Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- upstream subdomain.example {
- server 127.0.0.1:8082;
- server 127.0.0.1:8083;
- server 127.0.0.1:8085;
- server 127.0.0.1:8086;
- server 127.0.0.1:8087;
- server 127.0.0.1:8088;
- server 127.0.0.1:8089;
- server 127.0.0.1:8090;
- }
- server {
- listen subdomain.example.co.uk:80;
- server_name subdomain.example.co.uk;
- return 301 https://$server_name$request_uri;
- }
- server {
- # Allow large uploads
- client_max_body_size 500M;
- listen subdomain.example.co.uk:443;
- # DO NOT EDIT BELOW HERE --------------------------------------------
- ssl on;
- ssl_protocols TLSv1.2;
- ssl_certificate /etc/letsencrypt/live/subdomain.example.co.uk/fullchain.pem; # managed by Certbot
- ssl_certificate_key /etc/letsencrypt/live/subdomain.example.co.uk/privkey.pem; # managed by Certbot
- ssl_ecdh_curve secp384r1;
- ssl_ciphers 'EECDH+AESGCM:EDH+AESGCM:AES256+EECDH:AES256+EDH';
- ssl_prefer_server_ciphers on;
- ssl_dhparam /etc/nginx/ssl/dhparam.pem;
- # DO NOT EDIT ABOVE HERE --------------------------------------------
- # Prevent click jacking.
- add_header X-Frame-Options "SAMEORIGIN";
- # Prevent man-in-middle attacks
- add_header Strict-Transport-Security "max-age=63072000; includeSubdomains; ";
- server_name subdomain.example.co.uk;
- access_log /var/log/nginx/subdomain.example.access.log;
- location /nginx_status {
- access_log off;
- allow 109.169.3.140;
- allow 62.232.230.27;
- allow 127.0.0.1;
- deny all;
- stub_status on;
- }
- location / {
- proxy_pass http://subdomain.example;
- proxy_redirect off;
- proxy_set_header Host $host;
- proxy_set_header X-Real-IP $remote_addr;
- proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
- proxy_pass_request_body on;
- proxy_pass_request_headers on;
- proxy_connect_timeout 300;
- proxy_send_timeout 300;
- proxy_read_timeout 300;
- send_timeout 300;
- # - - - - - - - - - -
- # SERVICE STATUS
- # 'proxy_intercept_errors' needs to be turned on for Error pages to work
- #proxy_intercept_errors on;
- include /etc/nginx/conf.d/service/*.conf;
- # - - - - - - - - - -
- }
- }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement