Deployment-Rules for second server

This commit is contained in:
2026-09-26 11:51:49 +02:00
parent 790e8e1dbc
commit 985c9ce07e
9 changed files with 814 additions and 1 deletions
+54
View File
@@ -0,0 +1,54 @@
# nginx im Container "web" auf endeavour.
# TLS terminiert der KeyHelp-Webserver auf dem Host und reicht per Proxy an 127.0.0.1:8080 weiter.
# Echte Client-IP aus X-Forwarded-For übernehmen, aber nur von Docker-internen Adressen
# (der Proxy auf dem Host erreicht den Container über das Bridge-Gateway).
set_real_ip_from 10.0.0.0/8;
set_real_ip_from 172.16.0.0/12;
set_real_ip_from 192.168.0.0/16;
real_ip_header X-Forwarded-For;
real_ip_recursive on;
server {
listen 80 default_server;
server_name _;
root /var/www/html/public;
index index.php;
server_tokens off;
client_max_body_size 70m;
location / {
try_files $uri $uri/ /index.php?$query_string;
}
# Vite-Assets sind versioniert (Hash im Dateinamen) und dürfen lange gecacht werden.
location /build/assets/ {
expires 1y;
add_header Cache-Control "public, immutable";
access_log off;
try_files $uri =404;
}
location ~ \.php$ {
try_files $uri =404;
fastcgi_split_path_info ^(.+\.php)(/.+)$;
fastcgi_pass app:9000;
fastcgi_index index.php;
include fastcgi_params;
fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;
# Nach außen läuft alles über HTTPS (KeyHelp). So erzeugt Laravel https-URLs,
# ohne dass im App-Code trustProxies gesetzt werden muss.
fastcgi_param HTTPS on;
fastcgi_param REQUEST_SCHEME https;
fastcgi_param SERVER_PORT 443;
fastcgi_read_timeout 300;
}
location ~ /\.(?!well-known) {
deny all;
}
}