swee

swee / main.conf nginx.conf

Last active 21 hours ago

Like 0

Revision b4a856ecece87c42071a9e74af327786cddf05dc

main.conf nginx.conf Raw
1map "$request_method:$uri" $var_auth_basic {
2 default "Restricted";
3 ~^GET:/v2/$ "Restricted";
4 ~^GET:.+$ off;
5 ~^HEAD:.+$ off;
6}
7
8server {
9 # Listen
10 listen 443 quic reuseport;
11 listen [::]:443 quic reuseport;
12 listen 443 ssl;
13 listen [::]:443 ssl;
14 listen 80;
15 listen [::]:80;
16 server_name swee.codes;
17
18 # other 101% important nginx stuff
19
20 index index.php index.html index.htm;
21 root /var/www/swee.codes;
22 error_page 404 /errors/404.html;
23 error_page 418 /errors/418.html;
24 error_page 500 /errors/500.html;
25 error_page 502 /errors/502.html;
26
27 # Headers
28 add_header 'Access-Control-Allow-Origin' '*';
29 add_header "Cache-Control" "public, max-age=300";
30 add_header "X-Frame-Policy" "SAMEORIGIN";
31 # TODO: Find a way to fix the header adding without setting it her
32 add_header Alt-Svc 'h3=":443"; ma=86400, h3-29=":443"; ma=86400' always;
33 add_header x-quic 'h3' always;
34 add_header Strict-Transport-Security "max-age=31536000; includeSubDomains; preload" always;
35 add_header Referrer-Policy 'no-referrer' always;
36 add_header X-Content-Type-Options 'nosniff' always;
37 add_header X-Frame-Options 'SAMEORIGIN' always;
38 add_header Content-Security-Policy "frame-src 'self'; img-src *; font-src https://git.swee.codes https://cdn.swee.codes; media-src *; style-src-attr 'unsafe-inline'; style-src-elem 'self' https://cdn.swee.codes 'unsafe-inline'; default-src 'none'" always;
39
40
41 # Upgrade HTTP if required
42 if ($do_upgrade) {
43 return 302 https://$host$request_uri;
44 }
45
46 # Remove this once I'm not paranoid anymore
47 #auth_basic "Work in progress!";
48 #auth_basic_user_file /etc/nginx/htpasswd;
49 #location /paranoia.txt {
50 # auth_basic off;
51 #}
52 #error_page 401 /paranoia.txt;
53
54 # Rewrite PHP if exists
55 location / {
56 if (-e $request_filename.php){
57 rewrite ^/(.*)$ /$1.php;
58 }
59 try_files $uri $uri.html $uri.htm $uri/ /special.php$request_uri;
60 }
61
62 # Fancy directory listings
63 fancyindex on;
64 fancyindex_exact_size off;
65 fancyindex_css_href "https://cdn.swee.codes/assets/fancyindex.css";
66
67 # Handle PHP
68 location ~ \.php(?:$|/) {
69 fastcgi_split_path_info ^(.+\.php)(/.*)$;
70 fastcgi_pass 127.0.0.1:9000;
71 fastcgi_index index.php;
72 fastcgi_param LASTFM_KEY "ef574200571a6bfdf5142b94edd70bbd";
73 include fastcgi_params;
74 include fastcgi.conf;
75 fastcgi_param PATH_INFO $fastcgi_path_info;
76 fastcgi_intercept_errors on;
77 }
78
79 # Block sensitive directories
80 location /.git {
81 return 418;
82 }
83
84 # OCI registry
85 location /v2/ {
86 client_max_body_size 5G;
87 proxy_pass http://127.0.0.1:5678/v2/;
88 proxy_set_header Host $host;
89 proxy_set_header X-Real-IP $remote_addr;
90 proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
91 proxy_set_header X-Forwarded-Proto $scheme;
92 proxy_http_version 1.1;
93 proxy_set_header Connection "";
94 chunked_transfer_encoding off;
95
96 auth_basic $var_auth_basic;
97 auth_basic_user_file /etc/registry/htpasswd;
98 }
99
100 # Proxy matrix client
101
102 location ~ ^/_(matrix|synapse)/client {
103 proxy_pass https://matrix.swee.codes;
104 proxy_set_header X-Forwarded-For $remote_addr;
105 proxy_set_header X-Forwarded-Proto $scheme;
106 proxy_set_header Host $host;
107 proxy_http_version 1.1;
108 }
109
110
111 # Redirect sweetlogo to its repo
112
113 location ~ ^/sweetlogo.(.*)$ {
114 return 301 https://git.swee.codes/swee/sweetlogo/raw/branch/main/sweetlogo.$1;
115 }
116
117 # Redirect uploads to R2
118
119 location ~ ^/uploads/(.*)$ {
120 return 301 https://cdn.swee.codes/uploads/$1;
121 }
122
123 # Redirect apt repo to cdn2
124
125 location ~ ^/apt-repo/(.*)$ {
126 return 301 https://debian.pkg.swee.codes/$1;
127 }
128
129 # TODO: Use this again when chainlink is up
130
131 #location /u/ {
132 #rewrite /u/(.*) /$1 break;
133 #proxy_pass https://u.swee.codes/;
134 #proxy_ssl_server_name on;
135 #proxy_set_header Host u.swee.codes;
136 #}
137
138 # Certbot shit
139
140 ssl_certificate /etc/letsencrypt/live/swee.codes/fullchain.pem; # managed by Certbot
141 ssl_certificate_key /etc/letsencrypt/live/swee.codes/privkey.pem; # managed by Certbot
142 include /etc/letsencrypt/options-ssl-nginx.conf; # managed by Certbot
143 ssl_dhparam /etc/letsencrypt/ssl-dhparams.pem; # managed by Certbot
144}
part of nginx.conf Raw
1 map "$http_upgrade_insecure_requests:$scheme" $do_upgrade {
2 "1:http" 1;
3 default 0;
4 }