anapirata.conf 2.3 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293
  1. ## Configuração para anapirata.partidopirata.org
  2. server {
  3. listen 80;
  4. listen [::]:80;
  5. server_name anapirata.partidopirata.org;
  6. root /var/www/www/default/;
  7. index index.php index.html index.htm;
  8. location / {
  9. # proxy_pass http://docker1;
  10. proxy_pass http://entwickler;
  11. proxy_set_header Host $host;
  12. proxy_set_header X-Forwarded-For $remote_addr;
  13. proxy_set_header X-Forwarded-Proto $scheme;
  14. }
  15. location ~ /\.ht {
  16. deny all;
  17. }
  18. }
  19. server {
  20. listen 80;
  21. listen [::]:80;
  22. server_name *.anapirata.partidopirata.org;
  23. return 301 http://anapirata.partidopirata.org$request_uri;
  24. }
  25. ## SSL
  26. server {
  27. listen 443 ssl;
  28. listen [::]:443 ssl;
  29. ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
  30. ssl_prefer_server_ciphers on;
  31. ssl_ciphers "EECDH+AESGCM:EDH+AESGCM:AES256+EECDH:AES256+EDH";
  32. ssl_ecdh_curve secp384r1;
  33. ssl_session_cache shared:SSL:10m;
  34. ssl_session_tickets off;
  35. ssl_stapling on;
  36. ssl_stapling_verify on;
  37. resolver 208.67.220.220 208.67.222.222 valid=300s;
  38. resolver_timeout 5s;
  39. add_header Strict-Transport-Security "max-age=63072000; includeSubdomains; preload";
  40. add_header X-Frame-Options SAMEORIGIN;
  41. add_header X-Content-Type-Options nosniff;
  42. ssl_certificate /etc/letsencrypt/live/partidopirata.org/fullchain.pem;
  43. ssl_certificate_key /etc/letsencrypt/live/partidopirata.org/privkey.pem;
  44. ssl_trusted_certificate /etc/letsencrypt/live/partidopirata.org/chain.pem;
  45. server_name anapirata.partidopirata.org;
  46. root /var/www/www/default/;
  47. index index.php index.html index.htm;
  48. location / {
  49. ## TODO: Configurar SSL nos upstreams
  50. # proxy_pass http://docker1;
  51. proxy_pass http://entwickler;
  52. proxy_set_header Host $host;
  53. proxy_set_header X-Forwarded-For $remote_addr;
  54. proxy_set_header X-Forwarded-Proto $scheme;
  55. }
  56. location ~ /\.ht {
  57. deny all;
  58. }
  59. }
  60. ## Tor
  61. #server {
  62. # listen 127.0.0.1:42981;
  63. # allow 127.0.0.1;
  64. # deny all;
  65. #
  66. # add_header X-Frame-Options SAMEORIGIN;
  67. # add_header X-Content-Type-Options nosniff;
  68. #
  69. # server_name ana5s26zq5enf6ov.onion;
  70. #
  71. # root /var/www/www/default/;
  72. #
  73. # index index.php index.html index.htm;
  74. #
  75. # location / {
  76. # ## TODO: Configurar SSL nos upstreams
  77. # proxy_pass http://docker1;
  78. # proxy_set_header Host $host;
  79. # proxy_set_header X-Forwarded-For $remote_addr;
  80. # proxy_set_header X-Forwarded-Proto $scheme;
  81. # }
  82. # location ~ /\.ht {
  83. # deny all;
  84. # }
  85. #}