diff options
author | Johannes Stoelp <johannes.stoelp@gmail.com> | 2022-12-07 21:48:57 +0100 |
---|---|---|
committer | Johannes Stoelp <johannes.stoelp@gmail.com> | 2022-12-07 21:48:57 +0100 |
commit | 4bdfbf725d977442ab853731f362b6a61ef242df (patch) | |
tree | 03a85ee7f2ebcc465c8c72c62044511c954bbfbe /roles/webserver/files/user_conf.d/memzero.conf | |
parent | abda2021f9a5cdeecdf48d749d5b467aa552da12 (diff) | |
download | ansible-memzero-4bdfbf725d977442ab853731f362b6a61ef242df.tar.gz ansible-memzero-4bdfbf725d977442ab853731f362b6a61ef242df.zip |
baikal: add service and proxy pass
Diffstat (limited to 'roles/webserver/files/user_conf.d/memzero.conf')
-rw-r--r-- | roles/webserver/files/user_conf.d/memzero.conf | 26 |
1 files changed, 26 insertions, 0 deletions
diff --git a/roles/webserver/files/user_conf.d/memzero.conf b/roles/webserver/files/user_conf.d/memzero.conf index 4e709ce..3a9013f 100644 --- a/roles/webserver/files/user_conf.d/memzero.conf +++ b/roles/webserver/files/user_conf.d/memzero.conf @@ -37,6 +37,32 @@ server { } server { + # Listen to port 443 on both IPv4 and IPv6. + listen 443 ssl; + listen [::]:443 ssl; + + # Domain names this server should respond to. + server_name dav.memzero.de; + + # Load the certificate files. + ssl_certificate /etc/letsencrypt/live/memzero/fullchain.pem; + ssl_certificate_key /etc/letsencrypt/live/memzero/privkey.pem; + ssl_trusted_certificate /etc/letsencrypt/live/memzero/chain.pem; + + # Load the Diffie-Hellman parameter. + ssl_dhparam /etc/letsencrypt/dhparams/dhparam.pem; + + location / { + proxy_set_header Host $host; + proxy_set_header X-Real-IP $remote_addr; + proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; + proxy_set_header X-Forwarded-Proto $scheme; + + proxy_pass http://baikal; + } +} + +server { # Drop any request that does not match any of the other server names. listen 443 ssl default_server; ssl_reject_handshake on; |