Deployment-Rules for second server
This commit is contained in:
@@ -0,0 +1,54 @@
|
||||
# nginx im Container "web" auf endeavour.
|
||||
# TLS terminiert der KeyHelp-Webserver auf dem Host und reicht per Proxy an 127.0.0.1:8080 weiter.
|
||||
|
||||
# Echte Client-IP aus X-Forwarded-For übernehmen, aber nur von Docker-internen Adressen
|
||||
# (der Proxy auf dem Host erreicht den Container über das Bridge-Gateway).
|
||||
set_real_ip_from 10.0.0.0/8;
|
||||
set_real_ip_from 172.16.0.0/12;
|
||||
set_real_ip_from 192.168.0.0/16;
|
||||
real_ip_header X-Forwarded-For;
|
||||
real_ip_recursive on;
|
||||
|
||||
server {
|
||||
listen 80 default_server;
|
||||
server_name _;
|
||||
|
||||
root /var/www/html/public;
|
||||
index index.php;
|
||||
|
||||
server_tokens off;
|
||||
client_max_body_size 70m;
|
||||
|
||||
location / {
|
||||
try_files $uri $uri/ /index.php?$query_string;
|
||||
}
|
||||
|
||||
# Vite-Assets sind versioniert (Hash im Dateinamen) und dürfen lange gecacht werden.
|
||||
location /build/assets/ {
|
||||
expires 1y;
|
||||
add_header Cache-Control "public, immutable";
|
||||
access_log off;
|
||||
try_files $uri =404;
|
||||
}
|
||||
|
||||
location ~ \.php$ {
|
||||
try_files $uri =404;
|
||||
fastcgi_split_path_info ^(.+\.php)(/.+)$;
|
||||
fastcgi_pass app:9000;
|
||||
fastcgi_index index.php;
|
||||
include fastcgi_params;
|
||||
fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;
|
||||
|
||||
# Nach außen läuft alles über HTTPS (KeyHelp). So erzeugt Laravel https-URLs,
|
||||
# ohne dass im App-Code trustProxies gesetzt werden muss.
|
||||
fastcgi_param HTTPS on;
|
||||
fastcgi_param REQUEST_SCHEME https;
|
||||
fastcgi_param SERVER_PORT 443;
|
||||
|
||||
fastcgi_read_timeout 300;
|
||||
}
|
||||
|
||||
location ~ /\.(?!well-known) {
|
||||
deny all;
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user