ara-infra/roles/website/files/ara.recordsansible.org.conf

53 lines
1.6 KiB
Plaintext

upstream hugo {
server 127.0.0.1:1313;
}
server {
listen 80;
server_name www.getara.org getara.org www.recordsansible.org ara.recordsansible.org;
return 301 https://ara.recordsansible.org$request_uri;
}
server {
listen 443;
server_name ara.recordsansible.org;
ssl on;
ssl_certificate /etc/letsencrypt/live/ara.recordsansible.org/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/ara.recordsansible.org/privkey.pem;
ssl_session_cache shared:SSL:10m;
ssl_session_timeout 10m;
ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
ssl_ciphers HIGH:!aNULL:!MD5;
access_log /var/log/nginx/ara.recordsansible.org_access.log;
error_log /var/log/nginx/ara.recordsansible.org_error.log;
# Media: images, icons, video, audio, HTC
location ~* \.(?:jpg|jpeg|gif|png|ico|cur|gz|svg|mp4|ogg|ogv|webm|htc)$ {
access_log off;
add_header Cache-Control "max-age=2592000";
}
# CSS and Javascript
location ~* \.(?:css|js)$ {
add_header Cache-Control "max-age=2592000";
access_log off;
}
location ^~ {
# checks for static file, if not found proxy to server
try_files $uri @proxy_to_server;
}
location @proxy_to_server {
# Redefine the header fields that NGINX sends to the upstream server
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
# Define the location of the proxy server to send the request to
proxy_pass http://hugo;
}
}