123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263 |
- ## glowing-bear site config
- server {
- ## Redirect http to https
- listen 80;
- listen [::]:80;
- server_name glow.demu.red;
- return 301 https://$host$request_uri;
- }
- server {
- listen 443 ssl;
- listen [::]:443 ssl;
- server_name glow.demu.red;
- root /var/www/glowing-bear;
- access_log /var/log/nginx/glow_access.log;
- error_log /var/log/nginx/glow_error.log;
- ## Lock Down Access
- #auth_basic "Authorized Access Only";
- #auth_basic_user_file /var/www/glowing-bear/.htpasswd;
- ## Disable all methods besides HEAD, GET and POST.
- if ($request_method !~ ^(GET|HEAD|POST)$ ) {
- return 444;
- }
- index index.html;
- ## Include certbot fix
- include /etc/nginx/snippets/nginx.well-known.conf;
- ## Include ssl
- include /etc/nginx/snippets/nginx.ssl.conf;
- ### Deny Stuffs ### {{{
- ## Protect specific TXT and config files
- location ~ /(\.|readme.html|readme.md|changelog.txt|changelog.md|contributing.txt|contributing.md|license.txt|license.md|legalnotice|privacy.txt|privacy.md|security.txt|security.md|sample-.*txt)
- {
- deny all;
- }
- ## Protect .git files
- location ~ /\.git/ {
- access_log off;
- log_not_found off;
- deny all;
- }
- ### End Deny Stuffs ### }}}
- ## Error Redirects
- error_page 403 /error.html;
- error_page 404 /error.html;
- error_page 405 /error.html;
- error_page 500 501 502 503 504 /error.html;
- location = /error.html {
- root /var/www/error;
- internal;
- }
- }
|