| 6 | listen 443 ssl; | |
| 7 | http2 on; | |
| 8 | ||
| 9 | server_name mz.cleberg.net; | |
| 10 | ||
| 11 | include custom.d/tls/ssl_engine.conf; | |
| 12 | include custom.d/tls/certificate_files.conf; | |
| 13 | include custom.d/tls/policy_balanced.conf; | |
| 14 | include custom.d/basic.conf; | |
| 15 | ||
| 16 | # ---------------------------------------------------------------------- | |
| 17 | # | Custom rules & config for specific website | | |
| 18 | # ---------------------------------------------------------------------- | |
| 19 | location / { | |
| 20 | set $upstream http://127.0.0.1:3474; | |
| 21 | proxy_pass $upstream; | |
| 22 | ||
| 23 | include custom.d/reverse_proxy/basic.conf; | |
| 24 | } | |
| 25 | ||
| 26 | include custom.d/security/robots_index_only.conf; | |
| 27 | # ---------------------------------------------------------------------- | |
| 28 | } | |
| 29 | ||
| 30 | # ---------------------------------------------------------------------- | |
| 31 | # | Config file for non-secure host | | |
| 32 | # ---------------------------------------------------------------------- | |
| 33 | server { | |
| 34 | listen [::]:80; | |
| 35 | listen 80; | |
| 36 | server_name mz.cleberg.net; | |
| 37 | ||
| 38 | return 301 https://$host$request_uri; | |
| 39 | } | |
linux/nginx/etc/nginx/conf.d/no-ssl.default.conf added +27
| @@ -0,0 +1,27 @@ | ||
| 1 | # ---------------------------------------------------------------------- | |
| 2 | # | Default behavior for unknown hosts | | |
| 3 | # ---------------------------------------------------------------------- | |
| 4 | # | |
| 5 | # Drop requests for unknown hosts. | |
| 6 | # | |
| 7 | # If no default server is defined, Nginx will use the first found server. | |
| 8 | # To prevent host header attacks, or other potential problems when an unknown | |
| 9 | # server name is used in a request, it's recommended to drop the request | |
| 10 | # returning 444 "No Response". | |
| 11 | # | |
| 12 | # (1) In production, only secure hosts should be used (all `no-ssl` disabled). | |
| 13 | # If so, redirect first ANY request to a secure connection before handling | |
| 14 | # it, even if the host is unknown. | |
| 15 | # | |
| 16 | # https://observatory.mozilla.org/faq/ | |
| 17 | ||
| 18 | server { | |
| 19 | listen [::]:80 default_server deferred; | |
| 20 | listen 80 default_server deferred; | |
| 21 | ||
| 22 | server_name _; | |
| 23 | ||
| 24 | # (1) | |
| 25 | return 301 https://$host$request_uri; | |
| 26 | # return 444; | |
| 27 | } | |
linux/nginx/etc/nginx/conf.d/office.conf added +35
| @@ -0,0 +1,35 @@ | ||
| 1 | # ---------------------------------------------------------------------- | |
| 2 | # | Config file for host | | |
| 3 | # ---------------------------------------------------------------------- | |
| 4 | server { | |
| 5 | listen [::]:443 ssl; | |
| 6 | listen 443 ssl; | |
| 7 | http2 on; | |
| 8 | ||
| 9 | server_name office.cleberg.net; | |
| 10 | root /var/www/office/; | |
| 11 | ||
| 12 | include custom.d/tls/ssl_engine.conf; | |
| 13 | include custom.d/tls/certificate_files.conf; | |
| 14 | include custom.d/tls/policy_balanced.conf; | |
| 15 | include custom.d/basic.conf; | |
| 16 | ||
| 17 | # ---------------------------------------------------------------------- | |
| 18 | # | Custom rules & config for specific website | | |
| 19 | # ---------------------------------------------------------------------- | |
| 20 | location / { | |
| 21 | try_files $uri $uri/ /index.html; | |
| 22 | } | |
| 23 | # ---------------------------------------------------------------------- | |
| 24 | } | |
| 25 | ||
| 26 | # ---------------------------------------------------------------------- | |
| 27 | # | Config file for non-secure host | | |
| 28 | # ---------------------------------------------------------------------- | |
| 29 | server { | |
| 30 | listen [::]:80; | |
| 31 | listen 80; | |
| 32 | server_name office.cleberg.net; | |
| 33 | ||
| 34 | return 301 https://$host$request_uri; | |
| 35 | } | |
linux/nginx/etc/nginx/conf.d/org.conf added +35
| @@ -0,0 +1,35 @@ | ||
| 1 | # ---------------------------------------------------------------------- | |
| 2 | # | Config file for host | | |
| 3 | # ---------------------------------------------------------------------- | |
| 4 | server { | |
| 5 | listen [::]:443 ssl; | |
| 6 | listen 443 ssl; | |
| 7 | http2 on; | |
| 8 | ||
| 9 | server_name org.cleberg.net; | |
| 10 | root /var/www/org/; | |
| 11 | ||
| 12 | include custom.d/tls/ssl_engine.conf; | |
| 13 | include custom.d/tls/certificate_files.conf; | |
| 14 | include custom.d/tls/policy_balanced.conf; | |
| 15 | include custom.d/basic.conf; | |
| 16 | ||
| 17 | # ---------------------------------------------------------------------- | |
| 18 | # | Custom rules & config for specific website | | |
| 19 | # ---------------------------------------------------------------------- | |
| 20 | location / { | |
| 21 | try_files $uri $uri/ /index.html; | |
| 22 | } | |
| 23 | # ---------------------------------------------------------------------- | |
| 24 | } | |
| 25 | ||
| 26 | # ---------------------------------------------------------------------- | |
| 27 | # | Config file for non-secure host | | |
| 28 | # ---------------------------------------------------------------------- | |
| 29 | server { | |
| 30 | listen [::]:80; | |
| 31 | listen 80; | |
| 32 | server_name org.cleberg.net; | |
| 33 | ||
| 34 | return 301 https://$host$request_uri; | |
| 35 | } | |
linux/nginx/etc/nginx/conf.d/paste.conf added +39
| @@ -0,0 +1,39 @@ | ||
| 1 | # ---------------------------------------------------------------------- | |
| 2 | # | Config file for host | | |
| 3 | # ---------------------------------------------------------------------- | |
| 4 | server { | |
| 5 | listen [::]:443 ssl; | |
| 6 | listen 443 ssl; | |
| 7 | http2 on; | |
| 8 | ||
| 9 | server_name paste.cleberg.net; | |
| 10 | ||
| 11 | include custom.d/tls/ssl_engine.conf; | |
| 12 | include custom.d/tls/certificate_files.conf; | |
| 13 | include custom.d/tls/policy_balanced.conf; | |
| 14 | include custom.d/basic.conf; | |
| 15 | ||
| 16 | # ---------------------------------------------------------------------- | |
| 17 | # | Custom rules & config for specific website | | |
| 18 | # ---------------------------------------------------------------------- | |
| 19 | location / { | |
| 20 | set $upstream http://127.0.0.1:8084; | |
| 21 | proxy_pass $upstream; | |
| 22 | ||
| 23 | include custom.d/reverse_proxy/basic.conf; | |
| 24 | } | |
| 25 | ||
| 26 | include custom.d/security/robots_index_only.conf; | |
| 27 | # ---------------------------------------------------------------------- | |
| 28 | } | |
| 29 | ||
| 30 | # ---------------------------------------------------------------------- | |
| 31 | # | Config file for non-secure host | | |
| 32 | # ---------------------------------------------------------------------- | |
| 33 | server { | |
| 34 | listen [::]:80; | |
| 35 | listen 80; | |
| 36 | server_name paste.cleberg.net; | |
| 37 | ||
| 38 | return 301 https://$host$request_uri; | |
| 39 | } | |
linux/nginx/etc/nginx/conf.d/pb.conf added +39
| @@ -0,0 +1,39 @@ | ||
| 1 | # ---------------------------------------------------------------------- | |
| 2 | # | Config file for host | | |
| 3 | # ---------------------------------------------------------------------- | |
| 4 | server { | |
| 5 | listen [::]:443 ssl; | |
| 6 | listen 443 ssl; | |
| 7 | http2 on; | |
| 8 | ||
| 9 | server_name pb.cleberg.net; | |
| 10 | ||
| 11 | include custom.d/tls/ssl_engine.conf; | |
| 12 | include custom.d/tls/certificate_files.conf; | |
| 13 | include custom.d/tls/policy_balanced.conf; | |
| 14 | include custom.d/basic.conf; | |
| 15 | ||
| 16 | # ---------------------------------------------------------------------- | |
| 17 | # | Custom rules & config for specific website | | |
| 18 | # ---------------------------------------------------------------------- | |
| 19 | location / { | |
| 20 | set $upstream http://127.0.0.1:8745; | |
| 21 | proxy_pass $upstream; | |
| 22 | ||
| 23 | include custom.d/reverse_proxy/basic.conf; | |
| 24 | } | |
| 25 | ||
| 26 | # include custom.d/security/robots_index_only.conf; | |
| 27 | # ---------------------------------------------------------------------- | |
| 28 | } | |
| 29 | ||
| 30 | # ---------------------------------------------------------------------- | |
| 31 | # | Config file for non-secure host | | |
| 32 | # ---------------------------------------------------------------------- | |
| 33 | server { | |
| 34 | listen [::]:80; | |
| 35 | listen 80; | |
| 36 | server_name pb.cleberg.net; | |
| 37 | ||
| 38 | return 301 https://$host$request_uri; | |
| 39 | } | |
linux/nginx/etc/nginx/conf.d/pgp.conf added +37
| @@ -0,0 +1,37 @@ | ||
| 1 | # ---------------------------------------------------------------------- | |
| 2 | # | Config file for host | | |
| 3 | # ---------------------------------------------------------------------- | |
| 4 | server { | |
| 5 | listen [::]:443 ssl; | |
| 6 | listen 443 ssl; | |
| 7 | http2 on; | |
| 8 | ||
| 9 | server_name pgp.cleberg.net; | |
| 10 | root /var/www/pgp/; | |
| 11 | ||
| 12 | include custom.d/tls/ssl_engine.conf; | |
| 13 | include custom.d/tls/certificate_files.conf; | |
| 14 | include custom.d/tls/policy_balanced.conf; | |
| 15 | include custom.d/basic.conf; | |
| 16 | ||
| 17 | # ---------------------------------------------------------------------- | |
| 18 | # | Custom rules & config for specific website | | |
| 19 | # ---------------------------------------------------------------------- | |
| 20 | location / { | |
| 21 | try_files $uri $uri/ /index.html; | |
| 22 | } | |
| 23 | ||
| 24 | include custom.d/security/robots_index_only.conf; | |
| 25 | # ---------------------------------------------------------------------- | |
| 26 | } | |
| 27 | ||
| 28 | # ---------------------------------------------------------------------- | |
| 29 | # | Config file for non-secure host | | |
| 30 | # ---------------------------------------------------------------------- | |
| 31 | server { | |
| 32 | listen [::]:80; | |
| 33 | listen 80; | |
| 34 | server_name pgp.cleberg.net; | |
| 35 | ||
| 36 | return 301 https://$host$request_uri; | |
| 37 | } | |
linux/nginx/etc/nginx/conf.d/photos.conf added +54
| @@ -0,0 +1,54 @@ | ||
| 1 | # ---------------------------------------------------------------------- | |
| 2 | # | Config file for host | | |
| 3 | # ---------------------------------------------------------------------- | |
| 4 | server { | |
| 5 | listen [::]:443 ssl; | |
| 6 | listen 443 ssl; | |
| 7 | http2 on; | |
| 8 | ||
| 9 | server_name photos.cleberg.net; | |
| 10 | ||
| 11 | include custom.d/tls/ssl_engine.conf; | |
| 12 | include custom.d/tls/certificate_files.conf; | |
| 13 | include custom.d/tls/policy_balanced.conf; | |
| 14 | include custom.d/basic.conf; | |
| 15 | ||
| 16 | # ---------------------------------------------------------------------- | |
| 17 | # | Custom rules & config for specific website | | |
| 18 | # ---------------------------------------------------------------------- | |
| 19 | # allow large file uploads | |
| 20 | client_max_body_size 50000M; | |
| 21 | ||
| 22 | # Set headers | |
| 23 | proxy_set_header Host $host; | |
| 24 | proxy_set_header X-Real-IP $remote_addr; | |
| 25 | proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; | |
| 26 | proxy_set_header X-Forwarded-Proto $scheme; | |
| 27 | ||
| 28 | # enable websockets: http://nginx.org/en/docs/http/websocket.html | |
| 29 | proxy_http_version 1.1; | |
| 30 | proxy_set_header Upgrade $http_upgrade; | |
| 31 | proxy_set_header Connection "upgrade"; | |
| 32 | proxy_redirect off; | |
| 33 | ||
| 34 | # set timeout | |
| 35 | proxy_read_timeout 600s; | |
| 36 | proxy_send_timeout 600s; | |
| 37 | send_timeout 600s; | |
| 38 | ||
| 39 | location / { | |
| 40 | proxy_pass http://127.0.0.1:2283; | |
| 41 | } | |
| 42 | # ---------------------------------------------------------------------- | |
| 43 | } | |
| 44 | ||
| 45 | # ---------------------------------------------------------------------- | |
| 46 | # | Config file for non-secure host | | |
| 47 | # ---------------------------------------------------------------------- | |
| 48 | server { | |
| 49 | listen [::]:80; | |
| 50 | listen 80; | |
| 51 | server_name photos.cleberg.net; | |
| 52 | ||
| 53 | return 301 https://$host$request_uri; | |
| 54 | } | |
linux/nginx/etc/nginx/conf.d/pin.conf added +39
| @@ -0,0 +1,39 @@ | ||
| 1 | # ---------------------------------------------------------------------- | |
| 2 | # | Config file for host | | |
| 3 | # ---------------------------------------------------------------------- | |
| 4 | server { | |
| 5 | listen [::]:443 ssl; | |
| 6 | listen 443 ssl; | |
| 7 | http2 on; | |
| 8 | ||
| 9 | server_name pin.cleberg.net; | |
| 10 | ||
| 11 | include custom.d/tls/ssl_engine.conf; | |
| 12 | include custom.d/tls/certificate_files.conf; | |
| 13 | include custom.d/tls/policy_balanced.conf; | |
| 14 | include custom.d/basic.conf; | |
| 15 | ||
| 16 | # ---------------------------------------------------------------------- | |
| 17 | # | Custom rules & config for specific website | | |
| 18 | # ---------------------------------------------------------------------- | |
| 19 | location / { | |
| 20 | set $upstream http://127.0.0.1:8086; | |
| 21 | proxy_pass $upstream; | |
| 22 | ||
| 23 | include custom.d/reverse_proxy/basic.conf; | |
| 24 | } | |
| 25 | ||
| 26 | include custom.d/security/robots_index_only.conf; | |
| 27 | # ---------------------------------------------------------------------- | |
| 28 | } | |
| 29 | ||
| 30 | # ---------------------------------------------------------------------- | |
| 31 | # | Config file for non-secure host | | |
| 32 | # ---------------------------------------------------------------------- | |
| 33 | server { | |
| 34 | listen [::]:80; | |
| 35 | listen 80; | |
| 36 | server_name pin.cleberg.net; | |
| 37 | ||
| 38 | return 301 https://$host$request_uri; | |
| 39 | } | |
linux/nginx/etc/nginx/conf.d/piped.conf added +40
| @@ -0,0 +1,40 @@ | ||
| 1 | # ---------------------------------------------------------------------- | |
| 2 | # | Config file for host | | |
| 3 | # ---------------------------------------------------------------------- | |
| 4 | server { | |
| 5 | listen [::]:443 ssl; | |
| 6 | listen 443 ssl; | |
| 7 | http2 on; | |
| 8 | ||
| 9 | server_name piped.cleberg.net pipedapi.cleberg.net pipedproxy.cleberg.net; | |
| 10 | ||
| 11 | include custom.d/tls/ssl_engine.conf; | |
| 12 | include custom.d/tls/certificate_files.conf; | |
| 13 | include custom.d/tls/policy_balanced.conf; | |
| 14 | include custom.d/basic.conf; | |
| 15 | ||
| 16 | # ---------------------------------------------------------------------- | |
| 17 | # | Custom rules & config for specific website | | |
| 18 | # ---------------------------------------------------------------------- | |
| 19 | location / { | |
| 20 | set $upstream http://127.0.0.1:8077; | |
| 21 | proxy_pass $upstream; | |
| 22 | ||
| 23 | proxy_set_header Host $host; | |
| 24 | # include custom.d/reverse_proxy/basic.conf; | |
| 25 | } | |
| 26 | ||
| 27 | include custom.d/security/robots_index_only.conf; | |
| 28 | # ---------------------------------------------------------------------- | |
| 29 | } | |
| 30 | ||
| 31 | # ---------------------------------------------------------------------- | |
| 32 | # | Config file for non-secure host | | |
| 33 | # ---------------------------------------------------------------------- | |
| 34 | server { | |
| 35 | listen [::]:80; | |
| 36 | listen 80; | |
| 37 | server_name piped.cleberg.net pipedapi.cleberg.net pipedproxy.cleberg.net; | |
| 38 | ||
| 39 | return 301 https://$host$request_uri; | |
| 40 | } | |
linux/nginx/etc/nginx/conf.d/projects.conf added +36
| @@ -0,0 +1,36 @@ | ||
| 1 | # ---------------------------------------------------------------------- | |
| 2 | # | Config file for host | | |
| 3 | # ---------------------------------------------------------------------- | |
| 4 | server { | |
| 5 | listen [::]:443 ssl; | |
| 6 | listen 443 ssl; | |
| 7 | http2 on; | |
| 8 | ||
| 9 | server_name projects.cleberg.net; | |
| 10 | root /var/www/projects/; | |
| 11 | autoindex on; | |
| 12 | ||
| 13 | include custom.d/tls/ssl_engine.conf; | |
| 14 | include custom.d/tls/certificate_files.conf; | |
| 15 | include custom.d/tls/policy_balanced.conf; | |
| 16 | include custom.d/basic.conf; | |
| 17 | ||
| 18 | # ---------------------------------------------------------------------- | |
| 19 | # | Custom rules & config for specific website | | |
| 20 | # ---------------------------------------------------------------------- | |
| 21 | location / { | |
| 22 | try_files $uri $uri/ /index.html; | |
| 23 | } | |
| 24 | # ---------------------------------------------------------------------- | |
| 25 | } | |
| 26 | ||
| 27 | # ---------------------------------------------------------------------- | |
| 28 | # | Config file for non-secure host | | |
| 29 | # ---------------------------------------------------------------------- | |
| 30 | server { | |
| 31 | listen [::]:80; | |
| 32 | listen 80; | |
| 33 | server_name projects.cleberg.net; | |
| 34 | ||
| 35 | return 301 https://$host$request_uri; | |
| 36 | } | |
linux/nginx/etc/nginx/conf.d/rd.conf added +39
| @@ -0,0 +1,39 @@ | ||
| 1 | # ---------------------------------------------------------------------- | |
| 2 | # | Config file for host | | |
| 3 | # ---------------------------------------------------------------------- | |
| 4 | server { | |
| 5 | listen [::]:443 ssl; | |
| 6 | listen 443 ssl; | |
| 7 | http2 on; | |
| 8 | ||
| 9 | server_name rd.cleberg.net; | |
| 10 | ||
| 11 | include custom.d/tls/ssl_engine.conf; | |
| 12 | include custom.d/tls/certificate_files.conf; | |
| 13 | include custom.d/tls/policy_balanced.conf; | |
| 14 | include custom.d/basic.conf; | |
| 15 | ||
| 16 | # ---------------------------------------------------------------------- | |
| 17 | # | Custom rules & config for specific website | | |
| 18 | # ---------------------------------------------------------------------- | |
| 19 | location / { | |
| 20 | set $upstream http://127.0.0.1:5758; | |
| 21 | proxy_pass $upstream; | |
| 22 | ||
| 23 | include custom.d/reverse_proxy/basic.conf; | |
| 24 | } | |
| 25 | ||
| 26 | include custom.d/security/robots_index_only.conf; | |
| 27 | # ---------------------------------------------------------------------- | |
| 28 | } | |
| 29 | ||
| 30 | # ---------------------------------------------------------------------- | |
| 31 | # | Config file for non-secure host | | |
| 32 | # ---------------------------------------------------------------------- | |
| 33 | server { | |
| 34 | listen [::]:80; | |
| 35 | listen 80; | |
| 36 | server_name rd.cleberg.net; | |
| 37 | ||
| 38 | return 301 https://$host$request_uri; | |
| 39 | } | |
linux/nginx/etc/nginx/conf.d/reminiscecleberg.com.conf added +56
| @@ -0,0 +1,56 @@ | ||
| 1 | # ---------------------------------------------------------------------- | |
| 2 | # | Config file for host | | |
| 3 | # ---------------------------------------------------------------------- | |
| 4 | server { | |
| 5 | listen [::]:443 ssl; | |
| 6 | listen 443 ssl; | |
| 7 | http2 on; | |
| 8 | ||
| 9 | server_name www.reminiscecleberg.com; | |
| 10 | ||
| 11 | include custom.d/tls/ssl_engine.conf; | |
| 12 | include custom.d/tls/policy_balanced.conf; | |
| 13 | # include custom.d/tls/certificate_files.conf; | |
| 14 | ssl_certificate /etc/letsencrypt/live/reminiscecleberg.com/fullchain.pem; | |
| 15 | ssl_certificate_key /etc/letsencrypt/live/reminiscecleberg.com/privkey.pem; | |
| 16 | ssl_trusted_certificate /etc/letsencrypt/live/reminiscecleberg.com/chain.pem; | |
| 17 | ||
| 18 | return 301 $scheme://reminiscecleberg.com$request_uri; | |
| 19 | } | |
| 20 | ||
| 21 | ||
| 22 | server { | |
| 23 | listen [::]:443 ssl; | |
| 24 | listen 443 ssl; | |
| 25 | http2 on; | |
| 26 | ||
| 27 | server_name reminiscecleberg.com; | |
| 28 | root /var/www/reminiscecleberg.com/; | |
| 29 | ||
| 30 | include custom.d/tls/ssl_engine.conf; | |
| 31 | include custom.d/tls/policy_balanced.conf; | |
| 32 | include custom.d/basic.conf; | |
| 33 | # include custom.d/tls/certificate_files.conf; | |
| 34 | ssl_certificate /etc/letsencrypt/live/reminiscecleberg.com/fullchain.pem; | |
| 35 | ssl_certificate_key /etc/letsencrypt/live/reminiscecleberg.com/privkey.pem; | |
| 36 | ssl_trusted_certificate /etc/letsencrypt/live/reminiscecleberg.com/chain.pem; | |
| 37 | ||
| 38 | # ---------------------------------------------------------------------- | |
| 39 | # | Custom rules & config for specific website | | |
| 40 | # ---------------------------------------------------------------------- | |
| 41 | location / { | |
| 42 | try_files $uri $uri/ =404; | |
| 43 | } | |
| 44 | # ---------------------------------------------------------------------- | |
| 45 | } | |
| 46 | ||
| 47 | # ---------------------------------------------------------------------- | |
| 48 | # | Config file for non-secure host | | |
| 49 | # ---------------------------------------------------------------------- | |
| 50 | server { | |
| 51 | listen [::]:80; | |
| 52 | listen 80; | |
| 53 | server_name www.reminiscecleberg.com reminiscecleberg.com; | |
| 54 | ||
| 55 | return 301 https://reminiscecleberg.com$request_uri; | |
| 56 | } | |
linux/nginx/etc/nginx/conf.d/rimgo.conf added +39
| @@ -0,0 +1,39 @@ | ||
| 1 | # ---------------------------------------------------------------------- | |
| 2 | # | Config file for host | | |
| 3 | # ---------------------------------------------------------------------- | |
| 4 | server { | |
| 5 | listen [::]:443 ssl; | |
| 6 | listen 443 ssl; | |
| 7 | http2 on; | |
| 8 | ||
| 9 | server_name rimgo.cleberg.net; | |
| 10 | ||
| 11 | include custom.d/tls/ssl_engine.conf; | |
| 12 | include custom.d/tls/certificate_files.conf; | |
| 13 | include custom.d/tls/policy_balanced.conf; | |
| 14 | include custom.d/basic.conf; | |
| 15 | ||
| 16 | # ---------------------------------------------------------------------- | |
| 17 | # | Custom rules & config for specific website | | |
| 18 | # ---------------------------------------------------------------------- | |
| 19 | location / { | |
| 20 | set $upstream http://127.0.0.1:3869; | |
| 21 | proxy_pass $upstream; | |
| 22 | ||
| 23 | include custom.d/reverse_proxy/basic.conf; | |
| 24 | } | |
| 25 | ||
| 26 | include custom.d/security/robots_index_only.conf; | |
| 27 | # ---------------------------------------------------------------------- | |
| 28 | } | |
| 29 | ||
| 30 | # ---------------------------------------------------------------------- | |
| 31 | # | Config file for non-secure host | | |
| 32 | # ---------------------------------------------------------------------- | |
| 33 | server { | |
| 34 | listen [::]:80; | |
| 35 | listen 80; | |
| 36 | server_name rimgo.cleberg.net; | |
| 37 | ||
| 38 | return 301 https://$host$request_uri; | |
| 39 | } | |
linux/nginx/etc/nginx/conf.d/rl.conf added +44
| @@ -0,0 +1,44 @@ | ||
| 1 | # ---------------------------------------------------------------------- | |
| 2 | # | Config file for host | | |
| 3 | # ---------------------------------------------------------------------- | |
| 4 | server { | |
| 5 | listen [::]:443 ssl; | |
| 6 | listen 443 ssl; | |
| 7 | http2 on; | |
| 8 | ||
| 9 | server_name rl.cleberg.net; | |
| 10 | ||
| 11 | include custom.d/tls/ssl_engine.conf; | |
| 12 | include custom.d/tls/certificate_files.conf; | |
| 13 | include custom.d/tls/policy_balanced.conf; | |
| 14 | include custom.d/basic.conf; | |
| 15 | ||
| 16 | # ---------------------------------------------------------------------- | |
| 17 | # | Custom rules & config for specific website | | |
| 18 | # ---------------------------------------------------------------------- | |
| 19 | location /authelia { | |
| 20 | include custom.d/reverse_proxy/authelia.conf; | |
| 21 | } | |
| 22 | ||
| 23 | location / { | |
| 24 | set $upstream http://192.168.0.251:8983; | |
| 25 | proxy_pass $upstream; | |
| 26 | ||
| 27 | include custom.d/reverse_proxy/authelia_request.conf; | |
| 28 | include custom.d/reverse_proxy/basic.conf; | |
| 29 | } | |
| 30 | ||
| 31 | include custom.d/security/robots_index_only.conf; | |
| 32 | # ---------------------------------------------------------------------- | |
| 33 | } | |
| 34 | ||
| 35 | # ---------------------------------------------------------------------- | |
| 36 | # | Config file for non-secure host | | |
| 37 | # ---------------------------------------------------------------------- | |
| 38 | server { | |
| 39 | listen [::]:80; | |
| 40 | listen 80; | |
| 41 | server_name rl.cleberg.net; | |
| 42 | ||
| 43 | return 301 https://$host$request_uri; | |
| 44 | } | |
linux/nginx/etc/nginx/conf.d/rss.conf added +58
| @@ -0,0 +1,58 @@ | ||
| 1 | # ---------------------------------------------------------------------- | |
| 2 | # | Config file for host | | |
| 3 | # ---------------------------------------------------------------------- | |
| 4 | upstream freshrss { | |
| 5 | server 192.168.0.251:8081; | |
| 6 | keepalive 64; | |
| 7 | } | |
| 8 | ||
| 9 | server { | |
| 10 | listen [::]:443 ssl; | |
| 11 | listen 443 ssl; | |
| 12 | http2 on; | |
| 13 | ||
| 14 | server_name rss.cleberg.net; | |
| 15 | ||
| 16 | include custom.d/tls/ssl_engine.conf; | |
| 17 | include custom.d/tls/certificate_files.conf; | |
| 18 | include custom.d/tls/policy_balanced.conf; | |
| 19 | include custom.d/basic.conf; | |
| 20 | ||
| 21 | # ---------------------------------------------------------------------- | |
| 22 | # | Custom rules & config for specific website | | |
| 23 | # ---------------------------------------------------------------------- | |
| 24 | location / { | |
| 25 | proxy_pass http://freshrss/; | |
| 26 | ||
| 27 | # include custom.d/reverse_proxy/basic.conf; | |
| 28 | ||
| 29 | add_header X-Frame-Options SAMEORIGIN; | |
| 30 | add_header X-XSS-Protection "1; mode=block"; | |
| 31 | proxy_redirect off; | |
| 32 | proxy_buffering off; | |
| 33 | proxy_set_header Host $host; | |
| 34 | proxy_set_header X-Real-IP $remote_addr; | |
| 35 | proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; | |
| 36 | proxy_set_header X-Forwarded-Proto $scheme; | |
| 37 | proxy_set_header X-Forwarded-Port $server_port; | |
| 38 | proxy_read_timeout 90; | |
| 39 | ||
| 40 | # Forward the Authorization header for the Google Reader API. | |
| 41 | proxy_set_header Authorization $http_authorization; | |
| 42 | proxy_pass_header Authorization; | |
| 43 | } | |
| 44 | ||
| 45 | include custom.d/security/robots_index_only.conf; | |
| 46 | # ---------------------------------------------------------------------- | |
| 47 | } | |
| 48 | ||
| 49 | # ---------------------------------------------------------------------- | |
| 50 | # | Config file for non-secure host | | |
| 51 | # ---------------------------------------------------------------------- | |
| 52 | server { | |
| 53 | listen [::]:80; | |
| 54 | listen 80; | |
| 55 | server_name rss.cleberg.net; | |
| 56 | ||
| 57 | return 301 https://$host$request_uri; | |
| 58 | } | |
linux/nginx/etc/nginx/conf.d/search.conf added +44
| @@ -0,0 +1,44 @@ | ||
| 1 | # ---------------------------------------------------------------------- | |
| 2 | # | Config file for host | | |
| 3 | # ---------------------------------------------------------------------- | |
| 4 | server { | |
| 5 | listen [::]:443 ssl; | |
| 6 | listen 443 ssl; | |
| 7 | http2 on; | |
| 8 | ||
| 9 | server_name search.cleberg.net; | |
| 10 | ||
| 11 | include custom.d/tls/ssl_engine.conf; | |
| 12 | include custom.d/tls/certificate_files.conf; | |
| 13 | include custom.d/tls/policy_balanced.conf; | |
| 14 | include custom.d/basic.conf; | |
| 15 | ||
| 16 | # ---------------------------------------------------------------------- | |
| 17 | # | Custom rules & config for specific website | | |
| 18 | # ---------------------------------------------------------------------- | |
| 19 | location / { | |
| 20 | set $upstream http://127.0.0.1:9191; | |
| 21 | proxy_pass $upstream; | |
| 22 | ||
| 23 | # include custom.d/reverse_proxy/basic.conf; | |
| 24 | proxy_set_header Host $host; | |
| 25 | proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; | |
| 26 | proxy_set_header Upgrade $http_upgrade; | |
| 27 | proxy_set_header Connection "upgrade"; | |
| 28 | proxy_http_version 1.1; | |
| 29 | } | |
| 30 | ||
| 31 | include custom.d/security/robots_index_only.conf; | |
| 32 | # ---------------------------------------------------------------------- | |
| 33 | } | |
| 34 | ||
| 35 | # ---------------------------------------------------------------------- | |
| 36 | # | Config file for non-secure host | | |
| 37 | # ---------------------------------------------------------------------- | |
| 38 | server { | |
| 39 | listen [::]:80; | |
| 40 | listen 80; | |
| 41 | server_name search.cleberg.net; | |
| 42 | ||
| 43 | return 301 https://$host$request_uri; | |
| 44 | } | |
linux/nginx/etc/nginx/conf.d/send.conf added +39
| @@ -0,0 +1,39 @@ | ||
| 1 | # ---------------------------------------------------------------------- | |
| 2 | # | Config file for host | | |
| 3 | # ---------------------------------------------------------------------- | |
| 4 | server { | |
| 5 | listen [::]:443 ssl; | |
| 6 | listen 443 ssl; | |
| 7 | http2 on; | |
| 8 | ||
| 9 | server_name send.cleberg.net; | |
| 10 | ||
| 11 | include custom.d/tls/ssl_engine.conf; | |
| 12 | include custom.d/tls/certificate_files.conf; | |
| 13 | include custom.d/tls/policy_balanced.conf; | |
| 14 | include custom.d/basic.conf; | |
| 15 | ||
| 16 | # ---------------------------------------------------------------------- | |
| 17 | # | Custom rules & config for specific website | | |
| 18 | # ---------------------------------------------------------------------- | |
| 19 | location / { | |
| 20 | set $upstream http://127.0.0.1:1443; | |
| 21 | proxy_pass $upstream; | |
| 22 | ||
| 23 | include custom.d/reverse_proxy/basic.conf; | |
| 24 | } | |
| 25 | ||
| 26 | include custom.d/security/robots_index_only.conf; | |
| 27 | # ---------------------------------------------------------------------- | |
| 28 | } | |
| 29 | ||
| 30 | # ---------------------------------------------------------------------- | |
| 31 | # | Config file for non-secure host | | |
| 32 | # ---------------------------------------------------------------------- | |
| 33 | server { | |
| 34 | listen [::]:80; | |
| 35 | listen 80; | |
| 36 | server_name send.cleberg.net; | |
| 37 | ||
| 38 | return 301 https://$host$request_uri; | |
| 39 | } | |
linux/nginx/etc/nginx/conf.d/slash.conf added +39
| @@ -0,0 +1,39 @@ | ||
| 1 | # ---------------------------------------------------------------------- | |
| 2 | # | Config file for host | | |
| 3 | # ---------------------------------------------------------------------- | |
| 4 | server { | |
| 5 | listen [::]:443 ssl; | |
| 6 | listen 443 ssl; | |
| 7 | http2 on; | |
| 8 | ||
| 9 | server_name slash.cleberg.net; | |
| 10 | ||
| 11 | include custom.d/tls/ssl_engine.conf; | |
| 12 | include custom.d/tls/certificate_files.conf; | |
| 13 | include custom.d/tls/policy_balanced.conf; | |
| 14 | include custom.d/basic.conf; | |
| 15 | ||
| 16 | # ---------------------------------------------------------------------- | |
| 17 | # | Custom rules & config for specific website | | |
| 18 | # ---------------------------------------------------------------------- | |
| 19 | location / { | |
| 20 | set $upstream http://192.168.0.251:5231; | |
| 21 | proxy_pass $upstream; | |
| 22 | ||
| 23 | include custom.d/reverse_proxy/basic.conf; | |
| 24 | } | |
| 25 | ||
| 26 | include custom.d/security/robots_index_only.conf; | |
| 27 | # ---------------------------------------------------------------------- | |
| 28 | } | |
| 29 | ||
| 30 | # ---------------------------------------------------------------------- | |
| 31 | # | Config file for non-secure host | | |
| 32 | # ---------------------------------------------------------------------- | |
| 33 | server { | |
| 34 | listen [::]:80; | |
| 35 | listen 80; | |
| 36 | server_name slash.cleberg.net; | |
| 37 | ||
| 38 | return 301 https://$host$request_uri; | |
| 39 | } | |
linux/nginx/etc/nginx/conf.d/small.conf added +39
| @@ -0,0 +1,39 @@ | ||
| 1 | # ---------------------------------------------------------------------- | |
| 2 | # | Config file for host | | |
| 3 | # ---------------------------------------------------------------------- | |
| 4 | server { | |
| 5 | listen [::]:443 ssl; | |
| 6 | listen 443 ssl; | |
| 7 | http2 on; | |
| 8 | ||
| 9 | server_name small.cleberg.net; | |
| 10 | ||
| 11 | include custom.d/tls/ssl_engine.conf; | |
| 12 | include custom.d/tls/certificate_files.conf; | |
| 13 | include custom.d/tls/policy_balanced.conf; | |
| 14 | include custom.d/basic.conf; | |
| 15 | ||
| 16 | # ---------------------------------------------------------------------- | |
| 17 | # | Custom rules & config for specific website | | |
| 18 | # ---------------------------------------------------------------------- | |
| 19 | location / { | |
| 20 | set $upstream http://127.0.0.1:8002; | |
| 21 | proxy_pass $upstream; | |
| 22 | ||
| 23 | include custom.d/reverse_proxy/basic.conf; | |
| 24 | } | |
| 25 | ||
| 26 | include custom.d/security/robots_index_only.conf; | |
| 27 | # ---------------------------------------------------------------------- | |
| 28 | } | |
| 29 | ||
| 30 | # ---------------------------------------------------------------------- | |
| 31 | # | Config file for non-secure host | | |
| 32 | # ---------------------------------------------------------------------- | |
| 33 | server { | |
| 34 | listen [::]:80; | |
| 35 | listen 80; | |
| 36 | server_name small.cleberg.net; | |
| 37 | ||
| 38 | return 301 https://$host$request_uri; | |
| 39 | } | |
linux/nginx/etc/nginx/conf.d/ssh.conf added +44
| @@ -0,0 +1,44 @@ | ||
| 1 | # ---------------------------------------------------------------------- | |
| 2 | # | Config file for host | | |
| 3 | # ---------------------------------------------------------------------- | |
| 4 | server { | |
| 5 | listen [::]:443 ssl; | |
| 6 | listen 443 ssl; | |
| 7 | http2 on; | |
| 8 | ||
| 9 | server_name ssh.cleberg.net; | |
| 10 | ||
| 11 | include custom.d/tls/ssl_engine.conf; | |
| 12 | include custom.d/tls/certificate_files.conf; | |
| 13 | include custom.d/tls/policy_balanced.conf; | |
| 14 | include custom.d/basic.conf; | |
| 15 | ||
| 16 | # ---------------------------------------------------------------------- | |
| 17 | # | Custom rules & config for specific website | | |
| 18 | # ---------------------------------------------------------------------- | |
| 19 | location /authelia { | |
| 20 | include custom.d/reverse_proxy/authelia.conf; | |
| 21 | } | |
| 22 | ||
| 23 | location / { | |
| 24 | set $upstream http://127.0.0.1:8169; | |
| 25 | proxy_pass $upstream; | |
| 26 | ||
| 27 | include custom.d/reverse_proxy/authelia_request.conf; | |
| 28 | include custom.d/reverse_proxy/basic.conf; | |
| 29 | } | |
| 30 | ||
| 31 | include custom.d/security/robots_index_only.conf; | |
| 32 | # ---------------------------------------------------------------------- | |
| 33 | } | |
| 34 | ||
| 35 | # ---------------------------------------------------------------------- | |
| 36 | # | Config file for non-secure host | | |
| 37 | # ---------------------------------------------------------------------- | |
| 38 | server { | |
| 39 | listen [::]:80; | |
| 40 | listen 80; | |
| 41 | server_name ssh.cleberg.net; | |
| 42 | ||
| 43 | return 301 https://$host$request_uri; | |
| 44 | } | |
linux/nginx/etc/nginx/conf.d/teddit.conf added +44
| @@ -0,0 +1,44 @@ | ||
| 1 | # ---------------------------------------------------------------------- | |
| 2 | # | Config file for host | | |
| 3 | # ---------------------------------------------------------------------- | |
| 4 | server { | |
| 5 | listen [::]:443 ssl; | |
| 6 | listen 443 ssl; | |
| 7 | http2 on; | |
| 8 | ||
| 9 | server_name teddit.cleberg.net; | |
| 10 | ||
| 11 | include custom.d/tls/ssl_engine.conf; | |
| 12 | include custom.d/tls/certificate_files.conf; | |
| 13 | include custom.d/tls/policy_balanced.conf; | |
| 14 | include custom.d/basic.conf; | |
| 15 | ||
| 16 | # ---------------------------------------------------------------------- | |
| 17 | # | Custom rules & config for specific website | | |
| 18 | # ---------------------------------------------------------------------- | |
| 19 | location /authelia { | |
| 20 | include custom.d/reverse_proxy/authelia.conf; | |
| 21 | } | |
| 22 | ||
| 23 | location / { | |
| 24 | set $upstream http://192.168.0.251:8181; | |
| 25 | proxy_pass $upstream; | |
| 26 | ||
| 27 | include custom.d/reverse_proxy/authelia_request.conf; | |
| 28 | include custom.d/reverse_proxy/basic.conf; | |
| 29 | } | |
| 30 | ||
| 31 | include custom.d/security/robots_index_only.conf; | |
| 32 | # ---------------------------------------------------------------------- | |
| 33 | } | |
| 34 | ||
| 35 | # ---------------------------------------------------------------------- | |
| 36 | # | Config file for non-secure host | | |
| 37 | # ---------------------------------------------------------------------- | |
| 38 | server { | |
| 39 | listen [::]:80; | |
| 40 | listen 80; | |
| 41 | server_name teddit.cleberg.net; | |
| 42 | ||
| 43 | return 301 https://$host$request_uri; | |
| 44 | } | |
linux/nginx/etc/nginx/conf.d/wyl.conf added +44
| @@ -0,0 +1,44 @@ | ||
| 1 | # ---------------------------------------------------------------------- | |
| 2 | # | Config file for host | | |
| 3 | # ---------------------------------------------------------------------- | |
| 4 | server { | |
| 5 | listen [::]:443 ssl; | |
| 6 | listen 443 ssl; | |
| 7 | http2 on; | |
| 8 | ||
| 9 | server_name wyl.cleberg.net; | |
| 10 | ||
| 11 | include custom.d/tls/ssl_engine.conf; | |
| 12 | include custom.d/tls/certificate_files.conf; | |
| 13 | include custom.d/tls/policy_balanced.conf; | |
| 14 | include custom.d/basic.conf; | |
| 15 | ||
| 16 | # ---------------------------------------------------------------------- | |
| 17 | # | Custom rules & config for specific website | | |
| 18 | # ---------------------------------------------------------------------- | |
| 19 | location /authelia { | |
| 20 | include custom.d/reverse_proxy/authelia.conf; | |
| 21 | } | |
| 22 | ||
| 23 | location / { | |
| 24 | set $upstream http://192.168.0.251:8840; | |
| 25 | proxy_pass $upstream; | |
| 26 | ||
| 27 | include custom.d/reverse_proxy/authelia_request.conf; | |
| 28 | include custom.d/reverse_proxy/basic.conf; | |
| 29 | } | |
| 30 | ||
| 31 | include custom.d/security/robots_index_only.conf; | |
| 32 | # ---------------------------------------------------------------------- | |
| 33 | } | |
| 34 | ||
| 35 | # ---------------------------------------------------------------------- | |
| 36 | # | Config file for non-secure host | | |
| 37 | # ---------------------------------------------------------------------- | |
| 38 | server { | |
| 39 | listen [::]:80; | |
| 40 | listen 80; | |
| 41 | server_name wyl.cleberg.net; | |
| 42 | ||
| 43 | return 301 https://$host$request_uri; | |
| 44 | } | |
linux/nginx/etc/nginx/custom.d/basic.conf added +8
| @@ -0,0 +1,8 @@ | ||
| 1 | # Nginx Server Configs | MIT License | |
| 2 | # https://github.com/h5bp/server-configs-nginx | |
| 3 | ||
| 4 | include custom.d/security/referrer-policy.conf; | |
| 5 | include custom.d/security/x-content-type-options.conf; | |
| 6 | include custom.d/security/x-frame-options.conf; | |
| 7 | include custom.d/location/security_file_access.conf; | |
| 8 | #include custom.d/cross-origin/requests.conf; | |
linux/nginx/etc/nginx/custom.d/cross-origin/requests.conf added +18
| @@ -0,0 +1,18 @@ | ||
| 1 | # ---------------------------------------------------------------------- | |
| 2 | # | Cross-origin requests | | |
| 3 | # ---------------------------------------------------------------------- | |
| 4 | ||
| 5 | # Allow cross-origin requests. | |
| 6 | # | |
| 7 | # https://developer.mozilla.org/en-US/docs/Web/HTTP/Access_control_CORS | |
| 8 | # https://enable-cors.org/ | |
| 9 | # https://www.w3.org/TR/cors/ | |
| 10 | ||
| 11 | # (!) Do not use this without understanding the consequences. | |
| 12 | # This will permit access from any other website. | |
| 13 | # Instead of using this file, consider using a specific rule such as | |
| 14 | # allowing access based on (sub)domain: | |
| 15 | # | |
| 16 | # add_header Access-Control-Allow-Origin "subdomain.example.com"; | |
| 17 | ||
| 18 | # add_header Access-Control-Allow-Origin $cors; | |
linux/nginx/etc/nginx/custom.d/cross-origin/resource_timing.conf added +15
| @@ -0,0 +1,15 @@ | ||
| 1 | # ---------------------------------------------------------------------- | |
| 2 | # | Cross-origin resource timing | | |
| 3 | # ---------------------------------------------------------------------- | |
| 4 | ||
| 5 | # Allow cross-origin access to the timing information for all resources. | |
| 6 | # | |
| 7 | # If a resource isn't served with a `Timing-Allow-Origin` header that would | |
| 8 | # allow its timing information to be shared with the document, some of the | |
| 9 | # attributes of the `PerformanceResourceTiming` object will be set to zero. | |
| 10 | # | |
| 11 | # https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Timing-Allow-Origin | |
| 12 | # https://www.w3.org/TR/resource-timing/ | |
| 13 | # https://www.stevesouders.com/blog/2014/08/21/resource-timing-practical-tips/ | |
| 14 | ||
| 15 | # add_header Timing-Allow-Origin "*"; | |
linux/nginx/etc/nginx/custom.d/errors/custom_errors.conf added +9
| @@ -0,0 +1,9 @@ | ||
| 1 | # ---------------------------------------------------------------------- | |
| 2 | # | Custom error messages/pages | | |
| 3 | # ---------------------------------------------------------------------- | |
| 4 | ||
| 5 | # Customize what Nginx returns to the client in case of an error. | |
| 6 | # | |
| 7 | # https://nginx.org/en/docs/http/ngx_http_core_module.html#error_page | |
| 8 | ||
| 9 | # error_page 404 /404.html; | |
linux/nginx/etc/nginx/custom.d/location/security_file_access.conf added +41
| @@ -0,0 +1,41 @@ | ||
| 1 | # ---------------------------------------------------------------------- | |
| 2 | # | File access | | |
| 3 | # ---------------------------------------------------------------------- | |
| 4 | ||
| 5 | # Block access to all hidden files and directories except for the | |
| 6 | # visible content from within the `/.well-known/` hidden directory. | |
| 7 | # | |
| 8 | # These types of files usually contain user preferences or the preserved state | |
| 9 | # of a utility, and can include rather private places like, for example, the | |
| 10 | # `.git` or `.svn` directories. | |
| 11 | # | |
| 12 | # The `/.well-known/` directory represents the standard (RFC 5785) path prefix | |
| 13 | # for "well-known locations" (e.g.: `/.well-known/manifest.json`, | |
| 14 | # `/.well-known/keybase.txt`), and therefore, access to its visible content | |
| 15 | # should not be blocked. | |
| 16 | # | |
| 17 | # https://www.mnot.net/blog/2010/04/07/well-known | |
| 18 | # https://tools.ietf.org/html/rfc5785 | |
| 19 | ||
| 20 | location ~* /\.(?!well-known\/) { | |
| 21 | deny all; | |
| 22 | } | |
| 23 | ||
| 24 | # - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - | |
| 25 | ||
| 26 | # Block access to files that can expose sensitive information. | |
| 27 | # | |
| 28 | # By default, block access to backup and source files that may be left by some | |
| 29 | # text editors and can pose a security risk when anyone has access to them. | |
| 30 | # | |
| 31 | # https://feross.org/cmsploit/ | |
| 32 | # | |
| 33 | # (!) Update the `location` regular expression from below to include any files | |
| 34 | # that might end up on your production server and can expose sensitive | |
| 35 | # information about your website. These files may include: configuration | |
| 36 | # files, files that contain metadata about the project (e.g.: project | |
| 37 | # dependencies, build scripts, etc.). | |
| 38 | ||
| 39 | location ~* (?:#.*#|\.(?:bak|conf|dist|fla|in[ci]|log|orig|psd|sh|sql|sw[op])|~)$ { | |
| 40 | deny all; | |
| 41 | } | |
linux/nginx/etc/nginx/custom.d/location/web_performance_filename-based_cache_busting.conf added +14
| @@ -0,0 +1,14 @@ | ||
| 1 | # ---------------------------------------------------------------------- | |
| 2 | # | Filename-based cache busting | | |
| 3 | # ---------------------------------------------------------------------- | |
| 4 | ||
| 5 | # If you're not using a build process to manage your filename version revving, | |
| 6 | # you might want to consider enabling the following directives. | |
| 7 | # | |
| 8 | # To understand why this is important and even a better solution than using | |
| 9 | # something like `*.css?v231`, please see: | |
| 10 | # https://www.stevesouders.com/blog/2008/08/23/revving-filenames-dont-use-querystring/ | |
| 11 | ||
| 12 | location ~* (.+)\.(?:\w+)\.(avifs?|bmp|css|cur|gif|ico|jpe?g|jxl|m?js|a?png|svgz?|webp|webmanifest)$ { | |
| 13 | try_files $uri $1.$2; | |
| 14 | } | |
linux/nginx/etc/nginx/custom.d/location/web_performance_svgz-compression.conf added +18
| @@ -0,0 +1,18 @@ | ||
| 1 | # ---------------------------------------------------------------------- | |
| 2 | # | SVGZ Compression | | |
| 3 | # ---------------------------------------------------------------------- | |
| 4 | ||
| 5 | # SVGZ files are already compressed. | |
| 6 | # Disable gzip function for `.svgz` files. | |
| 7 | ||
| 8 | location ~* \.svgz$ { | |
| 9 | gzip off; | |
| 10 | add_header Content-Encoding gzip; | |
| 11 | ||
| 12 | include custom.d/security/x-content-type-options.conf; | |
| 13 | include custom.d/security/content-security-policy.conf; | |
| 14 | include custom.d/security/referrer-policy.conf; | |
| 15 | include custom.d/security/permissions-policy.conf; | |
| 16 | include custom.d/security/cross-origin-policy.conf; | |
| 17 | include custom.d/cross-origin/requests.conf; | |
| 18 | } | |
linux/nginx/etc/nginx/custom.d/media_types/character_encodings.conf added +32
| @@ -0,0 +1,32 @@ | ||
| 1 | # ---------------------------------------------------------------------- | |
| 2 | # | Character encodings | | |
| 3 | # ---------------------------------------------------------------------- | |
| 4 | ||
| 5 | # Serve all resources labeled as `text/html` or `text/plain` with the media type | |
| 6 | # `charset` parameter set to `UTF-8`. | |
| 7 | # | |
| 8 | # https://nginx.org/en/docs/http/ngx_http_charset_module.html#charset | |
| 9 | ||
| 10 | charset utf-8; | |
| 11 | ||
| 12 | # - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - | |
| 13 | ||
| 14 | # Update charset_types to match updated mime.types. | |
| 15 | # `text/html` is always included by charset module. | |
| 16 | # Default: text/html text/xml text/plain text/vnd.wap.wml application/javascript application/rss+xml | |
| 17 | # | |
| 18 | # https://nginx.org/en/docs/http/ngx_http_charset_module.html#charset_types | |
| 19 | ||
| 20 | charset_types | |
| 21 | text/css | |
| 22 | text/plain | |
| 23 | text/vnd.wap.wml | |
| 24 | text/javascript | |
| 25 | text/markdown | |
| 26 | text/calendar | |
| 27 | text/x-component | |
| 28 | text/vcard | |
| 29 | text/cache-manifest | |
| 30 | text/vtt | |
| 31 | application/json | |
| 32 | application/manifest+json; | |
linux/nginx/etc/nginx/custom.d/media_types/media_types.conf added +18
| @@ -0,0 +1,18 @@ | ||
| 1 | # ---------------------------------------------------------------------- | |
| 2 | # | Media types | | |
| 3 | # ---------------------------------------------------------------------- | |
| 4 | ||
| 5 | # Serve resources with the proper media types (f.k.a. MIME types). | |
| 6 | # | |
| 7 | # https://www.iana.org/assignments/media-types/media-types.xhtml | |
| 8 | # https://nginx.org/en/docs/http/ngx_http_core_module.html#types | |
| 9 | ||
| 10 | include mime.types; | |
| 11 | ||
| 12 | # - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - | |
| 13 | ||
| 14 | # Default: text/plain | |
| 15 | # | |
| 16 | # https://nginx.org/en/docs/http/ngx_http_core_module.html#default_type | |
| 17 | ||
| 18 | default_type application/octet-stream; | |
linux/nginx/etc/nginx/custom.d/reverse_proxy/authelia.conf added +28
| @@ -0,0 +1,28 @@ | ||
| 1 | internal; | |
| 2 | set $upstream_authelia http://127.0.0.1:9092/api/verify; #change the IP and Port to match the IP and Port of your Authelia container | |
| 3 | proxy_pass_request_body off; | |
| 4 | proxy_pass $upstream_authelia; | |
| 5 | proxy_set_header Content-Length ""; | |
| 6 | ||
| 7 | # Timeout if the real server is dead | |
| 8 | proxy_next_upstream error timeout invalid_header http_500 http_502 http_503; | |
| 9 | client_body_buffer_size 128k; | |
| 10 | proxy_set_header Host $host; | |
| 11 | proxy_set_header X-Original-URL $scheme://$http_host$request_uri; | |
| 12 | proxy_set_header X-Real-IP $remote_addr; | |
| 13 | proxy_set_header X-Forwarded-For $remote_addr; | |
| 14 | proxy_set_header X-Forwarded-Proto $scheme; | |
| 15 | proxy_set_header X-Forwarded-Host $http_host; | |
| 16 | proxy_set_header X-Forwarded-Uri $request_uri; | |
| 17 | proxy_set_header X-Forwarded-Ssl on; | |
| 18 | proxy_redirect http:// $scheme://; | |
| 19 | proxy_http_version 1.1; | |
| 20 | proxy_set_header Connection ""; | |
| 21 | proxy_cache_bypass $cookie_session; | |
| 22 | proxy_no_cache $cookie_session; | |
| 23 | proxy_buffers 4 32k; | |
| 24 | ||
| 25 | send_timeout 5m; | |
| 26 | proxy_read_timeout 240; | |
| 27 | proxy_send_timeout 240; | |
| 28 | proxy_connect_timeout 240; | |
linux/nginx/etc/nginx/custom.d/reverse_proxy/authelia_request.conf added +10
| @@ -0,0 +1,10 @@ | ||
| 1 | auth_request /authelia; | |
| 2 | auth_request_set $target_url https://$http_host$request_uri; | |
| 3 | auth_request_set $user $upstream_http_remote_user; | |
| 4 | auth_request_set $email $upstream_http_remote_email; | |
| 5 | auth_request_set $groups $upstream_http_remote_groups; | |
| 6 | proxy_set_header Remote-User $user; | |
| 7 | proxy_set_header Remote-Email $email; | |
| 8 | proxy_set_header Remote-Groups $groups; | |
| 9 | ||
| 10 | error_page 401 =302 https://auth.cleberg.net/?rd=$target_url; | |
linux/nginx/etc/nginx/custom.d/reverse_proxy/basic.conf added +16
| @@ -0,0 +1,16 @@ | ||
| 1 | proxy_set_header Host $host; | |
| 2 | proxy_set_header Upgrade $http_upgrade; | |
| 3 | proxy_set_header Connection upgrade; | |
| 4 | proxy_set_header Accept-Encoding gzip; | |
| 5 | proxy_set_header X-Real-IP $remote_addr; | |
| 6 | proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; | |
| 7 | proxy_set_header X-Forwarded-Proto $scheme; | |
| 8 | proxy_set_header X-Forwarded-Host $http_host; | |
| 9 | proxy_set_header X-Forwarded-Uri $request_uri; | |
| 10 | proxy_set_header X-Forwarded-Ssl on; | |
| 11 | proxy_redirect http:// $scheme://; | |
| 12 | proxy_http_version 1.1; | |
| 13 | proxy_set_header Connection ""; | |
| 14 | proxy_cache_bypass $cookie_session; | |
| 15 | proxy_no_cache $cookie_session; | |
| 16 | proxy_buffers 64 256k; | |
linux/nginx/etc/nginx/custom.d/security/content-security-policy.conf added +28
| @@ -0,0 +1,28 @@ | ||
| 1 | # ---------------------------------------------------------------------- | |
| 2 | # | Content Security Policy (CSP) | | |
| 3 | # ---------------------------------------------------------------------- | |
| 4 | ||
| 5 | # Mitigate the risk of cross-site scripting and other content-injection | |
| 6 | # attacks. | |
| 7 | # | |
| 8 | # This can be done by setting a Content Security Policy which permits | |
| 9 | # trusted sources of content for your website. | |
| 10 | # | |
| 11 | # There is no policy that fits all websites, you will have to modify the | |
| 12 | # `Content-Security-Policy` directives in the example depending on your needs. | |
| 13 | # | |
| 14 | # To make your CSP implementation easier, you can use an online CSP header | |
| 15 | # generator such as: | |
| 16 | # https://report-uri.com/home/generate/ | |
| 17 | # | |
| 18 | # It is encouraged that you validate your CSP header using a CSP validator | |
| 19 | # such as: | |
| 20 | # https://csp-evaluator.withgoogle.com | |
| 21 | # | |
| 22 | # https://www.w3.org/TR/CSP/ | |
| 23 | # https://owasp.org/www-project-secure-headers/#content-security-policy | |
| 24 | # https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy | |
| 25 | # https://developers.google.com/web/fundamentals/security/csp | |
| 26 | # https://content-security-policy.com/ | |
| 27 | ||
| 28 | add_header Content-Security-Policy $content_security_policy always; | |
linux/nginx/etc/nginx/custom.d/security/cross-origin-policy.conf added +44
| @@ -0,0 +1,44 @@ | ||
| 1 | # ---------------------------------------------------------------------- | |
| 2 | # | Cross Origin Policy | | |
| 3 | # ---------------------------------------------------------------------- | |
| 4 | ||
| 5 | # Set strict a Cross Origin Policy to mitigate information leakage. | |
| 6 | # | |
| 7 | # (1) Cross-Origin-Embedder-Policy prevents a document from loading any | |
| 8 | # cross-origin resources that don’t explicitly grant the document | |
| 9 | # permission. | |
| 10 | # https://html.spec.whatwg.org/multipage/origin.html#coep | |
| 11 | # https://owasp.org/www-project-secure-headers/#cross-origin-embedder-policy | |
| 12 | # https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Cross-Origin-Embedder-Policy | |
| 13 | # | |
| 14 | # (2) Cross-Origin-Opener-Policy allows you to ensure a top-level document does | |
| 15 | # not share a browsing context group with cross-origin documents. | |
| 16 | # https://html.spec.whatwg.org/multipage/origin.html#cross-origin-opener-policies | |
| 17 | # https://owasp.org/www-project-secure-headers/#cross-origin-opener-policy | |
| 18 | # https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Cross-Origin-Opener-Policy | |
| 19 | # | |
| 20 | # (3) Cross-Origin-Resource-Policy allows to define a policy that lets web | |
| 21 | # sites and applications opt in to protection against certain requests from | |
| 22 | # other origins, to mitigate speculative side-channel attacks. | |
| 23 | # https://fetch.spec.whatwg.org/#cross-origin-resource-policy-header | |
| 24 | # https://owasp.org/www-project-secure-headers/#cross-origin-resource-policy | |
| 25 | # https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Cross-Origin-Resource-Policy | |
| 26 | # https://resourcepolicy.fyi/ | |
| 27 | # | |
| 28 | # To check your Cross Origin Policy, you can use an online service, such as: | |
| 29 | # https://securityheaders.com/ | |
| 30 | # https://observatory.mozilla.org/ | |
| 31 | # | |
| 32 | # https://web.dev/coop-coep/ | |
| 33 | # https://web.dev/why-coop-coep/ | |
| 34 | # https://web.dev/cross-origin-isolation-guide/ | |
| 35 | # https://scotthelme.co.uk/coop-and-coep/ | |
| 36 | ||
| 37 | # (1) | |
| 38 | add_header Cross-Origin-Embedder-Policy $coep_policy always; | |
| 39 | ||
| 40 | # (2) | |
| 41 | add_header Cross-Origin-Opener-Policy $coop_policy always; | |
| 42 | ||
| 43 | # (3) | |
| 44 | add_header Cross-Origin-Resource-Policy $corp_policy always; | |
linux/nginx/etc/nginx/custom.d/security/permissions-policy.conf added +24
| @@ -0,0 +1,24 @@ | ||
| 1 | # ---------------------------------------------------------------------- | |
| 2 | # | Permissions Policy | | |
| 3 | # ---------------------------------------------------------------------- | |
| 4 | ||
| 5 | # Set a strict Permissions Policy to mitigate access to browser features. | |
| 6 | # | |
| 7 | # The header uses a structured syntax, and allows sites to more tightly | |
| 8 | # restrict which origins can be granted access to features. | |
| 9 | # The list of available features: | |
| 10 | # https://github.com/w3c/webappsec-permissions-policy/blob/main/features.md | |
| 11 | # | |
| 12 | # The example policy below aims to disable all features expect synchronous | |
| 13 | # `XMLHttpRequest` requests on the same origin. | |
| 14 | # | |
| 15 | # To check your Permissions Policy, you can use an online service, such as: | |
| 16 | # https://securityheaders.com/ | |
| 17 | # https://observatory.mozilla.org/ | |
| 18 | # | |
| 19 | # https://www.w3.org/TR/permissions-policy-1/ | |
| 20 | # https://owasp.org/www-project-secure-headers/#permissions-policy | |
| 21 | # https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Feature-Policy | |
| 22 | # https://scotthelme.co.uk/a-new-security-header-feature-policy/ | |
| 23 | ||
| 24 | add_header Permissions-Policy $permissions_policy always; | |
linux/nginx/etc/nginx/custom.d/security/referrer-policy.conf added +25
| @@ -0,0 +1,25 @@ | ||
| 1 | # ---------------------------------------------------------------------- | |
| 2 | # | Referrer Policy | | |
| 3 | # ---------------------------------------------------------------------- | |
| 4 | ||
| 5 | # Set a strict Referrer Policy to mitigate information leakage. | |
| 6 | # | |
| 7 | # (1) The `Referrer-Policy` header is included in responses for resources | |
| 8 | # that are able to request (or navigate to) other resources. | |
| 9 | # | |
| 10 | # This includes the commonly used resource types: | |
| 11 | # HTML, CSS, XML/SVG, PDF documents, scripts and workers. | |
| 12 | # | |
| 13 | # To prevent referrer leakage entirely, specify the `no-referrer` value | |
| 14 | # instead. Note that the effect could impact analytics metrics negatively. | |
| 15 | # | |
| 16 | # To check your Referrer Policy, you can use an online service, such as: | |
| 17 | # https://securityheaders.com/ | |
| 18 | # https://observatory.mozilla.org/ | |
| 19 | # | |
| 20 | # https://www.w3.org/TR/referrer-policy/ | |
| 21 | # https://owasp.org/www-project-secure-headers/#referrer-policy | |
| 22 | # https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Referrer-Policy | |
| 23 | # https://scotthelme.co.uk/a-new-security-header-referrer-policy/ | |
| 24 | ||
| 25 | add_header Referrer-Policy $referrer_policy always; | |
linux/nginx/etc/nginx/custom.d/security/robots.txt added +3
| @@ -0,0 +1,3 @@ | ||
| 1 | User-agent: * | |
| 2 | Disallow: / | |
| 3 | Allow: /$ | |
linux/nginx/etc/nginx/custom.d/security/robots_index_only.conf added +4
| @@ -0,0 +1,4 @@ | ||
| 1 | location = /robots.txt { | |
| 2 | default_type text/plain; | |
| 3 | alias /etc/nginx/custom.d/security/robots.txt; | |
| 4 | } | |
linux/nginx/etc/nginx/custom.d/security/server_software_information.conf added +9
| @@ -0,0 +1,9 @@ | ||
| 1 | # ---------------------------------------------------------------------- | |
| 2 | # | Server software information | | |
| 3 | # ---------------------------------------------------------------------- | |
| 4 | ||
| 5 | # Prevent Nginx from sending its version number in the "Server" response header. | |
| 6 | # | |
| 7 | # https://nginx.org/en/docs/http/ngx_http_core_module.html#server_tokens | |
| 8 | ||
| 9 | server_tokens off; | |
linux/nginx/etc/nginx/custom.d/security/strict-transport-security.conf added +38
| @@ -0,0 +1,38 @@ | ||
| 1 | # ---------------------------------------------------------------------- | |
| 2 | # | HTTP Strict Transport Security (HSTS) | | |
| 3 | # ---------------------------------------------------------------------- | |
| 4 | ||
| 5 | # Force client-side TLS (Transport Layer Security) redirection. | |
| 6 | # | |
| 7 | # If a user types `example.com` in their browser, even if the server redirects | |
| 8 | # them to the secure version of the website, that still leaves a window of | |
| 9 | # opportunity (the initial HTTP connection) for an attacker to downgrade or | |
| 10 | # redirect the request. | |
| 11 | # | |
| 12 | # The following header ensures that a browser only connects to your server | |
| 13 | # via HTTPS, regardless of what the users type in the browser's address bar. | |
| 14 | # | |
| 15 | # (!) Be aware that Strict Transport Security is not revokable and you | |
| 16 | # must ensure being able to serve the site over HTTPS for the duration | |
| 17 | # you've specified in the `max-age` directive. When you don't have a | |
| 18 | # valid TLS connection anymore (e.g. due to an expired TLS certificate) | |
| 19 | # your visitors will see a nasty error message even when attempting to | |
| 20 | # connect over HTTP. | |
| 21 | # | |
| 22 | # (1) Preloading Strict Transport Security. | |
| 23 | # To submit your site for HSTS preloading, it is required that: | |
| 24 | # * the `includeSubDomains` directive is specified | |
| 25 | # * the `preload` directive is specified | |
| 26 | # * the `max-age` is specified with a value of at least 31536000 seconds | |
| 27 | # (1 year). | |
| 28 | # https://hstspreload.org/#deployment-recommendations | |
| 29 | # | |
| 30 | # https://tools.ietf.org/html/rfc6797#section-6.1 | |
| 31 | # https://owasp.org/www-project-secure-headers/#http-strict-transport-security | |
| 32 | # https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Strict-Transport-Security | |
| 33 | # https://www.html5rocks.com/en/tutorials/security/transport-layer-security/ | |
| 34 | # https://hstspreload.org/ | |
| 35 | ||
| 36 | # add_header Strict-Transport-Security "max-age=16070400; includeSubDomains" always; | |
| 37 | # (1) Enable your site for HSTS preload inclusion. | |
| 38 | add_header Strict-Transport-Security "max-age=31536000; includeSubDomains; preload" always; | |
linux/nginx/etc/nginx/custom.d/security/x-content-type-options.conf added +17
| @@ -0,0 +1,17 @@ | ||
| 1 | # ---------------------------------------------------------------------- | |
| 2 | # | Content Type Options | | |
| 3 | # ---------------------------------------------------------------------- | |
| 4 | ||
| 5 | # Prevent some browsers from MIME-sniffing the response. | |
| 6 | # | |
| 7 | # This reduces exposure to drive-by download attacks and cross-origin data | |
| 8 | # leaks, and should be left uncommented, especially if the server is serving | |
| 9 | # user-uploaded content or content that could potentially be treated as | |
| 10 | # executable by the browser. | |
| 11 | # | |
| 12 | # https://owasp.org/www-project-secure-headers/#x-content-type-options | |
| 13 | # https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/X-Content-Type-Options | |
| 14 | # https://blogs.msdn.microsoft.com/ie/2008/07/02/ie8-security-part-v-comprehensive-protection/ | |
| 15 | # https://mimesniff.spec.whatwg.org/ | |
| 16 | ||
| 17 | add_header X-Content-Type-Options nosniff always; | |
linux/nginx/etc/nginx/custom.d/security/x-frame-options.conf added +37
| @@ -0,0 +1,37 @@ | ||
| 1 | # ---------------------------------------------------------------------- | |
| 2 | # | Frame Options | | |
| 3 | # ---------------------------------------------------------------------- | |
| 4 | ||
| 5 | # Protect website against clickjacking. | |
| 6 | # | |
| 7 | # The example below sends the `X-Frame-Options` response header with the value | |
| 8 | # `DENY`, informing browsers not to display the content of the web page in any | |
| 9 | # frame. | |
| 10 | # | |
| 11 | # This might not be the best setting for everyone. You should read about the | |
| 12 | # other two possible values the `X-Frame-Options` header field can have: | |
| 13 | # `SAMEORIGIN` and `ALLOW-FROM`. | |
| 14 | # https://tools.ietf.org/html/rfc7034#section-2.1. | |
| 15 | # | |
| 16 | # Keep in mind that while you could send the `X-Frame-Options` header for all | |
| 17 | # of your website's pages, this has the potential downside that it forbids even | |
| 18 | # non-malicious framing of your content. | |
| 19 | # | |
| 20 | # Nonetheless, you should ensure that you send the `X-Frame-Options` header for | |
| 21 | # all pages that allow a user to make a state-changing operation (e.g: pages | |
| 22 | # that contain one-click purchase links, checkout or bank-transfer confirmation | |
| 23 | # pages, pages that make permanent configuration changes, etc.). | |
| 24 | # | |
| 25 | # Sending the `X-Frame-Options` header can also protect your website against | |
| 26 | # more than just clickjacking attacks. | |
| 27 | # https://cure53.de/xfo-clickjacking.pdf. | |
| 28 | # | |
| 29 | # (!) The `Content-Security-Policy` header has a `frame-ancestors` directive | |
| 30 | # which obsoletes this header for supporting browsers. | |
| 31 | # | |
| 32 | # https://tools.ietf.org/html/rfc7034 | |
| 33 | # https://owasp.org/www-project-secure-headers/#x-frame-options | |
| 34 | # https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/X-Frame-Options | |
| 35 | # https://docs.microsoft.com/archive/blogs/ieinternals/combating-clickjacking-with-x-frame-options | |
