diff --git a/config/nginx.conf b/config/nginx.conf index e69de29..b705dca 100644 --- a/config/nginx.conf +++ b/config/nginx.conf @@ -0,0 +1,191 @@ +user nginx; +worker_processes auto; + +error_log /logs/nginx_error; +pid /var/run/nginx.pid; + +events { + worker_connections 1024; +} + +http { + server_names_hash_bucket_size 64; + server_tokens off; + include include.conf; + include /etc/nginx/mime.types; + default_type application/octet-stream; + + # Proxy Cache storage - so we can cache the DoH response from the upstream + proxy_cache_path /var/cache/nginx/doh_cache levels=1:2 keys_zone=doh_cache:10m; + + real_ip_header proxy_protocol; + real_ip_recursive on; + set_real_ip_from 10.10.0.10; + + server { + listen 80 default_server; + + location / { + return 301 https://$host$request_uri; + } + location ~\.well-known { + access_log /logs/nginx_certbot_access; + root /certs/; + try_files $uri =404; + } + } + + server { + listen 10.10.0.2:443 ssl http2 proxy_protocol default_server; + listen 10.10.1.2:443 ssl http2 default_server; + ssl_certificate /certs/self_public; + ssl_certificate_key /certs/self_private; + + access_log /logs/nginx_ip_access; + + location = / { + root /app; + try_files $uri /override.html @auth; + } + + location / { + root /app; + auth_basic "Restricted Content"; + auth_basic_user_file /app/.htpasswd; + try_files $uri =404; + } + location @auth { + root /app; + auth_basic "Restricted Content"; + auth_basic_user_file /app/.htpasswd; + try_files $uri =404; + } + + location /tlgrm { + access_log /logs/nginx_tlgrm_access; + proxy_pass http://php; + } + + location @php { + proxy_pass http://php; + } + + location /adguard/ { + } + + location /webapp { + access_log /logs/nginx_webapp_access; + alias /app; + index index.html; + try_files $uri $uri/ @php; + } + + location /pac { + access_log /logs/nginx_pac_access; + proxy_set_header Host $http_host; + proxy_pass http://php; + } + + location /ws { + proxy_pass http://xr:443; + proxy_redirect off; + proxy_http_version 1.1; + proxy_set_header Upgrade $http_upgrade; + proxy_set_header Connection "upgrade"; + proxy_set_header Host $host; + proxy_set_header X-Real-IP $remote_addr; + proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; + proxy_read_timeout 5d; + } + location /dns-query { + access_log /logs/nginx_doh_access; + proxy_http_version 1.1; + proxy_set_header Connection ""; + proxy_set_header Host $host; + proxy_set_header X-Real-IP $remote_addr; + proxy_set_header X-Forwarded-Proto https; + proxy_set_header X-Forwarded-For $remote_addr; + proxy_set_header X-Forwarded-Host $remote_addr; + proxy_cache doh_cache; + proxy_cache_key $scheme$proxy_host$uri$is_args$args$request_body; + proxy_pass https://ad/dns-query; + } + } + + #~ + + #-domain + # server { + # server_name domain; + # listen 10.10.0.2:443 ssl http2 proxy_protocol; + # listen 10.10.1.2:443 ssl http2; + # ssl_certificate /certs/cert_public; + # ssl_certificate_key /certs/cert_private; + + # access_log /logs/nginx_domain_access; + + # location = / { + # root /app; + # try_files $uri /override.html @auth; + # } + + # location / { + # root /app; + # auth_basic "Restricted Content"; + # auth_basic_user_file /app/.htpasswd; + # try_files $uri =404; + # } + # location @auth { + # root /app; + # auth_basic "Restricted Content"; + # auth_basic_user_file /app/.htpasswd; + # try_files $uri =404; + # } + + # location @php { + # proxy_pass http://php; + # } + + # location /adguard/ { + # } + + # location /webapp { + # access_log /logs/nginx_webapp_access; + # alias /app; + # index index.html; + # try_files $uri $uri/ @php; + # } + + # location /pac { + # access_log /logs/nginx_pac_access; + # proxy_set_header Host $http_host; + # proxy_pass http://php; + # } + + # location /ws { + # proxy_pass http://xr:443; + # proxy_redirect off; + # proxy_http_version 1.1; + # proxy_set_header Upgrade $http_upgrade; + # proxy_set_header Connection "upgrade"; + # proxy_set_header Host $host; + # proxy_set_header X-Real-IP $remote_addr; + # proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; + # proxy_read_timeout 5d; + # } + # location /dns-query { + # access_log /logs/nginx_doh_access; + # proxy_http_version 1.1; + # proxy_set_header Connection ""; + # proxy_set_header Host $host; + # proxy_set_header X-Real-IP $remote_addr; + # proxy_set_header X-Forwarded-Proto https; + # proxy_set_header X-Forwarded-For $remote_addr; + # proxy_set_header X-Forwarded-Host $remote_addr; + # proxy_cache doh_cache; + # proxy_cache_key $scheme$proxy_host$uri$is_args$args$request_body; + # proxy_pass https://ad/dns-query; + # } + # } + #-domain +}