Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- server {
- listen 443 ssl;
- #listen 80; #for certs renew
- server_name registry.dev.geen.io;
- ssl_certificate /etc/letsencrypt/live/registry.dev.geen.io/fullchain.pem;
- ssl_certificate_key /etc/letsencrypt/live/registry.dev.geen.io/privkey.pem;
- ssl_protocols TLSv1.1 TLSv1.2;
- ssl_ciphers 'EECDH+AESGCM:EDH+AESGCM:AES256+EECDH:AES256+EDH';
- ssl_prefer_server_ciphers on;
- ssl_session_cache shared:SSL:10m;
- # disable any limits to avoid HTTP 413 for large image uploads
- client_max_body_size 0;
- # required to avoid HTTP 411: see Issue #1486 (https://github.com/docker/docker/issues/1486)
- chunked_transfer_encoding on;
- location '/.well-known/acme-challenge/' {
- default_type "text/plain";
- root /tmp/letsencrypt-auto;
- }
- location /v2/ {
- # Do not allow connections from docker 1.5 and earlier
- # docker pre-1.6.0 did not properly set the user agent on ping, catch "Go *" user agents
- if ($http_user_agent ~ "^(docker\/1\.(3|4|5(?!\.[0-9]-dev))|Go ).*$" ) {
- return 404;
- }
- # To add basic authentication to v2 use auth_basic setting.
- auth_basic "Registry realm";
- auth_basic_user_file /etc/nginx/.htpasswd;
- ## If $docker_distribution_api_version is empty, the header will not be added.
- ## See the map directive above where this variable is defined.
- add_header 'Docker-Distribution-Api-Version' $docker_distribution_api_version always;
- proxy_pass http://docker-registry;
- proxy_set_header Host $http_host; # required for docker client's sake
- proxy_set_header X-Real-IP $remote_addr; # pass on real client's IP
- proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
- proxy_set_header X-Forwarded-Proto $scheme;
- proxy_read_timeout 900;
- }
- }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement