Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- upstream repository {
- server 192.168.1.70:60080;
- }
- map $http_upgrade $connection_upgrade {
- default upgrade;
- '' close;
- }
- server {
- listen 443 ssl;
- server_name MY_SERVER;
- # SSL
- ssl_certificate file.crt;
- ssl_certificate_key file.key;
- # Recommendations from https://raymii.org/s/tutorials/Strong_SSL_Security_On_nginx.html
- ssl_protocols TLSv1.1 TLSv1.2;
- ssl_ciphers 'EECDH+AESGCM:EDH+AESGCM:AES256+EECDH:AES256+EDH';
- ssl_prefer_server_ciphers on;
- ssl_session_cache shared:SSL:10m;
- location /repository/ {
- proxy_http_version 1.1;
- proxy_set_header Host $http_host; # required for docker client's sake
- proxy_set_header X-Real-IP $remote_addr; # pass on real client's IP
- proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
- proxy_set_header X-Forwarded-Proto $scheme;
- proxy_read_timeout 900;
- proxy_set_header Connection "";
- proxy_buffers 32 4k;
- proxy_pass http://repository/;
- }
- }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement