mirror of
https://github.com/kazu634/nginx-config.git
synced 2025-02-27 21:43:25 +00:00
Update nginx configs.
This commit is contained in:
parent
d2426a28a5
commit
96438d5e0b
@ -1,7 +1,8 @@
|
|||||||
server {
|
server {
|
||||||
# allow access from localhost
|
listen 443 quic reuseport;
|
||||||
listen 443 quic reuseport backlog=1024;
|
listen 443 ssl backlog=1024;
|
||||||
listen 443 http2 ssl backlog=1024;
|
http2 on;
|
||||||
|
http3 on;
|
||||||
server_name blog.kazu634.com;
|
server_name blog.kazu634.com;
|
||||||
|
|
||||||
ssl_certificate /etc/lego/.lego/certificates/_.kazu634.com.crt;
|
ssl_certificate /etc/lego/.lego/certificates/_.kazu634.com.crt;
|
||||||
@ -31,33 +32,10 @@ server {
|
|||||||
access_log /var/log/nginx/blog.access.log json;
|
access_log /var/log/nginx/blog.access.log json;
|
||||||
error_log /var/log/nginx/blog.error.log;
|
error_log /var/log/nginx/blog.error.log;
|
||||||
|
|
||||||
|
large_client_header_buffers 8 32k;
|
||||||
|
|
||||||
location / {
|
location / {
|
||||||
# http2 server push:
|
# used to advertise the availability of HTTP/3
|
||||||
http2_push_preload on;
|
|
||||||
|
|
||||||
http2_push /apple-touch-icon.png;
|
|
||||||
http2_push /lib/normalize/normalize.min.css;
|
|
||||||
http2_push /css/style.min.css;
|
|
||||||
http2_push /lib/lightgallery/lightgallery.min.css;
|
|
||||||
http2_push /lib/katex/katex.min.css;
|
|
||||||
http2_push /lib/katex/copy-tex.min.css;
|
|
||||||
http2_push /lib/mapbox-gl/mapbox-gl.min.css;
|
|
||||||
http2_push /lib/smooth-scroll/smooth-scroll.min.js;
|
|
||||||
http2_push /lib/lazysizes/lazysizes.min.js;
|
|
||||||
http2_push /lib/twemoji/twemoji.min.js;
|
|
||||||
http2_push /lib/lightgallery/lightgallery.min.js;
|
|
||||||
http2_push /lib/lightgallery/lg-zoom.min.js;
|
|
||||||
http2_push /lib/clipboard/clipboard.min.js;
|
|
||||||
http2_push /lib/sharer/sharer.min.js;
|
|
||||||
http2_push /lib/katex/katex.min.js;
|
|
||||||
http2_push /lib/katex/auto-render.min.js;
|
|
||||||
http2_push /lib/katex/copy-tex.min.js;
|
|
||||||
http2_push /lib/katex/mhchem.min.js;
|
|
||||||
http2_push /js/theme.min.js;
|
|
||||||
http2_push https://embedr.flickr.com/assets/client-code.js;
|
|
||||||
http2_push https://platform.twitter.com/widgets.js;
|
|
||||||
|
|
||||||
# used to advertise the availability of HTTP/3
|
|
||||||
add_header Alt-Svc 'h3=":443"; ma=86400';
|
add_header Alt-Svc 'h3=":443"; ma=86400';
|
||||||
|
|
||||||
if (-e "/tmp/maintenance") {
|
if (-e "/tmp/maintenance") {
|
||||||
|
@ -1,6 +1,8 @@
|
|||||||
server {
|
server {
|
||||||
# allow access from localhost
|
listen 443 quic reuseport;
|
||||||
listen 443 ssl http2;
|
listen 443 ssl;
|
||||||
|
http2 on;
|
||||||
|
http3 on;
|
||||||
server_name test.kazu634.com;
|
server_name test.kazu634.com;
|
||||||
|
|
||||||
ssl_certificate /etc/lego/.lego/certificates/_.kazu634.com.crt;
|
ssl_certificate /etc/lego/.lego/certificates/_.kazu634.com.crt;
|
||||||
@ -30,88 +32,12 @@ server {
|
|||||||
access_log /var/log/nginx/stag.access.log json;
|
access_log /var/log/nginx/stag.access.log json;
|
||||||
error_log /var/log/nginx/stag.error.log;
|
error_log /var/log/nginx/stag.error.log;
|
||||||
|
|
||||||
http2_max_field_size 256k;
|
large_client_header_buffers 8 32k;
|
||||||
http2_max_header_size 256k;
|
|
||||||
|
|
||||||
location /oauth2/ {
|
|
||||||
proxy_pass http://127.0.0.1:4180;
|
|
||||||
|
|
||||||
# Configure proxying to auth
|
|
||||||
# proxy_pass_request_body off;
|
|
||||||
# proxy_set_header Content-Length "";
|
|
||||||
proxy_set_header Host $host;
|
|
||||||
# proxy_set_header X-Original-URL $scheme://$http_host$request_uri;
|
|
||||||
# proxy_set_header X-Original-Method $request_method;
|
|
||||||
proxy_set_header X-Real-IP $remote_addr;
|
|
||||||
proxy_set_header X-Scheme $scheme;
|
|
||||||
proxy_set_header X-Auth-Request-Redirect $request_uri;
|
|
||||||
# proxy_http_version 1.1;
|
|
||||||
# proxy_ssl_server_name on;
|
|
||||||
# proxy_pass_request_headers on;
|
|
||||||
# client_max_body_size "1m";
|
|
||||||
|
|
||||||
proxy_buffering on;
|
|
||||||
proxy_buffer_size 256k;
|
|
||||||
proxy_buffers 4 256k;
|
|
||||||
proxy_busy_buffers_size 256k;
|
|
||||||
}
|
|
||||||
|
|
||||||
location = /oauth2/auth {
|
|
||||||
proxy_pass http://127.0.0.1:4180;
|
|
||||||
|
|
||||||
# Configure proxying to auth
|
|
||||||
proxy_pass_request_body off;
|
|
||||||
proxy_set_header Content-Length "";
|
|
||||||
proxy_set_header Host $host;
|
|
||||||
# proxy_set_header X-Original-URL $scheme://$http_host$request_uri;
|
|
||||||
# proxy_set_header X-Original-Method $request_method;
|
|
||||||
# proxy_set_header X-Auth-Request-Redirect $request_uri;
|
|
||||||
proxy_set_header X-Real-IP $remote_addr;
|
|
||||||
proxy_set_header X-Scheme $scheme;
|
|
||||||
client_max_body_size "1m";
|
|
||||||
|
|
||||||
proxy_buffering on;
|
|
||||||
proxy_buffer_size 128k;
|
|
||||||
proxy_buffers 4 256k;
|
|
||||||
proxy_busy_buffers_size 256k;
|
|
||||||
}
|
|
||||||
|
|
||||||
location / {
|
location / {
|
||||||
auth_request /oauth2/auth;
|
auth_basic "限定公開中なのでユーザー名とパスワードを入れてください";
|
||||||
error_page 401 = /oauth2/sign_in;
|
auth_basic_user_file "/etc/nginx/basic-auth";
|
||||||
|
|
||||||
try_files $uri $uri/ /index.html;
|
try_files $uri $uri/ /index.html;
|
||||||
|
|
||||||
auth_request_set $user $upstream_http_x_auth_request_user;
|
|
||||||
auth_request_set $email $upstream_http_x_auth_request_email;
|
|
||||||
proxy_set_header X-User $user;
|
|
||||||
proxy_set_header X-Email $email;
|
|
||||||
|
|
||||||
# if you enabled --pass-access-token, this will pass the token to the backend
|
|
||||||
auth_request_set $token $upstream_http_x_auth_request_access_token;
|
|
||||||
proxy_set_header X-Access-Token $token;
|
|
||||||
|
|
||||||
# if you enabled --cookie-refresh, this is needed for it to work with auth_request
|
|
||||||
auth_request_set $auth_cookie $upstream_http_set_cookie;
|
|
||||||
add_header Set-Cookie $auth_cookie;
|
|
||||||
|
|
||||||
# When using the --set-authorization-header flag, some provider's cookies can exceed the 4kb
|
|
||||||
# limit and so the OAuth2 Proxy splits these into multiple parts.
|
|
||||||
# Nginx normally only copies the first `Set-Cookie` header from the auth_request to the response,
|
|
||||||
# so if your cookies are larger than 4kb, you will need to extract additional cookies manually.
|
|
||||||
auth_request_set $auth_cookie_name_upstream_1 $upstream_cookie_auth_cookie_name_1;
|
|
||||||
|
|
||||||
# Extract the Cookie attributes from the first Set-Cookie header and append them
|
|
||||||
# to the second part ($upstream_cookie_* variables only contain the raw cookie content)
|
|
||||||
if ($auth_cookie ~* "(; .*)") {
|
|
||||||
set $auth_cookie_name_0 $auth_cookie;
|
|
||||||
set $auth_cookie_name_1 "auth_cookie_name_1=$auth_cookie_name_upstream_1$1";
|
|
||||||
}
|
|
||||||
|
|
||||||
# Send both Set-Cookie headers now if there was a second part
|
|
||||||
if ($auth_cookie_name_upstream_1) {
|
|
||||||
add_header Set-Cookie $auth_cookie_name_0;
|
|
||||||
add_header Set-Cookie $auth_cookie_name_1;
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
@ -1,7 +1,8 @@
|
|||||||
server {
|
server {
|
||||||
# allow access from localhost
|
|
||||||
listen 443 quic;
|
listen 443 quic;
|
||||||
listen 443 http2 ssl;
|
listen 443 ssl;
|
||||||
|
http2 on;
|
||||||
|
http3 on;
|
||||||
server_name www.everun.club;
|
server_name www.everun.club;
|
||||||
|
|
||||||
ssl_certificate /etc/lego/.lego/certificates/_.everun.club.crt;
|
ssl_certificate /etc/lego/.lego/certificates/_.everun.club.crt;
|
||||||
@ -46,8 +47,10 @@ server {
|
|||||||
}
|
}
|
||||||
|
|
||||||
server {
|
server {
|
||||||
# allow access from localhost
|
listen 443 quic;
|
||||||
listen 443 ssl http2;
|
listen 443 ssl;
|
||||||
|
http3 on;
|
||||||
|
http2 on;
|
||||||
server_name everun.club;
|
server_name everun.club;
|
||||||
|
|
||||||
ssl_certificate /etc/lego/.lego/certificates/_.everun.club.crt;
|
ssl_certificate /etc/lego/.lego/certificates/_.everun.club.crt;
|
||||||
|
@ -1,6 +1,8 @@
|
|||||||
server {
|
server {
|
||||||
# allow access from localhost
|
listen 443 quic;
|
||||||
listen 443 ssl http2;
|
listen 443 ssl;
|
||||||
|
http2 on;
|
||||||
|
http3 on;
|
||||||
server_name staging.everun.club;
|
server_name staging.everun.club;
|
||||||
|
|
||||||
ssl_certificate /etc/lego/.lego/certificates/_.everun.club.crt;
|
ssl_certificate /etc/lego/.lego/certificates/_.everun.club.crt;
|
||||||
|
Loading…
Reference in New Issue
Block a user