~boringcactus/pig.observer

pig.observer/nginx.conf -rw-r--r-- 2.6 KiB
45af69d8 — Melody Horn containerize it 21 days ago
                                                                                
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
server {
    listen       80;
    listen       [::]:80;
    server_name  pig.observer;

    set $RD "";
    if ($scheme = http) {
        set $RD Y;
    }

    if ($host = pig.observer) {
        set $RD "${RD}Y";
    }

    if ($RD = YY) {
        return 301 https://$host$request_uri;
    }

    add_header Onion-Location http://y4b244ai6krmmd6kjjiptqibjb4rvgf7lpeobhpk3j5vkvhqytt6ulyd.onion$request_uri;

    charset utf-8;
    charset_types text/xml text/css text/plain application/javascript application/rss+xml;
    #access_log  /var/log/nginx/host.access.log  main;
    rewrite_log on;
    
    gzip on;
    add_header Strict-Transport-Security max-age=31536000 always;
    add_header X-Content-Type-Options nosniff;

    location /georgiasnapshots/ {
        add_header  Access-Control-Allow-Origin *;
        proxy_pass  http://navigator-c2c.dot.ga.gov/snapshots/;
    }

    location /georgiavss1/ {
        proxy_pass  http://vss1live.dot.ga.gov/lo/;
    }

    location /georgiavss2/ {
        proxy_pass  http://vss2live.dot.ga.gov/lo/;
    }

    location /georgiavss3/ {
        proxy_pass  http://vss3live.dot.ga.gov/lo/;
    }

    location /georgiavss4/ {
        proxy_pass  http://vss4live.dot.ga.gov/lo/;
    }

    location /georgiavss5/ {
        proxy_pass  http://vss5live.dot.ga.gov/lo/;
    }

    location / {
        root   /usr/share/nginx/html;
        index  index.html index.htm;
    }

    #error_page  404              /404.html;

    # redirect server error pages to the static page /50x.html
    #
    error_page   500 502 503 504  /50x.html;
    location = /50x.html {
        root   /usr/share/nginx/html;
    }

    # proxy the PHP scripts to Apache listening on 127.0.0.1:80
    #
    #location ~ \.php$ {
    #    proxy_pass   http://127.0.0.1;
    #}

    # pass the PHP scripts to FastCGI server listening on 127.0.0.1:9000
    #
    #location ~ \.php$ {
    #    root           html;
    #    fastcgi_pass   127.0.0.1:9000;
    #    fastcgi_index  index.php;
    #    fastcgi_param  SCRIPT_FILENAME  /scripts$fastcgi_script_name;
    #    include        fastcgi_params;
    #}

    # deny access to .htaccess files, if Apache's document root
    # concurs with nginx's one
    #
    #location ~ /\.ht {
    #    deny  all;
    #}


    listen 443 ssl; # managed by Certbot
    listen [::]:443 ssl;
    ssl_certificate /etc/letsencrypt/live/pig.observer/fullchain.pem; # managed by Certbot
    ssl_certificate_key /etc/letsencrypt/live/pig.observer/privkey.pem; # managed by Certbot
    include /etc/letsencrypt/options-ssl-nginx.conf; # managed by Certbot
    ssl_dhparam /etc/letsencrypt/ssl-dhparams.pem; # managed by Certbot

}