ansible/roles/reverse_proxy_http/templates/nginx/sites-available/reverse_proxy

53 lines
1.2 KiB
Plaintext
Raw Normal View History

2020-10-12 23:02:15 +02:00
{{ ansible_managed | comment }}
include "/etc/nginx/snippets/connection_upgrade.conf";
2020-10-12 23:02:15 +02:00
server {
listen 80;
listen [::]:80;
server_name {{ item.from }};
# Redirect to https
location / {
return 302 https://$host$request_uri;
}
2021-04-05 19:02:21 +02:00
2021-05-11 22:34:24 +02:00
include /etc/nginx/mime.types;
default_type application/octet-stream;
2021-05-12 10:39:18 +02:00
# FLoC you google
add_header Permissions-Policy interest-cohort=();
2021-05-11 22:34:24 +02:00
# "A man is not dead while his name is still spoken." -- Going Postal
add_header X-Clacks-Overhead "GNU {{ ', '.join(in_memoriam) }}";
2020-10-12 23:02:15 +02:00
}
server {
listen 443 ssl http2;
listen [::]:443 ssl http2;
2020-10-13 01:25:02 +02:00
ssl_certificate /etc/nginx/certs/{{ item.from }}.crt;
ssl_certificate_key /etc/nginx/certs/{{ item.from }}.key;
2020-10-12 23:02:15 +02:00
2020-10-13 01:25:02 +02:00
server_name {{ item.from }};
2020-10-12 23:02:15 +02:00
# Logs
access_log /var/log/nginx/{{ item.from }}.log;
error_log /var/log/nginx/{{ item.from }}_error.log;
location / {
proxy_pass {{ item.to }};
include "/etc/nginx/snippets/options-proxypass.conf";
}
2021-04-05 19:02:21 +02:00
2021-05-11 22:34:24 +02:00
include /etc/nginx/mime.types;
default_type application/octet-stream;
2021-05-12 10:39:18 +02:00
# FLoC you google
add_header Permissions-Policy interest-cohort=();
2021-05-11 22:34:24 +02:00
# "A man is not dead while his name is still spoken." -- Going Postal
add_header X-Clacks-Overhead "GNU {{ ', '.join(in_memoriam) }}";
2020-10-12 23:02:15 +02:00
}