Commit e443347380
Verified · cmc
Layout: unified · split
linux/nginx/etc/nginx/conf.d/1kb.conf +2 −2
| @@ -1,5 +1,5 @@ | ||
| 1 | 1 | server { |
| 2 | listen 443; | |
| 2 | listen 443 ssl; | |
| 3 | 3 | http2 on; |
| 4 | 4 | server_name 1kb.zerolabs.sh; |
| 5 | 5 | |
| @@ -19,7 +19,7 @@ server { | ||
| 19 | 19 | charset off; |
| 20 | 20 | |
| 21 | 21 | include custom.d/tls/ssl_engine.conf; |
| 22 | include custom.d/tls/certificate_files.conf; | |
| 22 | include custom.d/tls/certificate_files_zerolabs_sh.conf; | |
| 23 | 23 | |
| 24 | 24 | location = / { |
| 25 | 25 | try_files /index.html =404; |
linux/nginx/etc/nginx/conf.d/ao.conf +2 −3
| @@ -9,12 +9,11 @@ server { | ||
| 9 | 9 | |
| 10 | 10 | add_header Onion-Location "http://7lyqrn4ofxdq7lfporviu44zpc42wooh2bqazfhvpscgwby2vcwldzad.onion$request_uri" always; |
| 11 | 11 | include custom.d/tls/ssl_engine.conf; |
| 12 | include custom.d/tls/certificate_files.conf; | |
| 12 | include custom.d/tls/certificate_files_cleberg_net.conf; | |
| 13 | 13 | include custom.d/tls/policy_strict.conf; |
| 14 | 14 | include custom.d/basic.conf; |
| 15 | 15 | location / { |
| 16 | set $upstream http://127.0.0.1:9380; | |
| 17 | proxy_pass $upstream; | |
| 16 | proxy_pass $backend_address; | |
| 18 | 17 | include custom.d/reverse_proxy/basic.conf; |
| 19 | 18 | } |
| 20 | 19 | include custom.d/security/robots_index_only.conf; |
linux/nginx/etc/nginx/conf.d/art.conf +2 −3
| @@ -9,12 +9,11 @@ server { | ||
| 9 | 9 | } |
| 10 | 10 | |
| 11 | 11 | include custom.d/tls/ssl_engine.conf; |
| 12 | include custom.d/tls/certificate_files.conf; | |
| 12 | include custom.d/tls/certificate_files_cleberg_net.conf; | |
| 13 | 13 | include custom.d/tls/policy_strict.conf; |
| 14 | 14 | include custom.d/basic.conf; |
| 15 | 15 | location / { |
| 16 | set $upstream http://127.0.0.1:3003; | |
| 17 | proxy_pass $upstream; | |
| 16 | proxy_pass $backend_address; | |
| 18 | 17 | include custom.d/reverse_proxy/basic.conf; |
| 19 | 18 | } |
| 20 | 19 | include custom.d/security/robots_index_only.conf; |
linux/nginx/etc/nginx/conf.d/auth.conf +3 −4
| @@ -3,15 +3,14 @@ server { | ||
| 3 | 3 | http2 on; |
| 4 | 4 | server_name auth.zerolabs.sh; |
| 5 | 5 | include custom.d/tls/ssl_engine.conf; |
| 6 | include custom.d/tls/certificate_files.conf; | |
| 6 | include custom.d/tls/certificate_files_cleberg_net.conf; | |
| 7 | 7 | include custom.d/tls/policy_strict.conf; |
| 8 | 8 | include custom.d/basic.conf; |
| 9 | set $upstream http://127.0.0.1:9092; | |
| 10 | 9 | location / { |
| 11 | proxy_pass $upstream; | |
| 10 | proxy_pass $backend_address; | |
| 12 | 11 | include custom.d/reverse_proxy/basic.conf; |
| 13 | 12 | } |
| 14 | location /api/verify { proxy_pass $upstream; } | |
| 13 | location /api/verify { proxy_pass $backend_address; } | |
| 15 | 14 | } |
| 16 | 15 | |
| 17 | 16 | server { |
linux/nginx/etc/nginx/conf.d/br.conf +3 −4
| @@ -4,12 +4,11 @@ server { | ||
| 4 | 4 | server_name br.zerolabs.sh pkft6saqbmn6he5g626fphvlijmkdf4rzckjw6r57zsmuqm4ukd6i5ad.onion; |
| 5 | 5 | add_header Onion-Location "http://pkft6saqbmn6he5g626fphvlijmkdf4rzckjw6r57zsmuqm4ukd6i5ad.onion$request_uri" always; |
| 6 | 6 | include custom.d/tls/ssl_engine.conf; |
| 7 | include custom.d/tls/certificate_files.conf; | |
| 7 | include custom.d/tls/certificate_files_cleberg_net.conf; | |
| 8 | 8 | include custom.d/tls/policy_strict.conf; |
| 9 | 9 | include custom.d/basic.conf; |
| 10 | 10 | location / { |
| 11 | set $upstream http://127.0.0.1:3030; | |
| 12 | proxy_pass $upstream; | |
| 11 | proxy_pass $backend_address; | |
| 13 | 12 | include custom.d/reverse_proxy/basic.conf; |
| 14 | 13 | } |
| 15 | 14 | include custom.d/security/robots_index_only.conf; |
| @@ -33,7 +32,7 @@ server { | ||
| 33 | 32 | server_name br.cleberg.net; |
| 34 | 33 | |
| 35 | 34 | include custom.d/tls/ssl_engine.conf; |
| 36 | include custom.d/tls/certificate_files.conf; | |
| 35 | include custom.d/tls/certificate_files_cleberg_net.conf; | |
| 37 | 36 | include custom.d/tls/policy_strict.conf; |
| 38 | 37 | |
| 39 | 38 | return 301 https://br.zerolabs.sh$request_uri; |
linux/nginx/etc/nginx/conf.d/bt.conf +3 −3
| @@ -4,7 +4,7 @@ server { | ||
| 4 | 4 | server_name bt.zerolabs.sh; |
| 5 | 5 | |
| 6 | 6 | include custom.d/tls/ssl_engine.conf; |
| 7 | include custom.d/tls/certificate_files.conf; | |
| 7 | include custom.d/tls/certificate_files_cleberg_net.conf; | |
| 8 | 8 | include custom.d/tls/policy_strict.conf; |
| 9 | 9 | include custom.d/basic.conf; |
| 10 | 10 | |
| @@ -30,7 +30,7 @@ server { | ||
| 30 | 30 | proxy_set_header X-Forwarded-Server $host; |
| 31 | 31 | |
| 32 | 32 | proxy_pass_header X-Transmission-Session-Id; |
| 33 | proxy_pass http://127.0.0.1:9091; | |
| 33 | proxy_pass $backend_address; | |
| 34 | 34 | } |
| 35 | 35 | } |
| 36 | 36 | |
| @@ -52,7 +52,7 @@ server { | ||
| 52 | 52 | server_name bt.cleberg.net; |
| 53 | 53 | |
| 54 | 54 | include custom.d/tls/ssl_engine.conf; |
| 55 | include custom.d/tls/certificate_files.conf; | |
| 55 | include custom.d/tls/certificate_files_cleberg_net.conf; | |
| 56 | 56 | include custom.d/tls/policy_strict.conf; |
| 57 | 57 | |
| 58 | 58 | return 301 https://bt.zerolabs.sh$request_uri; |
linux/nginx/etc/nginx/conf.d/bw.conf +3 −4
| @@ -4,12 +4,11 @@ server { | ||
| 4 | 4 | server_name bw.zerolabs.sh z7kc27ceokwgddrcspxx4eb7b6xqmtjj26nohg3wgt6hsnnlfmk4apqd.onion; |
| 5 | 5 | add_header Onion-Location "http://z7kc27ceokwgddrcspxx4eb7b6xqmtjj26nohg3wgt6hsnnlfmk4apqd.onion$request_uri" always; |
| 6 | 6 | include custom.d/tls/ssl_engine.conf; |
| 7 | include custom.d/tls/certificate_files.conf; | |
| 7 | include custom.d/tls/certificate_files_cleberg_net.conf; | |
| 8 | 8 | include custom.d/tls/policy_strict.conf; |
| 9 | 9 | include custom.d/basic.conf; |
| 10 | 10 | location / { |
| 11 | set $upstream http://127.0.0.1:10416; | |
| 12 | proxy_pass $upstream; | |
| 11 | proxy_pass $backend_address; | |
| 13 | 12 | include custom.d/reverse_proxy/basic.conf; |
| 14 | 13 | } |
| 15 | 14 | include custom.d/security/robots_index_only.conf; |
| @@ -33,7 +32,7 @@ server { | ||
| 33 | 32 | server_name bw.cleberg.net; |
| 34 | 33 | |
| 35 | 34 | include custom.d/tls/ssl_engine.conf; |
| 36 | include custom.d/tls/certificate_files.conf; | |
| 35 | include custom.d/tls/certificate_files_cleberg_net.conf; | |
| 37 | 36 | include custom.d/tls/policy_strict.conf; |
| 38 | 37 | |
| 39 | 38 | return 301 https://bw.zerolabs.sh$request_uri; |
linux/nginx/etc/nginx/conf.d/cc.conf +3 −4
| @@ -4,12 +4,11 @@ server { | ||
| 4 | 4 | server_name cc.zerolabs.sh gipsohqqcehn4n6smyg5j5aap7ln6lwugyjm2lxyx4vfiwayjhpnodyd.onion; |
| 5 | 5 | add_header Onion-Location "http://gipsohqqcehn4n6smyg5j5aap7ln6lwugyjm2lxyx4vfiwayjhpnodyd.onion$request_uri" always; |
| 6 | 6 | include custom.d/tls/ssl_engine.conf; |
| 7 | include custom.d/tls/certificate_files.conf; | |
| 7 | include custom.d/tls/certificate_files_cleberg_net.conf; | |
| 8 | 8 | include custom.d/tls/policy_strict.conf; |
| 9 | 9 | include custom.d/basic.conf; |
| 10 | 10 | location / { |
| 11 | set $upstream http://127.0.0.1:8111; | |
| 12 | proxy_pass $upstream; | |
| 11 | proxy_pass $backend_address; | |
| 13 | 12 | include custom.d/reverse_proxy/basic.conf; |
| 14 | 13 | } |
| 15 | 14 | include custom.d/security/robots_index_only.conf; |
| @@ -33,7 +32,7 @@ server { | ||
| 33 | 32 | server_name cc.cleberg.net; |
| 34 | 33 | |
| 35 | 34 | include custom.d/tls/ssl_engine.conf; |
| 36 | include custom.d/tls/certificate_files.conf; | |
| 35 | include custom.d/tls/certificate_files_cleberg_net.conf; | |
| 37 | 36 | include custom.d/tls/policy_strict.conf; |
| 38 | 37 | |
| 39 | 38 | return 301 https://cc.zerolabs.sh$request_uri; |
linux/nginx/etc/nginx/conf.d/cleberg.dev.conf +2 −6
| @@ -4,9 +4,7 @@ server { | ||
| 4 | 4 | server_name www.cleberg.dev; |
| 5 | 5 | include custom.d/tls/ssl_engine.conf; |
| 6 | 6 | include custom.d/tls/policy_strict.conf; |
| 7 | ssl_certificate /etc/letsencrypt/live/cleberg.dev/fullchain.pem; | |
| 8 | ssl_certificate_key /etc/letsencrypt/live/cleberg.dev/privkey.pem; | |
| 9 | ssl_trusted_certificate /etc/letsencrypt/live/cleberg.dev/chain.pem; | |
| 7 | include custom.d/tls/certificate_files_cleberg_dev.conf; | |
| 10 | 8 | return 301 $scheme://cleberg.dev$request_uri; |
| 11 | 9 | } |
| 12 | 10 | |
| @@ -18,10 +16,8 @@ server { | ||
| 18 | 16 | root /var/www/cleberg.dev/; |
| 19 | 17 | include custom.d/tls/ssl_engine.conf; |
| 20 | 18 | include custom.d/tls/policy_strict.conf; |
| 19 | include custom.d/tls/certificate_files_cleberg_dev.conf; | |
| 21 | 20 | include custom.d/basic.conf; |
| 22 | ssl_certificate /etc/letsencrypt/live/cleberg.dev/fullchain.pem; | |
| 23 | ssl_certificate_key /etc/letsencrypt/live/cleberg.dev/privkey.pem; | |
| 24 | ssl_trusted_certificate /etc/letsencrypt/live/cleberg.dev/chain.pem; | |
| 25 | 21 | location / { try_files $uri $uri/ =404; } |
| 26 | 22 | } |
| 27 | 23 | |
linux/nginx/etc/nginx/conf.d/cleberg.io.conf +1 −3
| @@ -4,10 +4,8 @@ server { | ||
| 4 | 4 | server_name cleberg.io; |
| 5 | 5 | include custom.d/tls/ssl_engine.conf; |
| 6 | 6 | include custom.d/tls/policy_strict.conf; |
| 7 | include custom.d/tls/certificate_files_cleberg_io.conf; | |
| 7 | 8 | include custom.d/basic.conf; |
| 8 | ssl_certificate /etc/letsencrypt/live/cleberg.io/fullchain.pem; | |
| 9 | ssl_certificate_key /etc/letsencrypt/live/cleberg.io/privkey.pem; | |
| 10 | ssl_trusted_certificate /etc/letsencrypt/live/cleberg.io/chain.pem; | |
| 11 | 9 | return 301 https://cleberg.net; |
| 12 | 10 | } |
| 13 | 11 | |
linux/nginx/etc/nginx/conf.d/cleberg.net.conf +4 −56
| @@ -3,7 +3,7 @@ server { | ||
| 3 | 3 | http2 on; |
| 4 | 4 | server_name cleberg.net; |
| 5 | 5 | include custom.d/tls/ssl_engine.conf; |
| 6 | include custom.d/tls/certificate_files.conf; | |
| 6 | include custom.d/tls/certificate_files_cleberg_net.conf; | |
| 7 | 7 | include custom.d/tls/policy_strict.conf; |
| 8 | 8 | include custom.d/basic.conf; |
| 9 | 9 | include custom.d/security/strict-transport-security.conf; |
| @@ -13,33 +13,7 @@ server { | ||
| 13 | 13 | |
| 14 | 14 | add_header Onion-Location "http://paske4urhs6nttrtlkuwa5cowum3fjkc6yv6kl4ncx3mjxcd77764nqd.onion$request_uri" always; |
| 15 | 15 | |
| 16 | location /org/ { | |
| 17 | internal; | |
| 18 | alias /var/www/cleberg.net/org/; | |
| 19 | default_type text/plain; | |
| 20 | add_header Content-Type "text/plain; charset=utf-8"; | |
| 21 | } | |
| 22 | ||
| 23 | location / { | |
| 24 | try_files $uri $uri/ =404; | |
| 25 | } | |
| 26 | ||
| 27 | location /blog/ { | |
| 28 | rewrite ^/blog/((?!index)[^/]+)/(.*)$ /blog/$1.html permanent; | |
| 29 | if ($http_accept ~* "text/markdown") { | |
| 30 | rewrite ^/blog/([^/]+)\.html$ /org/blog/$1.org last; | |
| 31 | } | |
| 32 | } | |
| 33 | ||
| 34 | location ~ ^/([^/]+)\.html$ { | |
| 35 | if ($http_accept ~* "text/markdown") { | |
| 36 | rewrite ^/([^/]+)\.html$ /org/$1.org last; | |
| 37 | } | |
| 38 | try_files $uri =404; | |
| 39 | } | |
| 40 | ||
| 41 | location /atom.xml { return 301 $scheme://$host/feed.xml; } | |
| 42 | location /blog/salary-transparency.html { return 301 $scheme://$host/salary/; } | |
| 16 | include custom.d/sites/cleberg_net_static_locations.conf; | |
| 43 | 17 | } |
| 44 | 18 | |
| 45 | 19 | server { |
| @@ -47,7 +21,7 @@ server { | ||
| 47 | 21 | http2 on; |
| 48 | 22 | server_name hutch.cleberg.net; |
| 49 | 23 | include custom.d/tls/ssl_engine.conf; |
| 50 | include custom.d/tls/certificate_files.conf; | |
| 24 | include custom.d/tls/certificate_files_cleberg_net.conf; | |
| 51 | 25 | include custom.d/tls/policy_strict.conf; |
| 52 | 26 | include custom.d/basic.conf; |
| 53 | 27 | include custom.d/security/strict-transport-security.conf; |
| @@ -69,31 +43,5 @@ server { | ||
| 69 | 43 | include custom.d/basic.conf; |
| 70 | 44 | root /var/www/cleberg.net/; |
| 71 | 45 | |
| 72 | location /org/ { | |
| 73 | internal; | |
| 74 | alias /var/www/cleberg.net/org/; | |
| 75 | default_type text/plain; | |
| 76 | add_header Content-Type "text/plain; charset=utf-8"; | |
| 77 | } | |
| 78 | ||
| 79 | location / { | |
| 80 | try_files $uri $uri/ =404; | |
| 81 | } | |
| 82 | ||
| 83 | location /blog/ { | |
| 84 | rewrite ^/blog/((?!index)[^/]+)/(.*)$ /blog/$1.html permanent; | |
| 85 | if ($http_accept ~* "text/markdown") { | |
| 86 | rewrite ^/blog/([^/]+)\.html$ /org/blog/$1.org last; | |
| 87 | } | |
| 88 | } | |
| 89 | ||
| 90 | location ~ ^/([^/]+)\.html$ { | |
| 91 | if ($http_accept ~* "text/markdown") { | |
| 92 | rewrite ^/([^/]+)\.html$ /org/$1.org last; | |
| 93 | } | |
| 94 | try_files $uri =404; | |
| 95 | } | |
| 96 | ||
| 97 | location /atom.xml { return 301 $scheme://$host/feed.xml; } | |
| 98 | location /blog/salary-transparency.html { return 301 $scheme://$host/salary/; } | |
| 46 | include custom.d/sites/cleberg_net_static_locations.conf; | |
| 99 | 47 | } |
linux/nginx/etc/nginx/conf.d/cv.conf +1 −1
| @@ -4,7 +4,7 @@ server { | ||
| 4 | 4 | server_name cv.cleberg.net; |
| 5 | 5 | add_header Onion-Location "http://xe43aewwiybmbo5qsstx7t5kmgkd2ei4bkkvqinwd7fxfmkekvnjbbad.onion$request_uri" always; |
| 6 | 6 | include custom.d/tls/ssl_engine.conf; |
| 7 | include custom.d/tls/certificate_files.conf; | |
| 7 | include custom.d/tls/certificate_files_cleberg_net.conf; | |
| 8 | 8 | include custom.d/tls/policy_strict.conf; |
| 9 | 9 | include custom.d/basic.conf; |
| 10 | 10 | root /var/www/cv/; |
linux/nginx/etc/nginx/conf.d/ddns.conf +2 −3
| @@ -3,13 +3,12 @@ server { | ||
| 3 | 3 | http2 on; |
| 4 | 4 | server_name ddns.zerolabs.sh; |
| 5 | 5 | include custom.d/tls/ssl_engine.conf; |
| 6 | include custom.d/tls/certificate_files.conf; | |
| 6 | include custom.d/tls/certificate_files_cleberg_net.conf; | |
| 7 | 7 | include custom.d/tls/policy_strict.conf; |
| 8 | 8 | include custom.d/basic.conf; |
| 9 | 9 | location /authelia { include custom.d/reverse_proxy/authelia.conf; } |
| 10 | 10 | location / { |
| 11 | set $upstream http://127.0.0.1:8097; | |
| 12 | proxy_pass $upstream; | |
| 11 | proxy_pass $backend_address; | |
| 13 | 12 | include custom.d/reverse_proxy/authelia_request.conf; |
| 14 | 13 | include custom.d/reverse_proxy/basic.conf; |
| 15 | 14 | } |
linux/nginx/etc/nginx/conf.d/files.conf +1 −1
| @@ -4,7 +4,7 @@ server { | ||
| 4 | 4 | server_name files.cleberg.net; |
| 5 | 5 | add_header Onion-Location "http://yt2y635dc6zyxziy5ytkfz36bmkgcxuccq3meom6qp44gjdat54wt5id.onion$request_uri" always; |
| 6 | 6 | include custom.d/tls/ssl_engine.conf; |
| 7 | include custom.d/tls/certificate_files.conf; | |
| 7 | include custom.d/tls/certificate_files_cleberg_net.conf; | |
| 8 | 8 | include custom.d/tls/policy_strict.conf; |
| 9 | 9 | include custom.d/basic.conf; |
| 10 | 10 | root /var/www/files/; |
linux/nginx/etc/nginx/conf.d/gh.conf +3 −4
| @@ -3,12 +3,11 @@ server { | ||
| 3 | 3 | http2 on; |
| 4 | 4 | server_name gh.zerolabs.sh; |
| 5 | 5 | include custom.d/tls/ssl_engine.conf; |
| 6 | include custom.d/tls/certificate_files.conf; | |
| 6 | include custom.d/tls/certificate_files_cleberg_net.conf; | |
| 7 | 7 | include custom.d/tls/policy_strict.conf; |
| 8 | 8 | include custom.d/basic.conf; |
| 9 | 9 | location / { |
| 10 | set $upstream http://192.168.0.251:3039; | |
| 11 | proxy_pass $upstream; | |
| 10 | proxy_pass $backend_address; | |
| 12 | 11 | include custom.d/reverse_proxy/basic.conf; |
| 13 | 12 | } |
| 14 | 13 | include custom.d/security/robots_index_only.conf; |
| @@ -32,7 +31,7 @@ server { | ||
| 32 | 31 | server_name gh.cleberg.net; |
| 33 | 32 | |
| 34 | 33 | include custom.d/tls/ssl_engine.conf; |
| 35 | include custom.d/tls/certificate_files.conf; | |
| 34 | include custom.d/tls/certificate_files_cleberg_net.conf; | |
| 36 | 35 | include custom.d/tls/policy_strict.conf; |
| 37 | 36 | |
| 38 | 37 | return 301 https://gh.zerolabs.sh$request_uri; |
linux/nginx/etc/nginx/conf.d/gramps.conf +2 −3
| @@ -3,13 +3,12 @@ server { | ||
| 3 | 3 | http2 on; |
| 4 | 4 | server_name gramps.cleberg.net; |
| 5 | 5 | include custom.d/tls/ssl_engine.conf; |
| 6 | include custom.d/tls/certificate_files.conf; | |
| 6 | include custom.d/tls/certificate_files_cleberg_net.conf; | |
| 7 | 7 | include custom.d/tls/policy_strict.conf; |
| 8 | 8 | include custom.d/basic.conf; |
| 9 | 9 | location /authelia { include custom.d/reverse_proxy/authelia.conf; } |
| 10 | 10 | location / { |
| 11 | set $upstream http://127.0.0.1:5566; | |
| 12 | proxy_pass $upstream; | |
| 11 | proxy_pass $backend_address; | |
| 13 | 12 | include custom.d/reverse_proxy/authelia_request.conf; |
| 14 | 13 | include custom.d/reverse_proxy/basic.conf; |
| 15 | 14 | } |
linux/nginx/etc/nginx/conf.d/ha.conf +3 −4
| @@ -3,16 +3,15 @@ server { | ||
| 3 | 3 | http2 on; |
| 4 | 4 | server_name ha.zerolabs.sh; |
| 5 | 5 | include custom.d/tls/ssl_engine.conf; |
| 6 | include custom.d/tls/certificate_files.conf; | |
| 6 | include custom.d/tls/certificate_files_cleberg_net.conf; | |
| 7 | 7 | include custom.d/tls/policy_strict.conf; |
| 8 | 8 | include custom.d/basic.conf; |
| 9 | set $upstream http://192.168.0.214:8123; | |
| 10 | 9 | location / { |
| 11 | proxy_pass $upstream; | |
| 10 | proxy_pass $backend_address; | |
| 12 | 11 | proxy_set_header X-Forwarded-For $remote_addr; |
| 13 | 12 | } |
| 14 | 13 | location /api/websocket { |
| 15 | proxy_pass $upstream; | |
| 14 | proxy_pass $backend_address; | |
| 16 | 15 | proxy_http_version 1.1; |
| 17 | 16 | proxy_set_header Upgrade $http_upgrade; |
| 18 | 17 | proxy_set_header Connection "upgrade"; |
linux/nginx/etc/nginx/conf.d/hat.conf +3 −4
| @@ -4,12 +4,11 @@ server { | ||
| 4 | 4 | server_name hat.zerolabs.sh jfrkztgin2ngoj2fnssc2m2j2ycpchmrhzhudaucgvaib5iqwgfxexyd.onion; |
| 5 | 5 | add_header Onion-Location "http://jfrkztgin2ngoj2fnssc2m2j2ycpchmrhzhudaucgvaib5iqwgfxexyd.onion$request_uri" always; |
| 6 | 6 | include custom.d/tls/ssl_engine.conf; |
| 7 | include custom.d/tls/certificate_files.conf; | |
| 7 | include custom.d/tls/certificate_files_cleberg_net.conf; | |
| 8 | 8 | include custom.d/tls/policy_strict.conf; |
| 9 | 9 | include custom.d/basic.conf; |
| 10 | 10 | location / { |
| 11 | set $upstream http://192.168.0.251:3991; | |
| 12 | proxy_pass $upstream; | |
| 11 | proxy_pass $backend_address; | |
| 13 | 12 | include custom.d/reverse_proxy/basic.conf; |
| 14 | 13 | } |
| 15 | 14 | include custom.d/security/robots_index_only.conf; |
| @@ -33,7 +32,7 @@ server { | ||
| 33 | 32 | server_name hat.cleberg.net; |
| 34 | 33 | |
| 35 | 34 | include custom.d/tls/ssl_engine.conf; |
| 36 | include custom.d/tls/certificate_files.conf; | |
| 35 | include custom.d/tls/certificate_files_cleberg_net.conf; | |
| 37 | 36 | include custom.d/tls/policy_strict.conf; |
| 38 | 37 | |
| 39 | 38 | return 301 https://hat.zerolabs.sh$request_uri; |
linux/nginx/etc/nginx/conf.d/hn.conf +2 −2
| @@ -7,7 +7,7 @@ server { | ||
| 7 | 7 | autoindex on; |
| 8 | 8 | add_header Onion-Location "http://r3yfeffyj7ornpikojmw75u3sn2la7tqnmcmwgv2ov7if24sm5czqeid.onion$request_uri" always; |
| 9 | 9 | include custom.d/tls/ssl_engine.conf; |
| 10 | include custom.d/tls/certificate_files.conf; | |
| 10 | include custom.d/tls/certificate_files_cleberg_net.conf; | |
| 11 | 11 | include custom.d/tls/policy_strict.conf; |
| 12 | 12 | include custom.d/basic.conf; |
| 13 | 13 | location / { try_files $uri $uri/ /index.html; } |
| @@ -31,7 +31,7 @@ server { | ||
| 31 | 31 | server_name hn.cleberg.net; |
| 32 | 32 | |
| 33 | 33 | include custom.d/tls/ssl_engine.conf; |
| 34 | include custom.d/tls/certificate_files.conf; | |
| 34 | include custom.d/tls/certificate_files_cleberg_net.conf; | |
| 35 | 35 | include custom.d/tls/policy_strict.conf; |
| 36 | 36 | |
| 37 | 37 | return 301 https://hn.zerolabs.sh$request_uri; |
linux/nginx/etc/nginx/conf.d/img.conf +1 −1
| @@ -4,7 +4,7 @@ server { | ||
| 4 | 4 | server_name img.cleberg.net; |
| 5 | 5 | add_header Onion-Location "http://ltf2dfg7tj263ll24lxuq7igejcrhcazjp6whgg6u6vyjir2iahqggad.onion$request_uri" always; |
| 6 | 6 | include custom.d/tls/ssl_engine.conf; |
| 7 | include custom.d/tls/certificate_files.conf; | |
| 7 | include custom.d/tls/certificate_files_cleberg_net.conf; | |
| 8 | 8 | include custom.d/tls/policy_strict.conf; |
| 9 | 9 | include custom.d/basic.conf; |
| 10 | 10 | root /var/www/img/; |
linux/nginx/etc/nginx/conf.d/irc.conf +2 −3
| @@ -3,13 +3,12 @@ server { | ||
| 3 | 3 | http2 on; |
| 4 | 4 | server_name irc.zerolabs.sh; |
| 5 | 5 | include custom.d/tls/ssl_engine.conf; |
| 6 | include custom.d/tls/certificate_files.conf; | |
| 6 | include custom.d/tls/certificate_files_cleberg_net.conf; | |
| 7 | 7 | include custom.d/tls/policy_strict.conf; |
| 8 | 8 | include custom.d/basic.conf; |
| 9 | 9 | location /authelia { include custom.d/reverse_proxy/authelia.conf; } |
| 10 | 10 | location / { |
| 11 | set $upstream http://127.0.0.1:9900; | |
| 12 | proxy_pass $upstream; | |
| 11 | proxy_pass $backend_address; | |
| 13 | 12 | include custom.d/reverse_proxy/authelia_request.conf; |
| 14 | 13 | include custom.d/reverse_proxy/basic.conf; |
| 15 | 14 | } |
linux/nginx/etc/nginx/conf.d/ld.conf +3 −4
| @@ -4,12 +4,11 @@ server { | ||
| 4 | 4 | server_name ld.zerolabs.sh u3tyzuhs7o4hkizpbcxbm5yqzj74bjqb3phfqfszrx4u75dua7lpf7ad.onion; |
| 5 | 5 | add_header Onion-Location "http://u3tyzuhs7o4hkizpbcxbm5yqzj74bjqb3phfqfszrx4u75dua7lpf7ad.onion$request_uri" always; |
| 6 | 6 | include custom.d/tls/ssl_engine.conf; |
| 7 | include custom.d/tls/certificate_files.conf; | |
| 7 | include custom.d/tls/certificate_files_cleberg_net.conf; | |
| 8 | 8 | include custom.d/tls/policy_strict.conf; |
| 9 | 9 | include custom.d/basic.conf; |
| 10 | 10 | location / { |
| 11 | set $upstream http://127.0.0.1:3004; | |
| 12 | proxy_pass $upstream; | |
| 11 | proxy_pass $backend_address; | |
| 13 | 12 | include custom.d/reverse_proxy/basic.conf; |
| 14 | 13 | } |
| 15 | 14 | include custom.d/security/robots_index_only.conf; |
| @@ -33,7 +32,7 @@ server { | ||
| 33 | 32 | server_name ld.cleberg.net; |
| 34 | 33 | |
| 35 | 34 | include custom.d/tls/ssl_engine.conf; |
| 36 | include custom.d/tls/certificate_files.conf; | |
| 35 | include custom.d/tls/certificate_files_cleberg_net.conf; | |
| 37 | 36 | include custom.d/tls/policy_strict.conf; |
| 38 | 37 | |
| 39 | 38 | return 301 https://ld.zerolabs.sh$request_uri; |
linux/nginx/etc/nginx/conf.d/lt.conf +3 −4
| @@ -4,12 +4,11 @@ server { | ||
| 4 | 4 | server_name lt.zerolabs.sh nxw6545qeepw2s2kngowsxbcizjcxyimn7dq2bpvr3sqabsu2juj6gyd.onion; |
| 5 | 5 | add_header Onion-Location "http://nxw6545qeepw2s2kngowsxbcizjcxyimn7dq2bpvr3sqabsu2juj6gyd.onion$request_uri" always; |
| 6 | 6 | include custom.d/tls/ssl_engine.conf; |
| 7 | include custom.d/tls/certificate_files.conf; | |
| 7 | include custom.d/tls/certificate_files_cleberg_net.conf; | |
| 8 | 8 | include custom.d/tls/policy_strict.conf; |
| 9 | 9 | include custom.d/basic.conf; |
| 10 | 10 | location / { |
| 11 | set $upstream http://127.0.0.1:5000; | |
| 12 | proxy_pass $upstream; | |
| 11 | proxy_pass $backend_address; | |
| 13 | 12 | include custom.d/reverse_proxy/basic.conf; |
| 14 | 13 | } |
| 15 | 14 | include custom.d/security/robots_index_only.conf; |
| @@ -33,7 +32,7 @@ server { | ||
| 33 | 32 | server_name lt.cleberg.net; |
| 34 | 33 | |
| 35 | 34 | include custom.d/tls/ssl_engine.conf; |
| 36 | include custom.d/tls/certificate_files.conf; | |
| 35 | include custom.d/tls/certificate_files_cleberg_net.conf; | |
| 37 | 36 | include custom.d/tls/policy_strict.conf; |
| 38 | 37 | |
| 39 | 38 | return 301 https://lt.zerolabs.sh$request_uri; |
linux/nginx/etc/nginx/conf.d/mz.conf +3 −4
| @@ -4,12 +4,11 @@ server { | ||
| 4 | 4 | server_name mz.zerolabs.sh ltawlmsk6vhrig2awwshnduiv45anelx3thepkd6xh4n2s4jxu7wyrid.onion; |
| 5 | 5 | add_header Onion-Location "http://ltawlmsk6vhrig2awwshnduiv45anelx3thepkd6xh4n2s4jxu7wyrid.onion$request_uri" always; |
| 6 | 6 | include custom.d/tls/ssl_engine.conf; |
| 7 | include custom.d/tls/certificate_files.conf; | |
| 7 | include custom.d/tls/certificate_files_cleberg_net.conf; | |
| 8 | 8 | include custom.d/tls/policy_strict.conf; |
| 9 | 9 | include custom.d/basic.conf; |
| 10 | 10 | location / { |
| 11 | set $upstream http://127.0.0.1:3474; | |
| 12 | proxy_pass $upstream; | |
| 11 | proxy_pass $backend_address; | |
| 13 | 12 | include custom.d/reverse_proxy/basic.conf; |
| 14 | 13 | } |
| 15 | 14 | include custom.d/security/robots_index_only.conf; |
| @@ -33,7 +32,7 @@ server { | ||
| 33 | 32 | server_name mz.cleberg.net; |
| 34 | 33 | |
| 35 | 34 | include custom.d/tls/ssl_engine.conf; |
| 36 | include custom.d/tls/certificate_files.conf; | |
| 35 | include custom.d/tls/certificate_files_cleberg_net.conf; | |
| 37 | 36 | include custom.d/tls/policy_strict.conf; |
| 38 | 37 | |
| 39 | 38 | return 301 https://mz.zerolabs.sh$request_uri; |
linux/nginx/etc/nginx/conf.d/office.conf +2 −2
| @@ -5,7 +5,7 @@ server { | ||
| 5 | 5 | add_header Onion-Location "http://uwtjz6pof52bzdkj242mub77ls2ji3qiznbsuoir235rxynqxadpghid.onion$request_uri" always; |
| 6 | 6 | root /var/www/office/; |
| 7 | 7 | include custom.d/tls/ssl_engine.conf; |
| 8 | include custom.d/tls/certificate_files.conf; | |
| 8 | include custom.d/tls/certificate_files_cleberg_net.conf; | |
| 9 | 9 | include custom.d/tls/policy_strict.conf; |
| 10 | 10 | include custom.d/basic.conf; |
| 11 | 11 | location / { try_files $uri $uri/ /index.html; } |
| @@ -36,7 +36,7 @@ server { | ||
| 36 | 36 | server_name office.cleberg.net; |
| 37 | 37 | |
| 38 | 38 | include custom.d/tls/ssl_engine.conf; |
| 39 | include custom.d/tls/certificate_files.conf; | |
| 39 | include custom.d/tls/certificate_files_cleberg_net.conf; | |
| 40 | 40 | include custom.d/tls/policy_strict.conf; |
| 41 | 41 | |
| 42 | 42 | return 301 https://office.zerolabs.sh$request_uri; |
linux/nginx/etc/nginx/conf.d/org.conf +2 −2
| @@ -5,7 +5,7 @@ server { | ||
| 5 | 5 | add_header Onion-Location "http://7vsifofpucgi3wva52nbwhwglrmbyxgdapbkkmgniqlsskspux5zocyd.onion$request_uri" always; |
| 6 | 6 | root /var/www/org/; |
| 7 | 7 | include custom.d/tls/ssl_engine.conf; |
| 8 | include custom.d/tls/certificate_files.conf; | |
| 8 | include custom.d/tls/certificate_files_cleberg_net.conf; | |
| 9 | 9 | include custom.d/tls/policy_strict.conf; |
| 10 | 10 | include custom.d/basic.conf; |
| 11 | 11 | location / { try_files $uri $uri/ /index.html; } |
| @@ -36,7 +36,7 @@ server { | ||
| 36 | 36 | server_name org.cleberg.net; |
| 37 | 37 | |
| 38 | 38 | include custom.d/tls/ssl_engine.conf; |
| 39 | include custom.d/tls/certificate_files.conf; | |
| 39 | include custom.d/tls/certificate_files_cleberg_net.conf; | |
| 40 | 40 | include custom.d/tls/policy_strict.conf; |
| 41 | 41 | |
| 42 | 42 | return 301 https://org.zerolabs.sh$request_uri; |
linux/nginx/etc/nginx/conf.d/paste.conf +3 −4
| @@ -4,12 +4,11 @@ server { | ||
| 4 | 4 | server_name paste.zerolabs.sh ciserod7fbncypo762qcqtowldl3qjhlojfnmguiuvcj3rcyrhqs6ead.onion; |
| 5 | 5 | add_header Onion-Location "http://ciserod7fbncypo762qcqtowldl3qjhlojfnmguiuvcj3rcyrhqs6ead.onion$request_uri" always; |
| 6 | 6 | include custom.d/tls/ssl_engine.conf; |
| 7 | include custom.d/tls/certificate_files.conf; | |
| 7 | include custom.d/tls/certificate_files_cleberg_net.conf; | |
| 8 | 8 | include custom.d/tls/policy_strict.conf; |
| 9 | 9 | include custom.d/basic.conf; |
| 10 | 10 | location / { |
| 11 | set $upstream http://127.0.0.1:8084; | |
| 12 | proxy_pass $upstream; | |
| 11 | proxy_pass $backend_address; | |
| 13 | 12 | include custom.d/reverse_proxy/basic.conf; |
| 14 | 13 | } |
| 15 | 14 | include custom.d/security/robots_index_only.conf; |
| @@ -33,7 +32,7 @@ server { | ||
| 33 | 32 | server_name paste.cleberg.net; |
| 34 | 33 | |
| 35 | 34 | include custom.d/tls/ssl_engine.conf; |
| 36 | include custom.d/tls/certificate_files.conf; | |
| 35 | include custom.d/tls/certificate_files_cleberg_net.conf; | |
| 37 | 36 | include custom.d/tls/policy_strict.conf; |
| 38 | 37 | |
| 39 | 38 | return 301 https://paste.zerolabs.sh$request_uri; |
linux/nginx/etc/nginx/conf.d/pb.conf +3 −4
| @@ -6,13 +6,12 @@ server { | ||
| 6 | 6 | error_log /var/log/nginx/pb.log; |
| 7 | 7 | |
| 8 | 8 | include custom.d/tls/ssl_engine.conf; |
| 9 | include custom.d/tls/certificate_files.conf; | |
| 9 | include custom.d/tls/certificate_files_cleberg_net.conf; | |
| 10 | 10 | include custom.d/tls/policy_strict.conf; |
| 11 | 11 | include custom.d/basic.conf; |
| 12 | 12 | location /authelia { include custom.d/reverse_proxy/authelia.conf; } |
| 13 | 13 | location / { |
| 14 | set $upstream http://127.0.0.1:8745; | |
| 15 | proxy_pass $upstream; | |
| 14 | proxy_pass $backend_address; | |
| 16 | 15 | include custom.d/reverse_proxy/authelia_request.conf; |
| 17 | 16 | include custom.d/reverse_proxy/basic.conf; |
| 18 | 17 | } |
| @@ -37,7 +36,7 @@ server { | ||
| 37 | 36 | server_name pb.cleberg.net; |
| 38 | 37 | |
| 39 | 38 | include custom.d/tls/ssl_engine.conf; |
| 40 | include custom.d/tls/certificate_files.conf; | |
| 39 | include custom.d/tls/certificate_files_cleberg_net.conf; | |
| 41 | 40 | include custom.d/tls/policy_strict.conf; |
| 42 | 41 | |
| 43 | 42 | return 301 https://pb.zerolabs.sh$request_uri; |
linux/nginx/etc/nginx/conf.d/photos.conf +2 −2
| @@ -3,7 +3,7 @@ server { | ||
| 3 | 3 | http2 on; |
| 4 | 4 | server_name photos.cleberg.net; |
| 5 | 5 | include custom.d/tls/ssl_engine.conf; |
| 6 | include custom.d/tls/certificate_files.conf; | |
| 6 | include custom.d/tls/certificate_files_cleberg_net.conf; | |
| 7 | 7 | include custom.d/tls/policy_strict.conf; |
| 8 | 8 | include custom.d/basic.conf; |
| 9 | 9 | client_max_body_size 50000M; |
| @@ -18,7 +18,7 @@ server { | ||
| 18 | 18 | proxy_read_timeout 600s; |
| 19 | 19 | proxy_send_timeout 600s; |
| 20 | 20 | send_timeout 600s; |
| 21 | location / { proxy_pass http://127.0.0.1:2283; } | |
| 21 | location / { proxy_pass $backend_address; } | |
| 22 | 22 | } |
| 23 | 23 | |
| 24 | 24 | server { |
linux/nginx/etc/nginx/conf.d/pin.conf +3 −4
| @@ -4,12 +4,11 @@ server { | ||
| 4 | 4 | server_name pin.zerolabs.sh 3rtmxu6slammicquf5cpgiptjpzht3n342vh62utoyxchds5r76tadad.onion; |
| 5 | 5 | add_header Onion-Location "http://3rtmxu6slammicquf5cpgiptjpzht3n342vh62utoyxchds5r76tadad.onion$request_uri" always; |
| 6 | 6 | include custom.d/tls/ssl_engine.conf; |
| 7 | include custom.d/tls/certificate_files.conf; | |
| 7 | include custom.d/tls/certificate_files_cleberg_net.conf; | |
| 8 | 8 | include custom.d/tls/policy_strict.conf; |
| 9 | 9 | include custom.d/basic.conf; |
| 10 | 10 | location / { |
| 11 | set $upstream http://127.0.0.1:8086; | |
| 12 | proxy_pass $upstream; | |
| 11 | proxy_pass $backend_address; | |
| 13 | 12 | include custom.d/reverse_proxy/basic.conf; |
| 14 | 13 | } |
| 15 | 14 | include custom.d/security/robots_index_only.conf; |
| @@ -33,7 +32,7 @@ server { | ||
| 33 | 32 | server_name pin.cleberg.net; |
| 34 | 33 | |
| 35 | 34 | include custom.d/tls/ssl_engine.conf; |
| 36 | include custom.d/tls/certificate_files.conf; | |
| 35 | include custom.d/tls/certificate_files_cleberg_net.conf; | |
| 37 | 36 | include custom.d/tls/policy_strict.conf; |
| 38 | 37 | |
| 39 | 38 | return 301 https://pin.zerolabs.sh$request_uri; |
linux/nginx/etc/nginx/conf.d/piped.conf +3 −4
| @@ -4,12 +4,11 @@ server { | ||
| 4 | 4 | server_name piped.zerolabs.sh pipedapi.zerolabs.sh pipedproxy.zerolabs.sh 5ttqjwhhcxh7apxrge5b5cjqceiibrjlqv2hhtmukwfsitbzqk5hh4id.onion; |
| 5 | 5 | add_header Onion-Location "http://5ttqjwhhcxh7apxrge5b5cjqceiibrjlqv2hhtmukwfsitbzqk5hh4id.onion$request_uri" always; |
| 6 | 6 | include custom.d/tls/ssl_engine.conf; |
| 7 | include custom.d/tls/certificate_files.conf; | |
| 7 | include custom.d/tls/certificate_files_cleberg_net.conf; | |
| 8 | 8 | include custom.d/tls/policy_strict.conf; |
| 9 | 9 | include custom.d/basic.conf; |
| 10 | 10 | location / { |
| 11 | set $upstream http://127.0.0.1:8077; | |
| 12 | proxy_pass $upstream; | |
| 11 | proxy_pass $backend_address; | |
| 13 | 12 | proxy_set_header Host $host; |
| 14 | 13 | } |
| 15 | 14 | include custom.d/security/robots_index_only.conf; |
| @@ -33,7 +32,7 @@ server { | ||
| 33 | 32 | server_name piped.cleberg.net pipedapi.cleberg.net pipedproxy.cleberg.net; |
| 34 | 33 | |
| 35 | 34 | include custom.d/tls/ssl_engine.conf; |
| 36 | include custom.d/tls/certificate_files.conf; | |
| 35 | include custom.d/tls/certificate_files_cleberg_net.conf; | |
| 37 | 36 | include custom.d/tls/policy_strict.conf; |
| 38 | 37 | |
| 39 | 38 | return 301 https://pipedapi.zerolabs.sh$request_uri; |
linux/nginx/etc/nginx/conf.d/projects.conf +2 −2
| @@ -6,7 +6,7 @@ server { | ||
| 6 | 6 | root /var/www/projects/; |
| 7 | 7 | autoindex on; |
| 8 | 8 | include custom.d/tls/ssl_engine.conf; |
| 9 | include custom.d/tls/certificate_files.conf; | |
| 9 | include custom.d/tls/certificate_files_cleberg_net.conf; | |
| 10 | 10 | include custom.d/tls/policy_strict.conf; |
| 11 | 11 | include custom.d/basic.conf; |
| 12 | 12 | location / { try_files $uri $uri/ /index.html; } |
| @@ -39,7 +39,7 @@ server { | ||
| 39 | 39 | server_name projects.cleberg.net; |
| 40 | 40 | |
| 41 | 41 | include custom.d/tls/ssl_engine.conf; |
| 42 | include custom.d/tls/certificate_files.conf; | |
| 42 | include custom.d/tls/certificate_files_cleberg_net.conf; | |
| 43 | 43 | include custom.d/tls/policy_strict.conf; |
| 44 | 44 | |
| 45 | 45 | return 301 https://projects.zerolabs.sh$request_uri; |
linux/nginx/etc/nginx/conf.d/rd.conf +3 −4
| @@ -4,12 +4,11 @@ server { | ||
| 4 | 4 | server_name rd.zerolabs.sh voyxxivcoupelvedthpbjqsrdhkn4ty7qjurvsif4qbjejnldisqs5ad.onion; |
| 5 | 5 | add_header Onion-Location "http://voyxxivcoupelvedthpbjqsrdhkn4ty7qjurvsif4qbjejnldisqs5ad.onion$request_uri" always; |
| 6 | 6 | include custom.d/tls/ssl_engine.conf; |
| 7 | include custom.d/tls/certificate_files.conf; | |
| 7 | include custom.d/tls/certificate_files_cleberg_net.conf; | |
| 8 | 8 | include custom.d/tls/policy_strict.conf; |
| 9 | 9 | include custom.d/basic.conf; |
| 10 | 10 | location / { |
| 11 | set $upstream http://127.0.0.1:2944; | |
| 12 | proxy_pass $upstream; | |
| 11 | proxy_pass $backend_address; | |
| 13 | 12 | include custom.d/reverse_proxy/basic.conf; |
| 14 | 13 | } |
| 15 | 14 | include custom.d/security/robots_index_only.conf; |
| @@ -33,7 +32,7 @@ server { | ||
| 33 | 32 | server_name rd.cleberg.net; |
| 34 | 33 | |
| 35 | 34 | include custom.d/tls/ssl_engine.conf; |
| 36 | include custom.d/tls/certificate_files.conf; | |
| 35 | include custom.d/tls/certificate_files_cleberg_net.conf; | |
| 37 | 36 | include custom.d/tls/policy_strict.conf; |
| 38 | 37 | |
| 39 | 38 | return 301 https://rd.zerolabs.sh$request_uri; |
linux/nginx/etc/nginx/conf.d/reminiscecleberg.com.conf +2 −6
| @@ -4,9 +4,7 @@ server { | ||
| 4 | 4 | server_name www.reminiscecleberg.com; |
| 5 | 5 | include custom.d/tls/ssl_engine.conf; |
| 6 | 6 | include custom.d/tls/policy_strict.conf; |
| 7 | ssl_certificate /etc/letsencrypt/live/reminiscecleberg.com/fullchain.pem; | |
| 8 | ssl_certificate_key /etc/letsencrypt/live/reminiscecleberg.com/privkey.pem; | |
| 9 | ssl_trusted_certificate /etc/letsencrypt/live/reminiscecleberg.com/chain.pem; | |
| 7 | include custom.d/tls/certificate_files_reminiscecleberg_com.conf; | |
| 10 | 8 | return 301 $scheme://reminiscecleberg.com$request_uri; |
| 11 | 9 | } |
| 12 | 10 | |
| @@ -18,10 +16,8 @@ server { | ||
| 18 | 16 | root /var/www/reminiscecleberg.com/; |
| 19 | 17 | include custom.d/tls/ssl_engine.conf; |
| 20 | 18 | include custom.d/tls/policy_strict.conf; |
| 19 | include custom.d/tls/certificate_files_reminiscecleberg_com.conf; | |
| 21 | 20 | include custom.d/basic.conf; |
| 22 | ssl_certificate /etc/letsencrypt/live/reminiscecleberg.com/fullchain.pem; | |
| 23 | ssl_certificate_key /etc/letsencrypt/live/reminiscecleberg.com/privkey.pem; | |
| 24 | ssl_trusted_certificate /etc/letsencrypt/live/reminiscecleberg.com/chain.pem; | |
| 25 | 21 | location / { try_files $uri $uri/ =404; } |
| 26 | 22 | } |
| 27 | 23 | |
linux/nginx/etc/nginx/conf.d/rimgo.conf +3 −4
| @@ -4,12 +4,11 @@ server { | ||
| 4 | 4 | server_name rimgo.zerolabs.sh hcj62a4s6ok23oaa4xjnnvabj2aunod3464iuufh2wtehg2th3rwn3yd.onion; |
| 5 | 5 | add_header Onion-Location "http://hcj62a4s6ok23oaa4xjnnvabj2aunod3464iuufh2wtehg2th3rwn3yd.onion$request_uri" always; |
| 6 | 6 | include custom.d/tls/ssl_engine.conf; |
| 7 | include custom.d/tls/certificate_files.conf; | |
| 7 | include custom.d/tls/certificate_files_cleberg_net.conf; | |
| 8 | 8 | include custom.d/tls/policy_strict.conf; |
| 9 | 9 | include custom.d/basic.conf; |
| 10 | 10 | location / { |
| 11 | set $upstream http://127.0.0.1:3869; | |
| 12 | proxy_pass $upstream; | |
| 11 | proxy_pass $backend_address; | |
| 13 | 12 | include custom.d/reverse_proxy/basic.conf; |
| 14 | 13 | } |
| 15 | 14 | include custom.d/security/robots_index_only.conf; |
| @@ -33,7 +32,7 @@ server { | ||
| 33 | 32 | server_name rimgo.cleberg.net; |
| 34 | 33 | |
| 35 | 34 | include custom.d/tls/ssl_engine.conf; |
| 36 | include custom.d/tls/certificate_files.conf; | |
| 35 | include custom.d/tls/certificate_files_cleberg_net.conf; | |
| 37 | 36 | include custom.d/tls/policy_strict.conf; |
| 38 | 37 | |
| 39 | 38 | return 301 https://rimgo.zerolabs.sh$request_uri; |
linux/nginx/etc/nginx/conf.d/rl.conf +3 −4
| @@ -4,13 +4,12 @@ server { | ||
| 4 | 4 | server_name rl.zerolabs.sh s5wpjol4xe2mszhz4hoqobv4pqmoihb65dz2lbibujjjvhbpjvu45lad.onion; |
| 5 | 5 | add_header Onion-Location "http://s5wpjol4xe2mszhz4hoqobv4pqmoihb65dz2lbibujjjvhbpjvu45lad.onion$request_uri" always; |
| 6 | 6 | include custom.d/tls/ssl_engine.conf; |
| 7 | include custom.d/tls/certificate_files.conf; | |
| 7 | include custom.d/tls/certificate_files_cleberg_net.conf; | |
| 8 | 8 | include custom.d/tls/policy_strict.conf; |
| 9 | 9 | include custom.d/basic.conf; |
| 10 | 10 | location /authelia { include custom.d/reverse_proxy/authelia.conf; } |
| 11 | 11 | location / { |
| 12 | set $upstream http://127.0.0.1:8983; | |
| 13 | proxy_pass $upstream; | |
| 12 | proxy_pass $backend_address; | |
| 14 | 13 | include custom.d/reverse_proxy/authelia_request.conf; |
| 15 | 14 | include custom.d/reverse_proxy/basic.conf; |
| 16 | 15 | } |
| @@ -35,7 +34,7 @@ server { | ||
| 35 | 34 | server_name rl.cleberg.net; |
| 36 | 35 | |
| 37 | 36 | include custom.d/tls/ssl_engine.conf; |
| 38 | include custom.d/tls/certificate_files.conf; | |
| 37 | include custom.d/tls/certificate_files_cleberg_net.conf; | |
| 39 | 38 | include custom.d/tls/policy_strict.conf; |
| 40 | 39 | |
| 41 | 40 | return 301 https://rl.zerolabs.sh$request_uri; |
linux/nginx/etc/nginx/conf.d/rss.conf +1 −1
| @@ -4,7 +4,7 @@ server { | ||
| 4 | 4 | http2 on; |
| 5 | 5 | server_name rss.zerolabs.sh; |
| 6 | 6 | include custom.d/tls/ssl_engine.conf; |
| 7 | include custom.d/tls/certificate_files.conf; | |
| 7 | include custom.d/tls/certificate_files_cleberg_net.conf; | |
| 8 | 8 | include custom.d/tls/policy_strict.conf; |
| 9 | 9 | include custom.d/basic.conf; |
| 10 | 10 | location / { |
linux/nginx/etc/nginx/conf.d/search.conf +3 −4
| @@ -4,12 +4,11 @@ server { | ||
| 4 | 4 | server_name search.zerolabs.sh txwk667ks3vh76r2mfqiot2wdptentsne64nu6qam63zbpzbmhtkvnid.onion; |
| 5 | 5 | add_header Onion-Location "http://txwk667ks3vh76r2mfqiot2wdptentsne64nu6qam63zbpzbmhtkvnid.onion$request_uri" always; |
| 6 | 6 | include custom.d/tls/ssl_engine.conf; |
| 7 | include custom.d/tls/certificate_files.conf; | |
| 7 | include custom.d/tls/certificate_files_cleberg_net.conf; | |
| 8 | 8 | include custom.d/tls/policy_strict.conf; |
| 9 | 9 | include custom.d/basic.conf; |
| 10 | 10 | location / { |
| 11 | set $upstream http://127.0.0.1:9191; | |
| 12 | proxy_pass $upstream; | |
| 11 | proxy_pass $backend_address; | |
| 13 | 12 | proxy_set_header Host $host; |
| 14 | 13 | proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; |
| 15 | 14 | proxy_set_header Upgrade $http_upgrade; |
| @@ -37,7 +36,7 @@ server { | ||
| 37 | 36 | server_name search.cleberg.net; |
| 38 | 37 | |
| 39 | 38 | include custom.d/tls/ssl_engine.conf; |
| 40 | include custom.d/tls/certificate_files.conf; | |
| 39 | include custom.d/tls/certificate_files_cleberg_net.conf; | |
| 41 | 40 | include custom.d/tls/policy_strict.conf; |
| 42 | 41 | |
| 43 | 42 | return 301 https://search.zerolabs.sh$request_uri; |
linux/nginx/etc/nginx/conf.d/send.conf +3 −4
| @@ -4,12 +4,11 @@ server { | ||
| 4 | 4 | server_name send.zerolabs.sh 6jcf5qh2yg4axi42nbbcijglvoag74z7oq7xikqueebeb5vykj22miqd.onion; |
| 5 | 5 | add_header Onion-Location "http://6jcf5qh2yg4axi42nbbcijglvoag74z7oq7xikqueebeb5vykj22miqd.onion$request_uri" always; |
| 6 | 6 | include custom.d/tls/ssl_engine.conf; |
| 7 | include custom.d/tls/certificate_files.conf; | |
| 7 | include custom.d/tls/certificate_files_cleberg_net.conf; | |
| 8 | 8 | include custom.d/tls/policy_strict.conf; |
| 9 | 9 | include custom.d/basic.conf; |
| 10 | 10 | location / { |
| 11 | set $upstream http://192.168.0.251:1443; | |
| 12 | proxy_pass $upstream; | |
| 11 | proxy_pass $backend_address; | |
| 13 | 12 | include custom.d/reverse_proxy/basic.conf; |
| 14 | 13 | } |
| 15 | 14 | include custom.d/security/robots_index_only.conf; |
| @@ -33,7 +32,7 @@ server { | ||
| 33 | 32 | server_name send.cleberg.net; |
| 34 | 33 | |
| 35 | 34 | include custom.d/tls/ssl_engine.conf; |
| 36 | include custom.d/tls/certificate_files.conf; | |
| 35 | include custom.d/tls/certificate_files_cleberg_net.conf; | |
| 37 | 36 | include custom.d/tls/policy_strict.conf; |
| 38 | 37 | |
| 39 | 38 | return 301 https://send.zerolabs.sh$request_uri; |
linux/nginx/etc/nginx/conf.d/slash.conf +3 −4
| @@ -4,12 +4,11 @@ server { | ||
| 4 | 4 | server_name slash.zerolabs.sh svfj2zs33g572utlou6kx7uamhwen4nxdzvfetnhwjqs4mmdgoayc7qd.onion; |
| 5 | 5 | add_header Onion-Location "http://svfj2zs33g572utlou6kx7uamhwen4nxdzvfetnhwjqs4mmdgoayc7qd.onion$request_uri" always; |
| 6 | 6 | include custom.d/tls/ssl_engine.conf; |
| 7 | include custom.d/tls/certificate_files.conf; | |
| 7 | include custom.d/tls/certificate_files_cleberg_net.conf; | |
| 8 | 8 | include custom.d/tls/policy_strict.conf; |
| 9 | 9 | include custom.d/basic.conf; |
| 10 | 10 | location / { |
| 11 | set $upstream http://192.168.0.251:5231; | |
| 12 | proxy_pass $upstream; | |
| 11 | proxy_pass $backend_address; | |
| 13 | 12 | include custom.d/reverse_proxy/basic.conf; |
| 14 | 13 | } |
| 15 | 14 | include custom.d/security/robots_index_only.conf; |
| @@ -33,7 +32,7 @@ server { | ||
| 33 | 32 | server_name slash.cleberg.net; |
| 34 | 33 | |
| 35 | 34 | include custom.d/tls/ssl_engine.conf; |
| 36 | include custom.d/tls/certificate_files.conf; | |
| 35 | include custom.d/tls/certificate_files_cleberg_net.conf; | |
| 37 | 36 | include custom.d/tls/policy_strict.conf; |
| 38 | 37 | |
| 39 | 38 | return 301 https://slash.zerolabs.sh$request_uri; |
linux/nginx/etc/nginx/conf.d/small.conf +3 −4
| @@ -4,12 +4,11 @@ server { | ||
| 4 | 4 | server_name small.zerolabs.sh w2qsrbzjmlikhwvbhno3qfdjod53iyzlvzjamcvgkcmtbclmdkqerbqd.onion; |
| 5 | 5 | add_header Onion-Location "http://w2qsrbzjmlikhwvbhno3qfdjod53iyzlvzjamcvgkcmtbclmdkqerbqd.onion$request_uri" always; |
| 6 | 6 | include custom.d/tls/ssl_engine.conf; |
| 7 | include custom.d/tls/certificate_files.conf; | |
| 7 | include custom.d/tls/certificate_files_cleberg_net.conf; | |
| 8 | 8 | include custom.d/tls/policy_strict.conf; |
| 9 | 9 | include custom.d/basic.conf; |
| 10 | 10 | location / { |
| 11 | set $upstream http://127.0.0.1:8002; | |
| 12 | proxy_pass $upstream; | |
| 11 | proxy_pass $backend_address; | |
| 13 | 12 | include custom.d/reverse_proxy/basic.conf; |
| 14 | 13 | } |
| 15 | 14 | include custom.d/security/robots_index_only.conf; |
| @@ -33,7 +32,7 @@ server { | ||
| 33 | 32 | server_name small.cleberg.net; |
| 34 | 33 | |
| 35 | 34 | include custom.d/tls/ssl_engine.conf; |
| 36 | include custom.d/tls/certificate_files.conf; | |
| 35 | include custom.d/tls/certificate_files_cleberg_net.conf; | |
| 37 | 36 | include custom.d/tls/policy_strict.conf; |
| 38 | 37 | |
| 39 | 38 | return 301 https://small.zerolabs.sh$request_uri; |
linux/nginx/etc/nginx/conf.d/ssh.conf +2 −3
| @@ -3,13 +3,12 @@ server { | ||
| 3 | 3 | http2 on; |
| 4 | 4 | server_name ssh.zerolabs.sh; |
| 5 | 5 | include custom.d/tls/ssl_engine.conf; |
| 6 | include custom.d/tls/certificate_files.conf; | |
| 6 | include custom.d/tls/certificate_files_cleberg_net.conf; | |
| 7 | 7 | include custom.d/tls/policy_strict.conf; |
| 8 | 8 | include custom.d/basic.conf; |
| 9 | 9 | location /authelia { include custom.d/reverse_proxy/authelia.conf; } |
| 10 | 10 | location / { |
| 11 | set $upstream http://127.0.0.1:8169; | |
| 12 | proxy_pass $upstream; | |
| 11 | proxy_pass $backend_address; | |
| 13 | 12 | include custom.d/reverse_proxy/authelia_request.conf; |
| 14 | 13 | include custom.d/reverse_proxy/basic.conf; |
| 15 | 14 | } |
linux/nginx/etc/nginx/conf.d/zerolabs.sh.conf +2 −6
| @@ -4,9 +4,7 @@ server { | ||
| 4 | 4 | server_name www.zerolabs.sh; |
| 5 | 5 | include custom.d/tls/ssl_engine.conf; |
| 6 | 6 | include custom.d/tls/policy_strict.conf; |
| 7 | ssl_certificate /etc/letsencrypt/live/zerolabs.sh/fullchain.pem; | |
| 8 | ssl_certificate_key /etc/letsencrypt/live/zerolabs.sh/privkey.pem; | |
| 9 | ssl_trusted_certificate /etc/letsencrypt/live/zerolabs.sh/chain.pem; | |
| 7 | include custom.d/tls/certificate_files_zerolabs_sh.conf; | |
| 10 | 8 | return 301 $scheme://zerolabs.sh$request_uri; |
| 11 | 9 | } |
| 12 | 10 | |
| @@ -18,10 +16,8 @@ server { | ||
| 18 | 16 | root /var/www/zerolabs.sh/; |
| 19 | 17 | include custom.d/tls/ssl_engine.conf; |
| 20 | 18 | include custom.d/tls/policy_strict.conf; |
| 19 | include custom.d/tls/certificate_files_zerolabs_sh.conf; | |
| 21 | 20 | include custom.d/basic.conf; |
| 22 | ssl_certificate /etc/letsencrypt/live/zerolabs.sh/fullchain.pem; | |
| 23 | ssl_certificate_key /etc/letsencrypt/live/zerolabs.sh/privkey.pem; | |
| 24 | ssl_trusted_certificate /etc/letsencrypt/live/zerolabs.sh/chain.pem; | |
| 25 | 21 | location / { try_files $uri $uri/ =404; } |
| 26 | 22 | } |
| 27 | 23 | |
linux/nginx/etc/nginx/custom.d/http/backend_address.conf added +145
| @@ -0,0 +1,145 @@ | ||
| 1 | # Upstream URL per Host (clearnet and matching .onion listeners). Used as: | |
| 2 | # proxy_pass $backend_address; | |
| 3 | map $host $backend_address { | |
| 4 | hostnames; | |
| 5 | ||
| 6 | # --- ao | |
| 7 | 7lyqrn4ofxdq7lfporviu44zpc42wooh2bqazfhvpscgwby2vcwldzad.onion http://127.0.0.1:9380; | |
| 8 | ao.cleberg.net http://127.0.0.1:9380; | |
| 9 | ao.zerolabs.sh http://127.0.0.1:9380; | |
| 10 | ||
| 11 | # --- art | |
| 12 | art.cleberg.net http://127.0.0.1:3003; | |
| 13 | art.zerolabs.sh http://127.0.0.1:3003; | |
| 14 | mplqs2jxkjd5wxak3zjv55oxyadf4vwzx6ksgj4ztftndjl6elgsf4qd.onion http://127.0.0.1:3003; | |
| 15 | ||
| 16 | # --- auth (cleberg hostname reserved for future use) | |
| 17 | auth.cleberg.net http://127.0.0.1:9092; | |
| 18 | auth.zerolabs.sh http://127.0.0.1:9092; | |
| 19 | ||
| 20 | # --- br | |
| 21 | br.cleberg.net http://127.0.0.1:3030; | |
| 22 | br.zerolabs.sh http://127.0.0.1:3030; | |
| 23 | pkft6saqbmn6he5g626fphvlijmkdf4rzckjw6r57zsmuqm4ukd6i5ad.onion http://127.0.0.1:3030; | |
| 24 | ||
| 25 | # --- bt | |
| 26 | bt.cleberg.net http://127.0.0.1:9091; | |
| 27 | bt.zerolabs.sh http://127.0.0.1:9091; | |
| 28 | ||
| 29 | # --- bw | |
| 30 | bw.cleberg.net http://127.0.0.1:10416; | |
| 31 | bw.zerolabs.sh http://127.0.0.1:10416; | |
| 32 | z7kc27ceokwgddrcspxx4eb7b6xqmtjj26nohg3wgt6hsnnlfmk4apqd.onion http://127.0.0.1:10416; | |
| 33 | ||
| 34 | # --- cc | |
| 35 | cc.cleberg.net http://127.0.0.1:8111; | |
| 36 | cc.zerolabs.sh http://127.0.0.1:8111; | |
| 37 | gipsohqqcehn4n6smyg5j5aap7ln6lwugyjm2lxyx4vfiwayjhpnodyd.onion http://127.0.0.1:8111; | |
| 38 | ||
| 39 | # --- ddns | |
| 40 | ddns.cleberg.net http://127.0.0.1:8097; | |
| 41 | ddns.zerolabs.sh http://127.0.0.1:8097; | |
| 42 | ||
| 43 | # --- gh | |
| 44 | gh.cleberg.net http://192.168.0.251:3039; | |
| 45 | gh.zerolabs.sh http://192.168.0.251:3039; | |
| 46 | ||
| 47 | # --- gramps | |
| 48 | gramps.cleberg.net http://127.0.0.1:5566; | |
| 49 | ||
| 50 | # --- ha | |
| 51 | ha.cleberg.net http://192.168.0.214:8123; | |
| 52 | ha.zerolabs.sh http://192.168.0.214:8123; | |
| 53 | ||
| 54 | # --- hat | |
| 55 | hat.cleberg.net http://192.168.0.251:3991; | |
| 56 | hat.zerolabs.sh http://192.168.0.251:3991; | |
| 57 | jfrkztgin2ngoj2fnssc2m2j2ycpchmrhzhudaucgvaib5iqwgfxexyd.onion http://192.168.0.251:3991; | |
| 58 | ||
| 59 | # --- irc | |
| 60 | irc.cleberg.net http://127.0.0.1:9900; | |
| 61 | irc.zerolabs.sh http://127.0.0.1:9900; | |
| 62 | ||
| 63 | # --- ld | |
| 64 | ld.cleberg.net http://127.0.0.1:3004; | |
| 65 | ld.zerolabs.sh http://127.0.0.1:3004; | |
| 66 | u3tyzuhs7o4hkizpbcxbm5yqzj74bjqb3phfqfszrx4u75dua7lpf7ad.onion http://127.0.0.1:3004; | |
| 67 | ||
| 68 | # --- lt | |
| 69 | lt.cleberg.net http://127.0.0.1:5000; | |
| 70 | lt.zerolabs.sh http://127.0.0.1:5000; | |
| 71 | nxw6545qeepw2s2kngowsxbcizjcxyimn7dq2bpvr3sqabsu2juj6gyd.onion http://127.0.0.1:5000; | |
| 72 | ||
| 73 | # --- mz | |
| 74 | mz.cleberg.net http://127.0.0.1:3474; | |
| 75 | mz.zerolabs.sh http://127.0.0.1:3474; | |
| 76 | ltawlmsk6vhrig2awwshnduiv45anelx3thepkd6xh4n2s4jxu7wyrid.onion http://127.0.0.1:3474; | |
| 77 | ||
| 78 | # --- paste | |
| 79 | paste.cleberg.net http://127.0.0.1:8084; | |
| 80 | paste.zerolabs.sh http://127.0.0.1:8084; | |
| 81 | ciserod7fbncypo762qcqtowldl3qjhlojfnmguiuvcj3rcyrhqs6ead.onion http://127.0.0.1:8084; | |
| 82 | ||
| 83 | # --- pb | |
| 84 | pb.cleberg.net http://127.0.0.1:8745; | |
| 85 | pb.zerolabs.sh http://127.0.0.1:8745; | |
| 86 | ||
| 87 | # --- photos | |
| 88 | photos.cleberg.net http://127.0.0.1:2283; | |
| 89 | ||
| 90 | # --- pin | |
| 91 | pin.cleberg.net http://127.0.0.1:8086; | |
| 92 | pin.zerolabs.sh http://127.0.0.1:8086; | |
| 93 | 3rtmxu6slammicquf5cpgiptjpzht3n342vh62utoyxchds5r76tadad.onion http://127.0.0.1:8086; | |
| 94 | ||
| 95 | # --- piped | |
| 96 | piped.cleberg.net http://127.0.0.1:8077; | |
| 97 | piped.zerolabs.sh http://127.0.0.1:8077; | |
| 98 | pipedapi.cleberg.net http://127.0.0.1:8077; | |
| 99 | pipedapi.zerolabs.sh http://127.0.0.1:8077; | |
| 100 | pipedproxy.cleberg.net http://127.0.0.1:8077; | |