| 36 | ||
| 37 | add_header X-Frame-Options $x_frame_options always; | |
linux/nginx/etc/nginx/custom.d/tls/certificate_files.conf added +33
| @@ -0,0 +1,33 @@ | ||
| 1 | # ---------------------------------------------------------------------- | |
| 2 | # | Certificate files | | |
| 3 | # ---------------------------------------------------------------------- | |
| 4 | ||
| 5 | # This default SSL certificate will be served whenever the client lacks support | |
| 6 | # for SNI (Server Name Indication). | |
| 7 | # | |
| 8 | # (1) Certificate and key files location | |
| 9 | # The certificate file can contain an intermediate certificate. | |
| 10 | # | |
| 11 | # https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_certificate | |
| 12 | # | |
| 13 | # (2) Intermediate certificate location if loaded certificate (1) does not | |
| 14 | # contain intermediate certificate when enabling OCSP stapling. | |
| 15 | # | |
| 16 | # https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_trusted_certificate | |
| 17 | # | |
| 18 | # (3) CA certificate file location for client certificate authentication. | |
| 19 | # | |
| 20 | # https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_client_certificate | |
| 21 | ||
| 22 | # (1) | |
| 23 | # ssl_certificate /etc/nginx/certs/default.crt; | |
| 24 | # ssl_certificate_key /etc/nginx/certs/default.key; | |
| 25 | ssl_certificate /etc/letsencrypt/live/cleberg.net/fullchain.pem; | |
| 26 | ssl_certificate_key /etc/letsencrypt/live/cleberg.net/privkey.pem; | |
| 27 | ||
| 28 | # (2) | |
| 29 | # ssl_trusted_certificate /path/to/ca.crt; | |
| 30 | ssl_trusted_certificate /etc/letsencrypt/live/cleberg.net/chain.pem; | |
| 31 | ||
| 32 | # (3) | |
| 33 | # ssl_client_certificate /etc/nginx/default_ssl.crt; | |
linux/nginx/etc/nginx/custom.d/tls/ocsp_stapling.conf added +34
| @@ -0,0 +1,34 @@ | ||
| 1 | # ---------------------------------------------------------------------- | |
| 2 | # | Online Certificate Status Protocol stapling | | |
| 3 | # ---------------------------------------------------------------------- | |
| 4 | ||
| 5 | # OCSP is a lightweight, only one record to help clients verify the validity of | |
| 6 | # the server certificate. | |
| 7 | # OCSP stapling allows the server to send its cached OCSP record during the TLS | |
| 8 | # handshake, without the need of 3rd party OCSP responder. | |
| 9 | # | |
| 10 | # https://wiki.mozilla.org/Security/Server_Side_TLS#OCSP_Stapling | |
| 11 | # https://tools.ietf.org/html/rfc6066#section-8 | |
| 12 | # https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_stapling | |
| 13 | # | |
| 14 | # (1) Use Cloudflare 1.1.1.1 DNS resolver | |
| 15 | # https://developers.cloudflare.com/1.1.1.1/setting-up-1.1.1.1/ | |
| 16 | # | |
| 17 | # (2) Use Google 8.8.8.8 DNS resolver | |
| 18 | # https://developers.google.com/speed/public-dns/docs/using | |
| 19 | # | |
| 20 | # (3) Use OpenDNS resolver | |
| 21 | # https://use.opendns.com | |
| 22 | ||
| 23 | ssl_stapling on; | |
| 24 | ssl_stapling_verify on; | |
| 25 | ||
| 26 | resolver | |
| 27 | # (1) | |
| 28 | 1.1.1.1 1.0.0.1 [2606:4700:4700::1111] [2606:4700:4700::1001] | |
| 29 | # (2) | |
| 30 | 8.8.8.8 8.8.4.4 [2001:4860:4860::8888] [2001:4860:4860::8844] | |
| 31 | # (3) | |
| 32 | # 208.67.222.222 208.67.220.220 [2620:119:35::35] [2620:119:53::53] | |
| 33 | valid=60s; | |
| 34 | resolver_timeout 2s; | |
linux/nginx/etc/nginx/custom.d/tls/policy_balanced.conf added +20
| @@ -0,0 +1,20 @@ | ||
| 1 | # ---------------------------------------------------------------------- | |
| 2 | # | SSL policy - Balanced | | |
| 3 | # ---------------------------------------------------------------------- | |
| 4 | ||
| 5 | # For services that need to support a wide range of clients, this configuration | |
| 6 | # is reasonably balanced. | |
| 7 | # | |
| 8 | # (1) The NIST curves (prime256v1, secp384r1, secp521r1) are known to be weak | |
| 9 | # and potentially vulnerable but are required to support Microsoft Edge | |
| 10 | # and Safari. | |
| 11 | # https://safecurves.cr.yp.to/ | |
| 12 | # | |
| 13 | # https://wiki.mozilla.org/Security/Server_Side_TLS#Recommended_configurations | |
| 14 | # https://nginx.org/en/docs/http/ngx_http_ssl_module.html | |
| 15 | ||
| 16 | ssl_protocols TLSv1.2; | |
| 17 | ssl_ciphers EECDH+CHACHA20:EECDH+AES; | |
| 18 | ||
| 19 | # (1) | |
| 20 | ssl_ecdh_curve X25519:prime256v1:secp521r1:secp384r1; | |
linux/nginx/etc/nginx/custom.d/tls/policy_strict.conf added +50
| @@ -0,0 +1,50 @@ | ||
| 1 | # ---------------------------------------------------------------------- | |
| 2 | # | SSL policy - Strict | | |
| 3 | # ---------------------------------------------------------------------- | |
| 4 | ||
| 5 | # For services that don't need backward compatibility, the parameters below | |
| 6 | # provide the highest level of security and performance. | |
| 7 | # | |
| 8 | # (!) This policy enforces a strong TLS configuration, which may raise | |
| 9 | # errors with old clients. | |
| 10 | # If a more compatible profile is required, use the "balanced" policy. | |
| 11 | # | |
| 12 | # (!) TLSv1.3 and its 0-RTT feature require NGINX >=1.15.4 and OpenSSL >=1.1.1 | |
| 13 | # to be installed. | |
| 14 | # | |
| 15 | # (!) Don't enable `ssl_early_data` blindly! Requests sent within early data are | |
| 16 | # subject to replay attacks. | |
| 17 | # | |
| 18 | # (1) The NIST curves (prime256v1, secp384r1, secp521r1) are known to be weak | |
| 19 | # and potentially vulnerable. | |
| 20 | # | |
| 21 | # Add them back to the parameter `ssl_ecdh_curve` below to support | |
| 22 | # Microsoft Edge and Safari. | |
| 23 | # | |
| 24 | # https://safecurves.cr.yp.to/ | |
| 25 | # | |
| 26 | # (2) Enables TLS 1.3 0-RTT, allows for faster resumption of TLS sessions. | |
| 27 | # | |
| 28 | # (!) Requests sent within early data are subject to replay attacks. | |
| 29 | # To protect against such attacks at the application layer, the | |
| 30 | # `$ssl_early_data` variable should be used: | |
| 31 | # | |
| 32 | # proxy_set_header Early-Data $ssl_early_data; | |
| 33 | # | |
| 34 | # The application should return response code 425 "Too Early" for anything | |
| 35 | # that could contain user supplied data. | |
| 36 | # | |
| 37 | # https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/425 | |
| 38 | # | |
| 39 | # https://github.com/certbot/certbot/issues/6367 | |
| 40 | # https://github.com/mozilla/server-side-tls/issues/217 | |
| 41 | # https://nginx.org/en/docs/http/ngx_http_ssl_module.html | |
| 42 | ||
| 43 | ssl_protocols TLSv1.2 TLSv1.3; | |
| 44 | ssl_ciphers EECDH+CHACHA20:EECDH+AES; | |
| 45 | ||
| 46 | # (1) | |
| 47 | ssl_ecdh_curve X25519; | |
| 48 | ||
| 49 | # (2) | |
| 50 | #ssl_early_data on; | |
linux/nginx/etc/nginx/custom.d/tls/ssl_engine.conf added +47
| @@ -0,0 +1,47 @@ | ||
| 1 | # ---------------------------------------------------------------------- | |
| 2 | # | SSL engine | | |
| 3 | # ---------------------------------------------------------------------- | |
| 4 | ||
| 5 | # (1) Optimize SSL by caching session parameters for 24 hours. | |
| 6 | # This cuts down on the number of expensive SSL handshakes. | |
| 7 | # By enabling a cache, we tell the client to re-use the already | |
| 8 | # negotiated state. | |
| 9 | # Here 10m (10 MB) in ssl_session_cache is size value (not time). | |
| 10 | # 1 MB cache can store about 4000 sessions, so we can store 40000 sessions. | |
| 11 | # | |
| 12 | # (2) Use a higher keepalive timeout to reduce the need for repeated handshakes | |
| 13 | # (!) Shouldn't be done unless you serve primarily HTTPS. | |
| 14 | # Default is 75s | |
| 15 | # | |
| 16 | # (3) SSL buffer size | |
| 17 | # Set 1400 bytes to fit in one MTU. | |
| 18 | # https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_buffer_size | |
| 19 | # | |
| 20 | # (4) Disable session tickets | |
| 21 | # Session tickets keys are not auto-rotated. Only a HUP / restart will do | |
| 22 | # so and when a restart is performed the previous key is lost, which resets | |
| 23 | # all previous sessions. | |
| 24 | # Only enable session tickets if you set up a manual rotation mechanism. | |
| 25 | # https://trac.nginx.org/nginx/changeset/1356a3b9692441e163b4e78be4e9f5a46c7479e9/nginx | |
| 26 | # https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_session_tickets | |
| 27 | # | |
| 28 | # (5) The TLS 1.2 and 1.3 ciphers in use in current policies are not considered | |
| 29 | # dangerous. This directive let the client choose the one that best fits their needs. | |
| 30 | # https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_prefer_server_ciphers | |
| 31 | # https://wiki.mozilla.org/Security/Server_Side_TLS | |
| 32 | ||
| 33 | # (1) | |
| 34 | ssl_session_timeout 24h; | |
| 35 | ssl_session_cache shared:SSL:10m; | |
| 36 | ||
| 37 | # (2) | |
| 38 | keepalive_timeout 300s; | |
| 39 | ||
| 40 | # (3) | |
| 41 | # ssl_buffer_size 1400; | |
| 42 | ||
| 43 | # (4) | |
| 44 | ssl_session_tickets off; | |
| 45 | ||
| 46 | # (5) | |
| 47 | ssl_prefer_server_ciphers off; | |
linux/nginx/etc/nginx/custom.d/web_performance/cache-control.conf added +43
| @@ -0,0 +1,43 @@ | ||
| 1 | # ---------------------------------------------------------------------- | |
| 2 | # | Cache Control | | |
| 3 | # ---------------------------------------------------------------------- | |
| 4 | ||
| 5 | # Serve resources with appropriate cache control directives. | |
| 6 | # | |
| 7 | # The `Cache-Control` header field holds directives (instructions) that control | |
| 8 | # caching in browsers and shared caches (e.g. Proxies, CDNs). | |
| 9 | # Its use targets web performances improvement by specifying the expected | |
| 10 | # client and network caches behaviors. | |
| 11 | # | |
| 12 | # The usable cache directives are listed here: | |
| 13 | # https://www.iana.org/assignments/http-cache-directives/http-cache-directives.xml | |
| 14 | # | |
| 15 | # The cache directives are documented here: | |
| 16 | # https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Cache-Control#response_directives | |
| 17 | # | |
| 18 | # (!) Enable and configure this configuration with care. | |
| 19 | # Default values should embrace conformance for static files and simple | |
| 20 | # apps, but cache control definition at backend level is highly preferred. | |
| 21 | # Incorrect directives can lead to data leaks, or can degrade performances. | |
| 22 | # | |
| 23 | # More specifically, in-depth understanding on `public` vs `private` | |
| 24 | # directives meanings is highly recommended. A resource with `public` will | |
| 25 | # be cached by shared caches like CDN, even if a user session is active. | |
| 26 | # | |
| 27 | # (*) To avoid duplication of the directive `no-cache` on `Cache-Control`, | |
| 28 | # the value is skipped here. | |
| 29 | # The directive `no-cache` is already defined by Nginx `expires` when set | |
| 30 | # to `epoch`. This ensure a correct value enforcement whenever cache | |
| 31 | # control configuration is used or not. | |
| 32 | # Cache expiration configuration `expires` is described in the file | |
| 33 | # custom.d/web_performance/cache_expiration.conf. | |
| 34 | # https://nginx.org/en/docs/http/ngx_http_headers_module.html#expires | |
| 35 | # | |
| 36 | # https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Cache-Control | |
| 37 | # https://www.rfc-editor.org/rfc/rfc9111.html | |
| 38 | # https://www.rfc-editor.org/rfc/rfc8246.html | |
| 39 | # https://www.rfc-editor.org/rfc/rfc5861.html | |
| 40 | # https://www.iana.org/assignments/http-cache-directives/http-cache-directives.xml | |
| 41 | # https://cache-tests.fyi/ | |
| 42 | ||
| 43 | add_header Cache-Control $cache_control; | |
linux/nginx/etc/nginx/custom.d/web_performance/cache-file-descriptors.conf added +34
| @@ -0,0 +1,34 @@ | ||
| 1 | # ---------------------------------------------------------------------- | |
| 2 | # | Cache file-descriptors | | |
| 3 | # ---------------------------------------------------------------------- | |
| 4 | ||
| 5 | # This tells Nginx to cache open file handles, "Not Found" errors and | |
| 6 | # metadata about files and their permissions. | |
| 7 | # | |
| 8 | # Based on these cached metadata, Nginx can immediately begin sending data when | |
| 9 | # a popular file is requested, and will also know to immediately send a 404 if a | |
| 10 | # file is missing on disk, and so on. | |
| 11 | # | |
| 12 | # (!) It also means that the server won't react immediately to changes on disk, | |
| 13 | # which may be undesirable. | |
| 14 | # As only metadata are cached, edited files may be truncated until the cache | |
| 15 | # is refreshed. | |
| 16 | # https://github.com/h5bp/server-configs-nginx/issues/203 | |
| 17 | # | |
| 18 | # In the below configuration, inactive files are released from the cache after | |
| 19 | # 20 seconds, whereas active (recently requested) files are re-validated every | |
| 20 | # 30 seconds. | |
