swee

swee / main.conf nginx.conf

Last active 21 hours ago

Like 0

swee revised this gist 21 hours ago · 832d5bc

1 file changed

main.conf nginx.conf renamed to main.conf

File renamed without changes

swee revised this gist 21 hours ago · b4a856e

2 files changed, 148 insertions

main.conf nginx.conf (file created)
@@ -0,0 +1,144 @@
1 + map "$request_method:$uri" $var_auth_basic {
2 + default "Restricted";
3 + ~^GET:/v2/$ "Restricted";
4 + ~^GET:.+$ off;
5 + ~^HEAD:.+$ off;
6 + }
7 +
8 + server {
9 + # Listen
10 + listen 443 quic reuseport;
11 + listen [::]:443 quic reuseport;
12 + listen 443 ssl;
13 + listen [::]:443 ssl;
14 + listen 80;
15 + listen [::]:80;
16 + server_name swee.codes;
17 +
18 + # other 101% important nginx stuff
19 +
20 + index index.php index.html index.htm;
21 + root /var/www/swee.codes;
22 + error_page 404 /errors/404.html;
23 + error_page 418 /errors/418.html;
24 + error_page 500 /errors/500.html;
25 + error_page 502 /errors/502.html;
26 +
27 + # Headers
28 + add_header 'Access-Control-Allow-Origin' '*';
29 + add_header "Cache-Control" "public, max-age=300";
30 + add_header "X-Frame-Policy" "SAMEORIGIN";
31 + # TODO: Find a way to fix the header adding without setting it her
32 + add_header Alt-Svc 'h3=":443"; ma=86400, h3-29=":443"; ma=86400' always;
33 + add_header x-quic 'h3' always;
34 + add_header Strict-Transport-Security "max-age=31536000; includeSubDomains; preload" always;
35 + add_header Referrer-Policy 'no-referrer' always;
36 + add_header X-Content-Type-Options 'nosniff' always;
37 + add_header X-Frame-Options 'SAMEORIGIN' always;
38 + add_header Content-Security-Policy "frame-src 'self'; img-src *; font-src https://git.swee.codes https://cdn.swee.codes; media-src *; style-src-attr 'unsafe-inline'; style-src-elem 'self' https://cdn.swee.codes 'unsafe-inline'; default-src 'none'" always;
39 +
40 +
41 + # Upgrade HTTP if required
42 + if ($do_upgrade) {
43 + return 302 https://$host$request_uri;
44 + }
45 +
46 + # Remove this once I'm not paranoid anymore
47 + #auth_basic "Work in progress!";
48 + #auth_basic_user_file /etc/nginx/htpasswd;
49 + #location /paranoia.txt {
50 + # auth_basic off;
51 + #}
52 + #error_page 401 /paranoia.txt;
53 +
54 + # Rewrite PHP if exists
55 + location / {
56 + if (-e $request_filename.php){
57 + rewrite ^/(.*)$ /$1.php;
58 + }
59 + try_files $uri $uri.html $uri.htm $uri/ /special.php$request_uri;
60 + }
61 +
62 + # Fancy directory listings
63 + fancyindex on;
64 + fancyindex_exact_size off;
65 + fancyindex_css_href "https://cdn.swee.codes/assets/fancyindex.css";
66 +
67 + # Handle PHP
68 + location ~ \.php(?:$|/) {
69 + fastcgi_split_path_info ^(.+\.php)(/.*)$;
70 + fastcgi_pass 127.0.0.1:9000;
71 + fastcgi_index index.php;
72 + fastcgi_param LASTFM_KEY "ef574200571a6bfdf5142b94edd70bbd";
73 + include fastcgi_params;
74 + include fastcgi.conf;
75 + fastcgi_param PATH_INFO $fastcgi_path_info;
76 + fastcgi_intercept_errors on;
77 + }
78 +
79 + # Block sensitive directories
80 + location /.git {
81 + return 418;
82 + }
83 +
84 + # OCI registry
85 + location /v2/ {
86 + client_max_body_size 5G;
87 + proxy_pass http://127.0.0.1:5678/v2/;
88 + proxy_set_header Host $host;
89 + proxy_set_header X-Real-IP $remote_addr;
90 + proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
91 + proxy_set_header X-Forwarded-Proto $scheme;
92 + proxy_http_version 1.1;
93 + proxy_set_header Connection "";
94 + chunked_transfer_encoding off;
95 +
96 + auth_basic $var_auth_basic;
97 + auth_basic_user_file /etc/registry/htpasswd;
98 + }
99 +
100 + # Proxy matrix client
101 +
102 + location ~ ^/_(matrix|synapse)/client {
103 + proxy_pass https://matrix.swee.codes;
104 + proxy_set_header X-Forwarded-For $remote_addr;
105 + proxy_set_header X-Forwarded-Proto $scheme;
106 + proxy_set_header Host $host;
107 + proxy_http_version 1.1;
108 + }
109 +
110 +
111 + # Redirect sweetlogo to its repo
112 +
113 + location ~ ^/sweetlogo.(.*)$ {
114 + return 301 https://git.swee.codes/swee/sweetlogo/raw/branch/main/sweetlogo.$1;
115 + }
116 +
117 + # Redirect uploads to R2
118 +
119 + location ~ ^/uploads/(.*)$ {
120 + return 301 https://cdn.swee.codes/uploads/$1;
121 + }
122 +
123 + # Redirect apt repo to cdn2
124 +
125 + location ~ ^/apt-repo/(.*)$ {
126 + return 301 https://debian.pkg.swee.codes/$1;
127 + }
128 +
129 + # TODO: Use this again when chainlink is up
130 +
131 + #location /u/ {
132 + #rewrite /u/(.*) /$1 break;
133 + #proxy_pass https://u.swee.codes/;
134 + #proxy_ssl_server_name on;
135 + #proxy_set_header Host u.swee.codes;
136 + #}
137 +
138 + # Certbot shit
139 +
140 + ssl_certificate /etc/letsencrypt/live/swee.codes/fullchain.pem; # managed by Certbot
141 + ssl_certificate_key /etc/letsencrypt/live/swee.codes/privkey.pem; # managed by Certbot
142 + include /etc/letsencrypt/options-ssl-nginx.conf; # managed by Certbot
143 + ssl_dhparam /etc/letsencrypt/ssl-dhparams.pem; # managed by Certbot
144 + }
part of nginx.conf (file created)
@@ -0,0 +1,4 @@
1 + map "$http_upgrade_insecure_requests:$scheme" $do_upgrade {
2 + "1:http" 1;
3 + default 0;
4 + }