| 101 | pipedproxy.zerolabs.sh http://127.0.0.1:8077; | |
| 102 | 5ttqjwhhcxh7apxrge5b5cjqceiibrjlqv2hhtmukwfsitbzqk5hh4id.onion http://127.0.0.1:8077; | |
| 103 | ||
| 104 | # --- rd | |
| 105 | rd.cleberg.net http://127.0.0.1:2944; | |
| 106 | rd.zerolabs.sh http://127.0.0.1:2944; | |
| 107 | voyxxivcoupelvedthpbjqsrdhkn4ty7qjurvsif4qbjejnldisqs5ad.onion http://127.0.0.1:2944; | |
| 108 | ||
| 109 | # --- rimgo | |
| 110 | rimgo.cleberg.net http://127.0.0.1:3869; | |
| 111 | rimgo.zerolabs.sh http://127.0.0.1:3869; | |
| 112 | hcj62a4s6ok23oaa4xjnnvabj2aunod3464iuufh2wtehg2th3rwn3yd.onion http://127.0.0.1:3869; | |
| 113 | ||
| 114 | # --- rl | |
| 115 | rl.cleberg.net http://127.0.0.1:8983; | |
| 116 | rl.zerolabs.sh http://127.0.0.1:8983; | |
| 117 | s5wpjol4xe2mszhz4hoqobv4pqmoihb65dz2lbibujjjvhbpjvu45lad.onion http://127.0.0.1:8983; | |
| 118 | ||
| 119 | # --- search | |
| 120 | search.cleberg.net http://127.0.0.1:9191; | |
| 121 | search.zerolabs.sh http://127.0.0.1:9191; | |
| 122 | txwk667ks3vh76r2mfqiot2wdptentsne64nu6qam63zbpzbmhtkvnid.onion http://127.0.0.1:9191; | |
| 123 | ||
| 124 | # --- send | |
| 125 | send.cleberg.net http://192.168.0.251:1443; | |
| 126 | send.zerolabs.sh http://192.168.0.251:1443; | |
| 127 | 6jcf5qh2yg4axi42nbbcijglvoag74z7oq7xikqueebeb5vykj22miqd.onion http://192.168.0.251:1443; | |
| 128 | ||
| 129 | # --- slash | |
| 130 | slash.cleberg.net http://192.168.0.251:5231; | |
| 131 | slash.zerolabs.sh http://192.168.0.251:5231; | |
| 132 | svfj2zs33g572utlou6kx7uamhwen4nxdzvfetnhwjqs4mmdgoayc7qd.onion http://192.168.0.251:5231; | |
| 133 | ||
| 134 | # --- small | |
| 135 | small.cleberg.net http://127.0.0.1:8002; | |
| 136 | small.zerolabs.sh http://127.0.0.1:8002; | |
| 137 | w2qsrbzjmlikhwvbhno3qfdjod53iyzlvzjamcvgkcmtbclmdkqerbqd.onion http://127.0.0.1:8002; | |
| 138 | ||
| 139 | # --- ssh | |
| 140 | ssh.cleberg.net http://127.0.0.1:8169; | |
| 141 | ssh.zerolabs.sh http://127.0.0.1:8169; | |
| 142 | ||
| 143 | # --- wyl (reserved) | |
| 144 | wyl.cleberg.net http://192.168.0.251:8840; | |
| 145 | } | |
linux/nginx/etc/nginx/custom.d/http/content_type_maps.conf added +83
| @@ -0,0 +1,83 @@ | ||
| 1 | # Response header maps (see nginx.conf for context). | |
| 2 | # Add Cache-Control. | |
| 3 | map $sent_http_content_type $cache_control { | |
| 4 | default "public, immutable, stale-while-revalidate"; | |
| 5 | ||
| 6 | # No content | |
| 7 | "" "no-store"; | |
| 8 | ||
| 9 | # Manifest files | |
| 10 | ~*application/manifest\+json "public"; | |
| 11 | ~*text/cache-manifest ""; # `no-cache` (*) | |
| 12 | ||
| 13 | # Assets | |
| 14 | ~*image/svg\+xml "public, immutable, stale-while-revalidate"; | |
| 15 | ||
| 16 | # Data interchange | |
| 17 | ~*application/(atom|rdf|rss)\+xml "public, stale-while-revalidate"; | |
| 18 | ||
| 19 | # Documents | |
| 20 | ~*text/html "private, must-revalidate"; | |
| 21 | ~*text/markdown "private, must-revalidate"; | |
| 22 | ~*text/calendar "private, must-revalidate"; | |
| 23 | ||
| 24 | # Data | |
| 25 | ~*json ""; # `no-cache` (*) | |
| 26 | ~*xml ""; # `no-cache` (*) | |
| 27 | } | |
| 28 | ||
| 29 | # Add X-Frame-Options for HTML documents. | |
| 30 | map $sent_http_content_type $x_frame_options { | |
| 31 | ~*text/html DENY; | |
| 32 | } | |
| 33 | ||
| 34 | # Add Content-Security-Policy for HTML documents. | |
| 35 | map $sent_http_content_type $content_security_policy { | |
| 36 | ~*text/(html|javascript)|application/pdf|xml " | |
| 37 | default-src 'self'; | |
| 38 | img-src 'self' https://img.cleberg.net; | |
| 39 | base-uri 'none'; | |
| 40 | form-action 'self'; | |
| 41 | frame-ancestors 'none'; | |
| 42 | object-src 'none'; | |
| 43 | upgrade-insecure-requests | |
| 44 | "; | |
| 45 | } | |
| 46 | ||
| 47 | # Add Permissions-Policy for HTML documents. | |
| 48 | map $sent_http_content_type $permissions_policy { | |
| 49 | ~*text/(html|javascript)|application/pdf|xml "accelerometer=(),autoplay=(),browsing-topics=(),camera=(),display-capture=(),document-domain=(),encrypted-media=(),fullscreen=(),geolocation=(),gyroscope=(),magnetometer=(),microphone=(),midi=(),payment=(),picture-in-picture=(),publickey-credentials-get=(),screen-wake-lock=(),sync-xhr=(self),usb=(),web-share=(),xr-spatial-tracking=()"; | |
| 50 | } | |
| 51 | ||
| 52 | # Add Referrer-Policy for HTML documents. | |
| 53 | map $sent_http_content_type $referrer_policy { | |
| 54 | ~*text/(css|html|javascript)|application\/pdf|xml "strict-origin-when-cross-origin"; | |
| 55 | } | |
| 56 | ||
| 57 | # Add Cross-Origin-Policies for HTML documents. | |
| 58 | # Cross-Origin-Embedder-Policy | |
| 59 | map $sent_http_content_type $coep_policy { | |
| 60 | ~*text/(html|javascript)|application/pdf|xml "require-corp"; | |
| 61 | } | |
| 62 | # Cross-Origin-Opener-Policy | |
| 63 | map $sent_http_content_type $coop_policy { | |
| 64 | ~*text/(html|javascript)|application/pdf|xml "same-origin"; | |
| 65 | } | |
| 66 | # Cross-Origin-Resource-Policy | |
| 67 | map $sent_http_content_type $corp_policy { | |
| 68 | ~*text/(html|javascript)|application/pdf|xml "same-origin"; | |
| 69 | } | |
| 70 | ||
| 71 | # Add Access-Control-Allow-Origin. | |
| 72 | map $sent_http_content_type $cors { | |
| 73 | # Images | |
| 74 | ~*image/ "*"; | |
| 75 | ||
| 76 | # Web fonts | |
| 77 | ~*font/ "*"; | |
| 78 | ~*application/vnd.ms-fontobject "*"; | |
| 79 | ~*application/x-font-ttf "*"; | |
| 80 | ~*application/font-woff "*"; | |
| 81 | ~*application/x-font-woff "*"; | |
| 82 | ~*application/font-woff2 "*"; | |
| 83 | } | |
linux/nginx/etc/nginx/custom.d/sites/cleberg_net_static_locations.conf added +27
| @@ -0,0 +1,27 @@ | ||
| 1 | location /org/ { | |
| 2 | internal; | |
| 3 | alias /var/www/cleberg.net/org/; | |
| 4 | default_type text/plain; | |
| 5 | add_header Content-Type "text/plain; charset=utf-8"; | |
| 6 | } | |
| 7 | ||
| 8 | location / { | |
| 9 | try_files $uri $uri/ =404; | |
| 10 | } | |
| 11 | ||
| 12 | location /blog/ { | |
| 13 | rewrite ^/blog/((?!index)[^/]+)/(.*)$ /blog/$1.html permanent; | |
| 14 | if ($http_accept ~* "text/markdown") { | |
| 15 | rewrite ^/blog/([^/]+)\.html$ /org/blog/$1.org last; | |
| 16 | } | |
| 17 | } | |
| 18 | ||
| 19 | location ~ ^/([^/]+)\.html$ { | |
| 20 | if ($http_accept ~* "text/markdown") { | |
| 21 | rewrite ^/([^/]+)\.html$ /org/$1.org last; | |
| 22 | } | |
| 23 | try_files $uri =404; | |
| 24 | } | |
| 25 | ||
| 26 | location /atom.xml { return 301 $scheme://$host/feed.xml; } | |
| 27 | location /blog/salary-transparency.html { return 301 $scheme://$host/salary/; } | |
linux/nginx/etc/nginx/custom.d/tls/certificate_files.conf +2 −33
| @@ -1,33 +1,2 @@ | ||
| 1 | # ---------------------------------------------------------------------- | |
| 2 | # | Certificate files | | |
| 3 | # ---------------------------------------------------------------------- | |
| 4 | ||
| 5 | # This default SSL certificate will be served whenever the client lacks support | |
| 6 | # for SNI (Server Name Indication). | |
| 7 | # | |
| 8 | # (1) Certificate and key files location | |
| 9 | # The certificate file can contain an intermediate certificate. | |
| 10 | # | |
| 11 | # https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_certificate | |
| 12 | # | |
| 13 | # (2) Intermediate certificate location if loaded certificate (1) does not | |
| 14 | # contain intermediate certificate when enabling OCSP stapling. | |
| 15 | # | |
| 16 | # https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_trusted_certificate | |
| 17 | # | |
| 18 | # (3) CA certificate file location for client certificate authentication. | |
| 19 | # | |
| 20 | # https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_client_certificate | |
| 21 | ||
| 22 | # (1) | |
| 23 | # ssl_certificate /etc/nginx/certs/default.crt; | |
| 24 | # ssl_certificate_key /etc/nginx/certs/default.key; | |
| 25 | ssl_certificate /etc/letsencrypt/live/cleberg.net/fullchain.pem; | |
| 26 | ssl_certificate_key /etc/letsencrypt/live/cleberg.net/privkey.pem; | |
| 27 | ||
| 28 | # (2) | |
| 29 | # ssl_trusted_certificate /path/to/ca.crt; | |
| 30 | ssl_trusted_certificate /etc/letsencrypt/live/cleberg.net/chain.pem; | |
| 31 | ||
| 32 | # (3) | |
| 33 | # ssl_client_certificate /etc/nginx/default_ssl.crt; | |
| 1 | # Legacy include name: cleberg.net certificate (most zerolabs/cleberg.net vhosts). | |
| 2 | include certificate_files_cleberg_net.conf; | |
linux/nginx/etc/nginx/custom.d/tls/certificate_files_cleberg_dev.conf added +3
| @@ -0,0 +1,3 @@ | ||
| 1 | ssl_certificate /etc/letsencrypt/live/cleberg.dev/fullchain.pem; | |
| 2 | ssl_certificate_key /etc/letsencrypt/live/cleberg.dev/privkey.pem; | |
| 3 | ssl_trusted_certificate /etc/letsencrypt/live/cleberg.dev/chain.pem; | |
linux/nginx/etc/nginx/custom.d/tls/certificate_files_cleberg_io.conf added +3
| @@ -0,0 +1,3 @@ | ||
| 1 | ssl_certificate /etc/letsencrypt/live/cleberg.io/fullchain.pem; | |
| 2 | ssl_certificate_key /etc/letsencrypt/live/cleberg.io/privkey.pem; | |
| 3 | ssl_trusted_certificate /etc/letsencrypt/live/cleberg.io/chain.pem; | |
linux/nginx/etc/nginx/custom.d/tls/certificate_files_cleberg_net.conf added +16
| @@ -0,0 +1,16 @@ | ||
| 1 | # ---------------------------------------------------------------------- | |
| 2 | # | Certificate files — cleberg.net | | |
| 3 | # ---------------------------------------------------------------------- | |
| 4 | ||
| 5 | # This default SSL certificate will be served whenever the client lacks support | |
| 6 | # for SNI (Server Name Indication). | |
| 7 | # | |
| 8 | # (1) Certificate and key files location | |
| 9 | # https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_certificate | |
| 10 | # | |
| 11 | # (2) Intermediate certificate for OCSP stapling | |
| 12 | # https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_trusted_certificate | |
| 13 | ||
| 14 | ssl_certificate /etc/letsencrypt/live/cleberg.net/fullchain.pem; | |
| 15 | ssl_certificate_key /etc/letsencrypt/live/cleberg.net/privkey.pem; | |
| 16 | ssl_trusted_certificate /etc/letsencrypt/live/cleberg.net/chain.pem; | |
linux/nginx/etc/nginx/custom.d/tls/certificate_files_reminiscecleberg_com.conf added +3
| @@ -0,0 +1,3 @@ | ||
| 1 | ssl_certificate /etc/letsencrypt/live/reminiscecleberg.com/fullchain.pem; | |
| 2 | ssl_certificate_key /etc/letsencrypt/live/reminiscecleberg.com/privkey.pem; | |
| 3 | ssl_trusted_certificate /etc/letsencrypt/live/reminiscecleberg.com/chain.pem; | |
linux/nginx/etc/nginx/custom.d/tls/certificate_files_zerolabs_sh.conf added +3
| @@ -0,0 +1,3 @@ | ||
| 1 | ssl_certificate /etc/letsencrypt/live/zerolabs.sh/fullchain.pem; | |
| 2 | ssl_certificate_key /etc/letsencrypt/live/zerolabs.sh/privkey.pem; | |
| 3 | ssl_trusted_certificate /etc/letsencrypt/live/zerolabs.sh/chain.pem; | |
linux/nginx/etc/nginx/nginx.conf +2 −123
| @@ -106,133 +106,12 @@ http { | ||
| 106 | 106 | # Specify file cache expiration. |
| 107 | 107 | include custom.d/web_performance/cache_expiration.conf; |
| 108 | 108 | |
| 109 | # Add Cache-Control. | |
| 110 | # custom.d/web_performance/cache-control.conf | |
| 111 | map $sent_http_content_type $cache_control { | |
| 112 | default "public, immutable, stale-while-revalidate"; | |
| 113 | ||
| 114 | # No content | |
| 115 | "" "no-store"; | |
| 116 | ||
| 117 | # Manifest files | |
| 118 | ~*application/manifest\+json "public"; | |
| 119 | ~*text/cache-manifest ""; # `no-cache` (*) | |
| 120 | ||
| 121 | # Assets | |
| 122 | ~*image/svg\+xml "public, immutable, stale-while-revalidate"; | |
| 123 | ||
| 124 | # Data interchange | |
| 125 | ~*application/(atom|rdf|rss)\+xml "public, stale-while-revalidate"; | |
| 126 | ||
| 127 | # Documents | |
| 128 | ~*text/html "private, must-revalidate"; | |
| 129 | ~*text/markdown "private, must-revalidate"; | |
| 130 | ~*text/calendar "private, must-revalidate"; | |
| 131 | ||
| 132 | # Data | |
| 133 | ~*json ""; # `no-cache` (*) | |
| 134 | ~*xml ""; # `no-cache` (*) | |
| 135 | } | |
| 136 | ||
| 137 | # Add X-Frame-Options for HTML documents. | |
| 138 | # custom.d/security/x-frame-options.conf | |
| 139 | map $sent_http_content_type $x_frame_options { | |
| 140 | ~*text/html DENY; | |
| 141 | } | |
| 142 | ||
| 143 | # Add Content-Security-Policy for HTML documents. | |
| 144 | # custom.d/security/content-security-policy.conf | |
| 145 | map $sent_http_content_type $content_security_policy { | |
| 146 | ~*text/(html|javascript)|application/pdf|xml " | |
| 147 | default-src 'self'; | |
| 148 | img-src 'self' https://img.cleberg.net; | |
| 149 | base-uri 'none'; | |
| 150 | form-action 'self'; | |
| 151 | frame-ancestors 'none'; | |
| 152 | object-src 'none'; | |
| 153 | upgrade-insecure-requests | |
| 154 | "; | |
| 155 | } | |
| 156 | ||
| 157 | # Add Permissions-Policy for HTML documents. | |
| 158 | # custom.d/security/permissions-policy.conf | |
| 159 | map $sent_http_content_type $permissions_policy { | |
| 160 | ~*text/(html|javascript)|application/pdf|xml "accelerometer=(),autoplay=(),browsing-topics=(),camera=(),display-capture=(),document-domain=(),encrypted-media=(),fullscreen=(),geolocation=(),gyroscope=(),magnetometer=(),microphone=(),midi=(),payment=(),picture-in-picture=(),publickey-credentials-get=(),screen-wake-lock=(),sync-xhr=(self),usb=(),web-share=(),xr-spatial-tracking=()"; | |
| 161 | } | |
| 162 | ||
| 163 | # Add Referrer-Policy for HTML documents. | |
| 164 | # custom.d/security/referrer-policy.conf | |
| 165 | map $sent_http_content_type $referrer_policy { | |
| 166 | ~*text/(css|html|javascript)|application\/pdf|xml "strict-origin-when-cross-origin"; | |
| 167 | } | |
| 168 | ||
| 169 | # Add Cross-Origin-Policies for HTML documents. | |
| 170 | # custom.d/security/cross-origin-policy.conf | |
| 171 | # Cross-Origin-Embedder-Policy | |
| 172 | map $sent_http_content_type $coep_policy { | |
| 173 | ~*text/(html|javascript)|application/pdf|xml "require-corp"; | |
| 174 | } | |
| 175 | # Cross-Origin-Opener-Policy | |
| 176 | map $sent_http_content_type $coop_policy { | |
| 177 | ~*text/(html|javascript)|application/pdf|xml "same-origin"; | |
| 178 | } | |
| 179 | # Cross-Origin-Resource-Policy | |
| 180 | map $sent_http_content_type $corp_policy { | |
| 181 | ~*text/(html|javascript)|application/pdf|xml "same-origin"; | |
| 182 | } | |
| 183 | ||
| 184 | # Add Access-Control-Allow-Origin. | |
| 185 | # custom.d/cross-origin/requests.conf | |
| 186 | map $sent_http_content_type $cors { | |
| 187 | # Images | |
| 188 | ~*image/ "*"; | |
| 189 | ||
| 190 | # Web fonts | |
| 191 | ~*font/ "*"; | |
| 192 | ~*application/vnd.ms-fontobject "*"; | |
| 193 | ~*application/x-font-ttf "*"; | |
| 194 | ~*application/font-woff "*"; | |
| 195 | ~*application/x-font-woff "*"; | |
| 196 | ~*application/font-woff2 "*"; | |
| 197 | } | |
| 109 | include custom.d/http/content_type_maps.conf; | |
| 198 | 110 | |
| 199 | 111 | # Fix for onion links |
| 200 | 112 | server_names_hash_bucket_size 128; |
| 201 | 113 | |
| 202 | map $host $backend_address { | |
| 203 | hostnames; | |
| 204 | ||
| 205 | ao.cleberg.net http://127.0.0.1:9380; | |
| 206 | art.cleberg.net http://127.0.0.1:3003; | |
| 207 | auth.cleberg.net http://127.0.0.1:9092; | |
| 208 | br.cleberg.net http://127.0.0.1:3030; | |
| 209 | bt.cleberg.net http://127.0.0.1:9091; | |
| 210 | bw.cleberg.net http://127.0.0.1:10416; | |
| 211 | cc.cleberg.net http://127.0.0.1:8111; | |
| 212 | ddns.cleberg.net http://127.0.0.1:8097; | |
| 213 | gh.cleberg.net http://192.168.0.251:3039; | |
| 214 | ha.cleberg.net http://192.168.0.214:8123; | |
| 215 | hat.cleberg.net http://192.168.0.251:3991; | |
| 216 | irc.cleberg.net http://192.168.0.251:9900; | |
| 217 | ld.cleberg.net http://127.0.0.1:3004; | |
| 218 | lt.cleberg.net http://127.0.0.1:5000; | |
| 219 | mz.cleberg.net http://127.0.0.1:3474; | |
| 220 | paste.cleberg.net http://127.0.0.1:8084; | |
| 221 | pb.cleberg.net http://127.0.0.1:8745; | |
| 222 | photos.cleberg.net http://127.0.0.1:2283; | |
| 223 | pin.cleberg.net http://127.0.0.1:8086; | |
| 224 | piped.cleberg.net http://127.0.0.1:8077; | |
| 225 | rd.cleberg.net http://127.0.0.1:5758; | |
| 226 | rimgo.cleberg.net http://127.0.0.1:3869; | |
| 227 | rl.cleberg.net http://192.168.0.251:8983; | |
| 228 | rss.cleberg.net http://192.168.0.251:8081; | |
| 229 | search.cleberg.net http://127.0.0.1:9191; | |
| 230 | send.cleberg.net http://127.0.0.1:1443; | |
| 231 | slash.cleberg.net http://192.168.0.251:5231; | |
| 232 | small.cleberg.net http://127.0.0.1:8002; | |
| 233 | ssh.cleberg.net http://127.0.0.1:8169; | |
| 234 | wyl.cleberg.net http://192.168.0.251:8840; | |
| 235 | } | |
| 114 | include custom.d/http/backend_address.conf; | |
| 236 | 115 | |
| 237 | 116 | # Include files in the conf.d folder. |
| 238 | 117 | # `server` configuration files should be placed in the conf.d folder. |