| 21 | # Descriptors will not be cached unless they are used at least 2 times within | |
| 22 | # 20 seconds (the inactive time). | |
| 23 | # A maximum of the 1000 most recently used file descriptors can be cached at | |
| 24 | # any time. | |
| 25 | # | |
| 26 | # Production servers with stable file collections will definitely want to enable | |
| 27 | # the cache. | |
| 28 | # | |
| 29 | # https://nginx.org/en/docs/http/ngx_http_core_module.html#open_file_cache | |
| 30 | ||
| 31 | open_file_cache max=1000 inactive=20s; | |
| 32 | open_file_cache_valid 30s; | |
| 33 | open_file_cache_min_uses 2; | |
| 34 | open_file_cache_errors on; | |
linux/nginx/etc/nginx/custom.d/web_performance/cache_expiration.conf added +63
| @@ -0,0 +1,63 @@ | ||
| 1 | # ---------------------------------------------------------------------- | |
| 2 | # | Cache expiration | | |
| 3 | # ---------------------------------------------------------------------- | |
| 4 | ||
| 5 | # Serve resources with a far-future expiration date. | |
| 6 | # | |
| 7 | # (!) If you don't control versioning with filename-based cache busting, you | |
| 8 | # should consider lowering the cache times to something like one week. | |
| 9 | # | |
| 10 | # https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Cache-Control | |
| 11 | # https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Expires | |
| 12 | # https://nginx.org/en/docs/http/ngx_http_headers_module.html#expires | |
| 13 | ||
| 14 | map $sent_http_content_type $expires { | |
| 15 | # Default: Fallback | |
| 16 | default 1y; | |
| 17 | ||
| 18 | # Default: No content | |
| 19 | "" off; | |
| 20 | ||
| 21 | # Specific: Assets | |
| 22 | ~*image/svg\+xml 1y; | |
| 23 | ~*image/vnd.microsoft.icon 1w; | |
| 24 | ~*image/x-icon 1w; | |
| 25 | ||
| 26 | # Specific: Manifests | |
| 27 | ~*application/manifest\+json 1w; | |
| 28 | ~*text/cache-manifest epoch; | |
| 29 | ||
| 30 | # Specific: Data interchange | |
| 31 | ~*application/atom\+xml 1h; | |
| 32 | ~*application/rdf\+xml 1h; | |
| 33 | ~*application/rss\+xml 1h; | |
| 34 | ||
| 35 | # Specific: Documents | |
| 36 | ~*text/html epoch; | |
| 37 | ~*text/markdown epoch; | |
| 38 | ~*text/calendar epoch; | |
| 39 | ||
| 40 | # Specific: Other | |
| 41 | ~*text/x-cross-domain-policy 1w; | |
| 42 | ||
| 43 | # Generic: Data | |
| 44 | ~*json epoch; | |
| 45 | ~*xml epoch; | |
| 46 | ||
| 47 | # Generic: WebAssembly | |
| 48 | # ~*application/wasm 1y; # default | |
| 49 | ||
| 50 | # Generic: Assets | |
| 51 | # ~*application/javascript 1y; # default | |
| 52 | # ~*application/x-javascript 1y; # default | |
| 53 | # ~*text/javascript 1y; # default | |
| 54 | # ~*text/css 1y; # default | |
| 55 | ||
| 56 | # Generic: Medias | |
| 57 | # ~*audio/ 1y; # default | |
| 58 | # ~*image/ 1y; # default | |
| 59 | # ~*video/ 1y; # default | |
| 60 | # ~*font/ 1y; # default | |
| 61 | } | |
| 62 | ||
| 63 | expires $expires; | |
linux/nginx/etc/nginx/custom.d/web_performance/compression.conf added +71
| @@ -0,0 +1,71 @@ | ||
| 1 | # ---------------------------------------------------------------------- | |
| 2 | # | Compression | | |
| 3 | # ---------------------------------------------------------------------- | |
| 4 | ||
| 5 | # https://nginx.org/en/docs/http/ngx_http_gzip_module.html | |
| 6 | ||
| 7 | # Enable gzip compression. | |
| 8 | # Default: off | |
| 9 | gzip on; | |
| 10 | ||
| 11 | # Compression level (1-9). | |
| 12 | # 5 is a perfect compromise between size and CPU usage, offering about 75% | |
| 13 | # reduction for most ASCII files (almost identical to level 9). | |
| 14 | # Default: 1 | |
| 15 | gzip_comp_level 5; | |
| 16 | ||
| 17 | # Don't compress anything that's already small and unlikely to shrink much if at | |
| 18 | # all (the default is 20 bytes, which is bad as that usually leads to larger | |
| 19 | # files after gzipping). | |
| 20 | # Default: 20 | |
| 21 | gzip_min_length 256; | |
| 22 | ||
| 23 | # Compress data even for clients that are connecting to us via proxies, | |
| 24 | # identified by the "Via" header (required for CloudFront). | |
| 25 | # Default: off | |
| 26 | gzip_proxied any; | |
| 27 | ||
| 28 | # Tell proxies to cache both the gzipped and regular version of a resource | |
| 29 | # whenever the client's Accept-Encoding capabilities header varies; | |
| 30 | # Avoids the issue where a non-gzip capable client (which is extremely rare | |
| 31 | # today) would display gibberish if their proxy gave them the gzipped version. | |
| 32 | # Default: off | |
| 33 | gzip_vary on; | |
| 34 | ||
| 35 | # Compress all output labeled with one of the following MIME-types. | |
| 36 | # `text/html` is always compressed by gzip module. | |
| 37 | # Default: text/html | |
| 38 | gzip_types | |
| 39 | application/atom+xml | |
| 40 | application/geo+json | |
| 41 | application/javascript | |
| 42 | application/x-javascript | |
| 43 | application/json | |
| 44 | application/ld+json | |
| 45 | application/manifest+json | |
| 46 | application/rdf+xml | |
| 47 | application/rss+xml | |
| 48 | application/vnd.ms-fontobject | |
| 49 | application/wasm | |
| 50 | application/x-web-app-manifest+json | |
| 51 | application/xhtml+xml | |
| 52 | application/xml | |
| 53 | font/eot | |
| 54 | font/otf | |
| 55 | font/ttf | |
| 56 | image/bmp | |
| 57 | image/svg+xml | |
| 58 | image/vnd.microsoft.icon | |
| 59 | image/x-icon | |
| 60 | text/cache-manifest | |
| 61 | text/calendar | |
| 62 | text/css | |
| 63 | text/javascript | |
| 64 | text/markdown | |
| 65 | text/plain | |
| 66 | text/xml | |
| 67 | text/vcard | |
| 68 | text/vnd.rim.location.xloc | |
| 69 | text/vtt | |
| 70 | text/x-component | |
| 71 | text/x-cross-domain-policy; | |
linux/nginx/etc/nginx/custom.d/web_performance/content_transformation.conf added +30
| @@ -0,0 +1,30 @@ | ||
| 1 | # ---------------------------------------------------------------------- | |
| 2 | # | Content transformation | | |
| 3 | # ---------------------------------------------------------------------- | |
| 4 | ||
| 5 | # Prevent intermediate caches or proxies (such as those used by mobile | |
| 6 | # network providers) and browsers data-saving features from modifying | |
| 7 | # the website's content using the `no-transform` directive for | |
| 8 | # `Cache-Control` header. | |
| 9 | # | |
| 10 | # https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Cache-Control | |
| 11 | # https://tools.ietf.org/html/rfc7234#section-5.2.2.4 | |
| 12 | # | |
| 13 | # (!) Carefully consider the impact on your visitors before disabling | |
| 14 | # content transformation. These transformations are performed to | |
| 15 | # improve the experience for data- and cost-constrained users | |
| 16 | # (e.g. users on a 2G connection). | |
| 17 | # | |
| 18 | # You can test the effects of content transformation applied by | |
| 19 | # Google's Lite Mode by visiting: https://googleweblight.com/i?u=https://www.example.com | |
| 20 | # | |
| 21 | # https://support.google.com/webmasters/answer/6211428 | |
| 22 | # | |
| 23 | # (!) If you are using `ngx_pagespeed`, note that disabling this will | |
| 24 | # prevent `PageSpeed` from rewriting HTML files, and, if the | |
| 25 | # `pagespeed DisableRewriteOnNoTransform` directive isn't set to | |
| 26 | # `off`, also from rewriting other resources. | |
| 27 | # | |
| 28 | # https://developers.google.com/speed/pagespeed/module/configuration#notransform | |
| 29 | ||
| 30 | add_header Cache-Control "no-transform"; | |
linux/nginx/etc/nginx/custom.d/web_performance/pre-compressed_content_brotli.conf added +17
| @@ -0,0 +1,17 @@ | ||
| 1 | # ---------------------------------------------------------------------- | |
| 2 | # | Brotli pre-compressed content | | |
| 3 | # ---------------------------------------------------------------------- | |
| 4 | ||
| 5 | # Serve brotli compressed CSS, JS, HTML, SVG, ICS and JSON files if they exist | |
| 6 | # and if the client accepts br encoding. | |
| 7 | # | |
| 8 | # (!) To make this part relevant, you need to generate encoded files by your | |
| 9 | # own. Enabling this part will not auto-generate brotlied files. | |
| 10 | # | |
| 11 | # Note that some clients (e.g. browsers) require a secure connection to request | |
| 12 | # brotli-compressed resources. | |
| 13 | # https://www.chromestatus.com/feature/5420797577396224 | |
| 14 | # | |
| 15 | # https://github.com/eustas/ngx_brotli/#brotli_static | |
| 16 | ||
| 17 | brotli_static on; | |
linux/nginx/etc/nginx/custom.d/web_performance/pre-compressed_content_gzip.conf added +13
| @@ -0,0 +1,13 @@ | ||
| 1 | # ---------------------------------------------------------------------- | |
| 2 | # | GZip pre-compressed content | | |
| 3 | # ---------------------------------------------------------------------- | |
| 4 | ||
| 5 | # Serve gzip compressed CSS, JS, HTML, SVG, ICS, and JSON files if they exist | |
| 6 | # and if the client accepts gzip encoding. | |
| 7 | # | |
| 8 | # (!) To make this part relevant, you need to generate encoded files by your | |
| 9 | # own. Enabling this part will not auto-generate gziped files. | |
| 10 | # | |
| 11 | # https://nginx.org/en/docs/http/ngx_http_gzip_static_module.html | |
| 12 | ||
| 13 | gzip_static on; | |
linux/nginx/etc/nginx/fastcgi_params added +25
| @@ -0,0 +1,25 @@ | ||
| 1 | ||
| 2 | fastcgi_param QUERY_STRING $query_string; | |
| 3 | fastcgi_param REQUEST_METHOD $request_method; | |
| 4 | fastcgi_param CONTENT_TYPE $content_type; | |
| 5 | fastcgi_param CONTENT_LENGTH $content_length; | |
| 6 | ||
| 7 | fastcgi_param SCRIPT_NAME $fastcgi_script_name; | |
| 8 | fastcgi_param REQUEST_URI $request_uri; | |
| 9 | fastcgi_param DOCUMENT_URI $document_uri; | |
| 10 | fastcgi_param DOCUMENT_ROOT $document_root; | |
| 11 | fastcgi_param SERVER_PROTOCOL $server_protocol; | |
| 12 | fastcgi_param REQUEST_SCHEME $scheme; | |
| 13 | fastcgi_param HTTPS $https if_not_empty; | |
| 14 | ||
| 15 | fastcgi_param GATEWAY_INTERFACE CGI/1.1; | |
| 16 | fastcgi_param SERVER_SOFTWARE nginx/$nginx_version; | |
| 17 | ||
| 18 | fastcgi_param REMOTE_ADDR $remote_addr; | |
| 19 | fastcgi_param REMOTE_PORT $remote_port; | |
| 20 | fastcgi_param SERVER_ADDR $server_addr; | |
| 21 | fastcgi_param SERVER_PORT $server_port; | |
| 22 | fastcgi_param SERVER_NAME $server_name; | |
| 23 | ||
| 24 | # PHP only, required if PHP was built with --enable-force-cgi-redirect | |
| 25 | fastcgi_param REDIRECT_STATUS 200; | |
linux/nginx/etc/nginx/mime.types added +138
| @@ -0,0 +1,138 @@ | ||
| 1 | types { | |
| 2 | ||
| 3 | # Data interchange | |
| 4 | ||
| 5 | application/atom+xml atom; | |
| 6 | application/json json map topojson; | |
| 7 | application/ld+json jsonld; | |
| 8 | application/rss+xml rss; | |
| 9 | # Normalize to standard type. | |
| 10 | # https://tools.ietf.org/html/rfc7946#section-12 | |
| 11 | application/geo+json geojson; | |
| 12 | application/xml xml; | |
| 13 | # Normalize to standard type. | |
| 14 | # https://tools.ietf.org/html/rfc3870#section-2 | |
| 15 | application/rdf+xml rdf; | |
| 16 | ||
| 17 | ||
| 18 | # JavaScript | |
| 19 | ||
| 20 | # Servers should use text/javascript for JavaScript resources. | |
| 21 | # https://html.spec.whatwg.org/multipage/scripting.html#scriptingLanguages | |
| 22 | text/javascript js mjs; | |
| 23 | application/wasm wasm; | |
| 24 | ||
| 25 | # Manifest files | |
| 26 | ||
| 27 | application/manifest+json webmanifest; | |
| 28 | application/x-web-app-manifest+json webapp; | |
| 29 | text/cache-manifest appcache; | |
| 30 | ||
| 31 | ||
| 32 | # Media files | |
| 33 | ||
| 34 | audio/midi mid midi kar; | |
| 35 | audio/mp4 aac f4a f4b m4a; | |
| 36 | audio/mpeg mp3; | |
| 37 | audio/ogg oga ogg opus; | |
| 38 | audio/x-realaudio ra; | |
| 39 | audio/x-wav wav; | |
| 40 | image/apng apng; | |
| 41 | image/avif avif avifs; | |
| 42 | image/bmp bmp; | |
| 43 | image/gif gif; | |
| 44 | image/jpeg jpeg jpg; | |
| 45 | image/jxl jxl; | |
| 46 | image/jxr jxr hdp wdp; | |
| 47 | image/png png; | |
| 48 | image/svg+xml svg svgz; | |
| 49 | image/tiff tif tiff; | |
| 50 | image/vnd.wap.wbmp wbmp; | |
| 51 | image/webp webp; | |
| 52 | image/x-jng jng; | |
| 53 | video/3gpp 3gp 3gpp; | |
| 54 | video/mp4 f4p f4v m4v mp4; | |
| 55 | video/mpeg mpeg mpg; | |
| 56 | video/ogg ogv; | |
| 57 | video/quicktime mov; | |
| 58 | video/webm webm; | |
| 59 | video/x-flv flv; | |
| 60 | video/x-mng mng; | |
| 61 | video/x-ms-asf asf asx; | |
| 62 | video/x-msvideo avi; | |
| 63 | ||
| 64 | # Serving `.ico` image files with a different media type | |
| 65 | # prevents Internet Explorer from displaying then as images: | |
| 66 | # https://github.com/h5bp/html5-boilerplate/commit/37b5fec090d00f38de64b591bcddcb205aadf8ee | |
| 67 | ||
| 68 | image/x-icon cur ico; | |
| 69 | ||
| 70 | ||
| 71 | # Microsoft Office | |
| 72 | ||
| 73 | application/msword doc; | |
| 74 | application/vnd.ms-excel xls; | |
| 75 | application/vnd.ms-powerpoint ppt; | |
| 76 | application/vnd.openxmlformats-officedocument.wordprocessingml.document docx; | |
| 77 | application/vnd.openxmlformats-officedocument.spreadsheetml.sheet xlsx; | |
| 78 | application/vnd.openxmlformats-officedocument.presentationml.presentation pptx; | |
| 79 | ||
| 80 | ||
| 81 | # Web fonts | |
| 82 | ||
| 83 | font/woff woff; | |
| 84 | font/woff2 woff2; | |
| 85 | application/vnd.ms-fontobject eot; | |
| 86 | font/ttf ttf; | |
| 87 | font/collection ttc; | |
| 88 | font/otf otf; | |
| 89 | ||
| 90 | ||
| 91 | # Other | |
| 92 | ||
| 93 | application/java-archive ear jar war; | |
| 94 | application/mac-binhex40 hqx; | |
| 95 | application/octet-stream bin deb dll dmg exe img iso msi msm msp safariextz; | |
| 96 | application/pdf pdf; | |
| 97 | application/postscript ai eps ps; | |
| 98 | application/rtf rtf; | |
| 99 | application/vnd.google-earth.kml+xml kml; | |
| 100 | application/vnd.google-earth.kmz kmz; | |
| 101 | application/vnd.wap.wmlc wmlc; | |
| 102 | application/x-7z-compressed 7z; | |
| 103 | application/x-bb-appworld bbaw; | |
| 104 | application/x-bittorrent torrent; | |
| 105 | application/x-chrome-extension crx; | |
| 106 | application/x-cocoa cco; | |
| 107 | application/x-java-archive-diff jardiff; | |
| 108 | application/x-java-jnlp-file jnlp; | |
| 109 | application/x-makeself run; | |
| 110 | application/x-opera-extension oex; | |
| 111 | application/x-perl pl pm; | |
| 112 | application/x-pilot pdb prc; | |
| 113 | application/x-rar-compressed rar; | |
| 114 | application/x-redhat-package-manager rpm; | |
| 115 | application/x-sea sea; | |
| 116 | application/x-shockwave-flash swf; | |
| 117 | application/x-stuffit sit; | |
| 118 | application/x-tcl tcl tk; | |
| 119 | application/x-x509-ca-cert crt der pem; | |
| 120 | application/x-xpinstall xpi; | |
| 121 | application/xhtml+xml xhtml; | |
| 122 | application/xslt+xml xsl; | |
| 123 | application/zip zip; | |
| 124 | text/calendar ics; | |
| 125 | text/css css; | |
| 126 | text/csv csv; | |
| 127 | text/html htm html shtml; | |
| 128 | text/markdown md markdown; | |
| 129 | text/mathml mml; | |
| 130 | text/plain txt; | |
| 131 | text/vcard vcard vcf; | |
| 132 | text/vnd.rim.location.xloc xloc; | |
| 133 | text/vnd.sun.j2me.app-descriptor jad; | |
| 134 | text/vnd.wap.wml wml; | |
| 135 | text/vtt vtt; | |
| 136 | text/x-component htc; | |
| 137 | ||
| 138 | } | |
linux/nginx/etc/nginx/nginx.conf added +198
| @@ -0,0 +1,198 @@ | ||
| 1 | # Configuration File - Nginx Server Configs | |
| 2 | # https://nginx.org/en/docs/ | |
| 3 | ||
| 4 | # Run as a unique, less privileged user for security reasons. | |
| 5 | # Default: nobody nobody | |
| 6 | # https://nginx.org/en/docs/ngx_core_module.html#user | |
| 7 | # https://en.wikipedia.org/wiki/Principle_of_least_privilege | |
| 8 | # user www-data; | |
| 9 | user nginx; | |
| 10 | ||
| 11 | # Sets the worker threads to the number of CPU cores available in the system for | |
| 12 | # best performance. Should be > the number of CPU cores. | |
| 13 | # Maximum number of connections = worker_processes * worker_connections | |
| 14 | # Default: 1 | |
| 15 | # https://nginx.org/en/docs/ngx_core_module.html#worker_processes | |
| 16 | worker_processes auto; | |
| 17 | ||
| 18 | # Maximum number of open files per worker process. | |
| 19 | # Should be > worker_connections. | |
| 20 | # Default: no limit | |
| 21 | # https://nginx.org/en/docs/ngx_core_module.html#worker_rlimit_nofile | |
| 22 | worker_rlimit_nofile 8192; | |
| 23 | ||
| 24 | # Provides the configuration file context in which the directives that affect | |
| 25 | # connection processing are specified. | |
| 26 | # https://nginx.org/en/docs/ngx_core_module.html#events | |
| 27 | events { | |
| 28 | ||
| 29 | # If you need more connections than this, you start optimizing your OS. | |
| 30 | # That's probably the point at which you hire people who are smarter than you | |
| 31 | # as this is *a lot* of requests. | |
| 32 | # Should be < worker_rlimit_nofile. | |
| 33 | # Default: 512 | |
| 34 | # https://nginx.org/en/docs/ngx_core_module.html#worker_connections | |
| 35 | worker_connections 8000; | |
| 36 | ||
| 37 | } | |
| 38 | ||
| 39 | # Log errors and warnings to this file | |
| 40 | # This is only used when you don't override it on a `server` level | |
| 41 | # Default: logs/error.log error | |
| 42 | # https://nginx.org/en/docs/ngx_core_module.html#error_log | |
| 43 | # error_log /var/log/nginx/error.log warn; | |
| 44 | error_log /dev/null emerg; | |
| 45 | ||
| 46 | # The file storing the process ID of the main process | |
| 47 | # Default: logs/nginx.pid | |
| 48 | # https://nginx.org/en/docs/ngx_core_module.html#pid | |
| 49 | pid /var/run/nginx.pid; | |
| 50 | ||
| 51 | # Include files in the custom.d folder. | |
| 52 | # Custom configuration and value files should be placed in the custom.d | |
| 53 | # folder. | |
| 54 | # The configurations should be disabled by prefixing files with a dot. | |
| 55 | # include custom.d/*.conf; | |
| 56 | ||
| 57 | http { | |
| 58 | ||
| 59 | # Hide Nginx version information. | |
| 60 | include custom.d/security/server_software_information.conf; | |
| 61 | ||
| 62 | # Specify media (MIME) types for files. | |
| 63 | include custom.d/media_types/media_types.conf; | |
| 64 | ||
| 65 | # Set character encodings. | |
| 66 | include custom.d/media_types/character_encodings.conf; | |
| 67 | ||
| 68 | # Include $http_x_forwarded_for within default format used in log files | |
| 69 | # https://nginx.org/en/docs/http/ngx_http_log_module.html#log_format | |
| 70 | log_format main '$remote_addr - $remote_user [$time_local] "$request" ' | |
| 71 | '$status $body_bytes_sent "$http_referer" ' | |
| 72 | '"$http_user_agent" "$http_x_forwarded_for" "$host"'; | |
| 73 | ||
| 74 | # Log access to this file | |
| 75 | # This is only used when you don't override it on a `server` level | |
| 76 | # Default: logs/access.log combined | |
| 77 | # https://nginx.org/en/docs/http/ngx_http_log_module.html#access_log | |
| 78 | # access_log /var/log/nginx/access.log main; | |
| 79 | access_log off; | |
| 80 | ||
| 81 | # How long to allow each connection to stay idle. | |
| 82 | # Longer values are better for each individual client, particularly for SSL, | |
| 83 | # but means that worker connections are tied up longer. | |
| 84 | # Default: 75s | |
| 85 | # https://nginx.org/en/docs/http/ngx_http_core_module.html#keepalive_timeout | |
| 86 | # keepalive_timeout 20s; | |
| 87 | keepalive_timeout 75s; | |
| 88 | ||
| 89 | # Speed up file transfers by using `sendfile()` to copy directly between | |
| 90 | # descriptors rather than using `read()`/`write()``. | |
| 91 | # For performance reasons, on FreeBSD systems w/ ZFS this option should be | |
| 92 | # disabled as ZFS's ARC caches frequently used files in RAM by default. | |
| 93 | # Default: off | |
| 94 | # https://nginx.org/en/docs/http/ngx_http_core_module.html#sendfile | |
| 95 | sendfile on; | |
| 96 | ||
| 97 | # Don't send out partial frames; this increases throughput since TCP frames | |
| 98 | # are filled up before being sent out. | |
| 99 | # Default: off | |
| 100 | # https://nginx.org/en/docs/http/ngx_http_core_module.html#tcp_nopush | |
| 101 | tcp_nopush on; | |
| 102 | ||
| 103 | # Enable gzip compression. | |
| 104 | include custom.d/web_performance/compression.conf; | |
| 105 | ||
| 106 | # Specify file cache expiration. | |
| 107 | include custom.d/web_performance/cache_expiration.conf; | |
| 108 | ||
| 109 | # Add Cache-Control. | |
| 110 | # custom.d/web_performance/cache-control.conf | |
| 111 | map $sent_http_content_type $cache_control { | |
| 112 | default "public, immutable, stale-while-revalidate"; | |
| 113 | ||
| 114 | # No content | |
| 115 | "" "no-store"; | |
| 116 | ||
| 117 | # Manifest files | |
| 118 | ~*application/manifest\+json "public"; | |
| 119 | ~*text/cache-manifest ""; # `no-cache` (*) | |
| 120 | ||
| 121 | # Assets | |
| 122 | ~*image/svg\+xml "public, immutable, stale-while-revalidate"; | |
| 123 | ||
| 124 | # Data interchange | |
| 125 | ~*application/(atom|rdf|rss)\+xml "public, stale-while-revalidate"; | |
| 126 | ||
| 127 | # Documents | |
| 128 | ~*text/html "private, must-revalidate"; | |
| 129 | ~*text/markdown "private, must-revalidate"; | |
| 130 | ~*text/calendar "private, must-revalidate"; | |
| 131 | ||
| 132 | # Data | |
| 133 | ~*json ""; # `no-cache` (*) | |
| 134 | ~*xml ""; # `no-cache` (*) | |
| 135 | } | |
| 136 | ||
| 137 | # Add X-Frame-Options for HTML documents. | |
| 138 | # custom.d/security/x-frame-options.conf | |
| 139 | map $sent_http_content_type $x_frame_options { | |
| 140 | ~*text/html DENY; | |
| 141 | } | |
| 142 | ||
| 143 | # Add Content-Security-Policy for HTML documents. | |
| 144 | # custom.d/security/content-security-policy.conf | |
| 145 | map $sent_http_content_type $content_security_policy { | |
| 146 | ~*text/(html|javascript)|application/pdf|xml "default-src 'self'; base-uri 'none'; form-action 'self'; frame-ancestors 'none'; object-src 'none'; upgrade-insecure-requests"; | |
| 147 | } | |
| 148 | ||
| 149 | # Add Permissions-Policy for HTML documents. | |
| 150 | # custom.d/security/permissions-policy.conf | |
| 151 | map $sent_http_content_type $permissions_policy { | |
| 152 | ~*text/(html|javascript)|application/pdf|xml "accelerometer=(),autoplay=(),browsing-topics=(),camera=(),display-capture=(),document-domain=(),encrypted-media=(),fullscreen=(),geolocation=(),gyroscope=(),magnetometer=(),microphone=(),midi=(),payment=(),picture-in-picture=(),publickey-credentials-get=(),screen-wake-lock=(),sync-xhr=(self),usb=(),web-share=(),xr-spatial-tracking=()"; | |
| 153 | } | |
| 154 | ||
| 155 | # Add Referrer-Policy for HTML documents. | |
| 156 | # custom.d/security/referrer-policy.conf | |
| 157 | map $sent_http_content_type $referrer_policy { | |
| 158 | ~*text/(css|html|javascript)|application\/pdf|xml "strict-origin-when-cross-origin"; | |
| 159 | } | |
| 160 | ||
| 161 | # Add Cross-Origin-Policies for HTML documents. | |
| 162 | # custom.d/security/cross-origin-policy.conf | |
| 163 | # Cross-Origin-Embedder-Policy | |
| 164 | map $sent_http_content_type $coep_policy { | |
| 165 | ~*text/(html|javascript)|application/pdf|xml "require-corp"; | |
| 166 | } | |
| 167 | # Cross-Origin-Opener-Policy | |
| 168 | map $sent_http_content_type $coop_policy { | |
| 169 | ~*text/(html|javascript)|application/pdf|xml "same-origin"; | |
| 170 | } | |
| 171 | # Cross-Origin-Resource-Policy | |
| 172 | map $sent_http_content_type $corp_policy { | |
| 173 | ~*text/(html|javascript)|application/pdf|xml "same-origin"; | |
| 174 | } | |
| 175 | ||
| 176 | # Add Access-Control-Allow-Origin. | |
| 177 | # custom.d/cross-origin/requests.conf | |
| 178 | map $sent_http_content_type $cors { | |
| 179 | # Images | |
| 180 | ~*image/ "*"; | |
| 181 | ||
| 182 | # Web fonts | |
| 183 | ~*font/ "*"; | |
| 184 | ~*application/vnd.ms-fontobject "*"; | |
| 185 | ~*application/x-font-ttf "*"; | |
| 186 | ~*application/font-woff "*"; | |
| 187 | ~*application/x-font-woff "*"; | |
| 188 | ~*application/font-woff2 "*"; | |
| 189 | } | |
| 190 | ||
| 191 | # Fix for onion links | |
| 192 | server_names_hash_bucket_size 128; | |
| 193 | ||
| 194 | # Include files in the conf.d folder. | |
| 195 | # `server` configuration files should be placed in the conf.d folder. | |
| 196 | # The configurations should be disabled by prefixing files with a dot. | |
| 197 | include conf.d/*.conf; | |
| 198 | } | |
linux/nginx/etc/nginx/scgi_params added +17
| @@ -0,0 +1,17 @@ | ||
| 1 | ||
| 2 | scgi_param REQUEST_METHOD $request_method; | |
| 3 | scgi_param REQUEST_URI $request_uri; | |
| 4 | scgi_param QUERY_STRING $query_string; | |
| 5 | scgi_param CONTENT_TYPE $content_type; | |
| 6 | ||
| 7 | scgi_param DOCUMENT_URI $document_uri; | |
| 8 | scgi_param DOCUMENT_ROOT $document_root; | |
| 9 | scgi_param SCGI 1; | |
| 10 | scgi_param SERVER_PROTOCOL $server_protocol; | |
| 11 | scgi_param REQUEST_SCHEME $scheme; | |
| 12 | scgi_param HTTPS $https if_not_empty; | |
| 13 | ||
| 14 | scgi_param REMOTE_ADDR $remote_addr; | |
| 15 | scgi_param REMOTE_PORT $remote_port; | |
| 16 | scgi_param SERVER_PORT $server_port; | |
| 17 | scgi_param SERVER_NAME $server_name; | |
linux/nginx/etc/nginx/uwsgi_params added +17
| @@ -0,0 +1,17 @@ | ||
| 1 | ||
| 2 | uwsgi_param QUERY_STRING $query_string; | |
| 3 | uwsgi_param REQUEST_METHOD $request_method; | |
| 4 | uwsgi_param CONTENT_TYPE $content_type; | |
| 5 | uwsgi_param CONTENT_LENGTH $content_length; | |
| 6 | ||
| 7 | uwsgi_param REQUEST_URI $request_uri; | |
| 8 | uwsgi_param PATH_INFO $document_uri; | |
| 9 | uwsgi_param DOCUMENT_ROOT $document_root; | |
| 10 | uwsgi_param SERVER_PROTOCOL $server_protocol; | |
| 11 | uwsgi_param REQUEST_SCHEME $scheme; | |
| 12 | uwsgi_param HTTPS $https if_not_empty; | |
| 13 | ||
| 14 | uwsgi_param REMOTE_ADDR $remote_addr; | |
| 15 | uwsgi_param REMOTE_PORT $remote_port; | |
| 16 | uwsgi_param SERVER_PORT $server_port; | |
| 17 | uwsgi_param SERVER_NAME $server_name; | |