multiple changes

This commit is contained in:
root
2021-01-10 08:10:06 +01:00
parent 3db6eadd83
commit 0c02fac0ba
10 changed files with 572 additions and 13 deletions

288
fet.at/2020.conf Normal file
View File

@@ -0,0 +1,288 @@
# -*-nginx-*-
server {
listen 80;
server_name *.2020.fet.at;
include snippets/letsencrypt.conf;
# root /var/www/html
# return 301 https://$host$request_uri;
}
server {
listen 443 ssl http2;
server_name docker.2020.fet.at;
ssl_certificate /etc/letsencrypt/live/2020.fet.at/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/2020.fet.at/privkey.pem;
ssl_trusted_certificate /etc/letsencrypt/live/2020.fet.at/chain.pem;
include snippets/ssl.conf;
include snippets/header.conf;
include snippets/ldap.conf;
client_max_body_size 100M;
location / {
proxy_pass http://fetsite4:9000;
include snippets/proxy_header.conf;
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "upgrade";
# proxy_set_header Authorization "";
# proxy_set_header REMOTE_USER $remote_user;
}
}
server {
listen 443 ssl http2;
server_name solr.2020.fet.at;
ssl_certificate /etc/letsencrypt/live/2020.fet.at/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/2020.fet.at/privkey.pem;
ssl_trusted_certificate /etc/letsencrypt/live/2020.fet.at/chain.pem;
include snippets/ssl.conf;
include snippets/header.conf;
include snippets/ldap.conf;
client_max_body_size 100M;
location / {
proxy_pass http://fetsitedev:8980;
include snippets/proxy_header.conf;
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "upgrade";
# proxy_set_header Authorization "";
# proxy_set_header REMOTE_USER $remote_user;
}
}
server {
listen 443 ssl http2;
server_name bot.2020.fet.at;
ssl_certificate /etc/letsencrypt/live/2020.fet.at/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/2020.fet.at/privkey.pem;
ssl_trusted_certificate /etc/letsencrypt/live/2020.fet.at/chain.pem;
include snippets/ssl.conf;
# include snippets/header.conf;
client_max_body_size 100M;
location / {
include snippets/ldap.conf;
proxy_pass http://fetsitedev:5000;
include snippets/proxy_header.conf;
proxy_http_version 1.1;
proxy_set_header REMOTE_USER $remote_user;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "upgrade";
}
location /income {
proxy_pass http://fetsitedev:5000;
include snippets/proxy_header.conf;
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "upgrade";
}
}
server {
listen 443 ssl http2;
server_name uat1.2020.fet.at;
ssl_certificate /etc/letsencrypt/live/2020.fet.at/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/2020.fet.at/privkey.pem;
ssl_trusted_certificate /etc/letsencrypt/live/2020.fet.at/chain.pem;
include snippets/ssl.conf;
include snippets/header.conf;
client_max_body_size 100M;
location / {
#include snippets/ldap.conf;
proxy_pass http://fetsite4:8001;
include snippets/proxy_header.conf;
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "upgrade";
# proxy_set_header Authorization "";
# proxy_set_header REMOTE_USER $remote_user;
}
location /api {
# deny all;
# allow 192.168.86.1/24;
# allow 128.130.95.200;
proxy_pass http://fetsite4:8001;
include snippets/proxy_header.conf;
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "upgrade";
}
}
server {
listen 443 ssl http2;
server_name etherpad2.2020.fet.at;
ssl_certificate /etc/letsencrypt/live/2020.fet.at/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/2020.fet.at/privkey.pem;
ssl_trusted_certificate /etc/letsencrypt/live/2020.fet.at/chain.pem;
include snippets/ssl.conf;
# include snippets/header.conf;
# include snippets/ldap.conf;
client_max_body_size 1000M;
location / {
proxy_pass http://fetsitedev:80;
include snippets/proxy_header.conf;
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "upgrade";
# proxy_set_header Authorization "";
# proxy_set_header REMOTE_USER $remote_user;
}
}
server {
listen 443 ssl http2;
server_name *.2020.fet.at;
ssl_certificate /etc/letsencrypt/live/2020.fet.at/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/2020.fet.at/privkey.pem;
ssl_trusted_certificate /etc/letsencrypt/live/2020.fet.at/chain.pem;
include snippets/ssl.conf;
# include snippets/header.conf;
client_max_body_size 1000M;
location / {
include snippets/ldap.conf;
proxy_pass http://fetsitedev:80;
include snippets/proxy_header.conf;
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "upgrade";
proxy_set_header Authorization "";
proxy_set_header REMOTE_USER $remote_user;
}
location /api {
satisfy any;
allow 192.168.86.0/24;
allow 128.130.95.206;
allow 128.130.95.200;
include snippets/ldap.conf;
# deny all;
proxy_pass http://fetsitedev:80;
include snippets/proxy_header.conf;
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "upgrade";
proxy_set_header Authorization "";
proxy_set_header REMOTE_USER $remote_user;
}
location /dev {
satisfy any;
allow 192.168.86.0/24;
allow 128.130.95.206;
allow 128.130.95.200;
include snippets/ldap.conf;
# deny all;
proxy_pass http://fetsitedev:80;
include snippets/proxy_header.conf;
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "upgrade";
proxy_set_header Authorization "";
proxy_set_header REMOTE_USER $remote_user;
}
}
server {
listen 443 ssl http2;
server_name patrick.2020.fet.at;
ssl_certificate /etc/letsencrypt/live/2020.fet.at/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/2020.fet.at/privkey.pem;
ssl_trusted_certificate /etc/letsencrypt/live/2020.fet.at/chain.pem;
include snippets/ssl.conf;
# include snippets/header.conf;
client_max_body_size 1000M;
location / {
proxy_pass http://fetsitedev:80;
include snippets/proxy_header.conf;
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "upgrade";
proxy_set_header Authorization "";
proxy_set_header REMOTE_USER $remote_user;
}
location /admin {
proxy_pass http://fetsitedev:80;
include snippets/proxy_header.conf;
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "upgrade";
proxy_set_header Authorization "";
proxy_set_header REMOTE_USER $remote_user;
}
}
server {
listen 443 ssl http2;
server_name alpha.2020.fet.at;
ssl_certificate /etc/letsencrypt/live/2020.fet.at/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/2020.fet.at/privkey.pem;
ssl_trusted_certificate /etc/letsencrypt/live/2020.fet.at/chain.pem;
include snippets/ssl.conf;
# include snippets/header.conf;
# include snippets/ldap.conf;
client_max_body_size 1000M;
location / {
proxy_pass http://fetsite6:8001;
include snippets/proxy_header.conf;
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "upgrade";
proxy_set_header Authorization "";
proxy_set_header REMOTE_USER $remote_user;
}
location /api {
satisfy any;
allow 192.168.86.0/24;
allow 128.130.95.206;
allow 128.130.95.200;
include snippets/ldap.conf;
# deny all;
proxy_pass http://fetsite6:8001;
include snippets/proxy_header.conf;
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "upgrade";
proxy_set_header Authorization "";
proxy_set_header REMOTE_USER $remote_user;
}
}

30
fet.at/2020.prod.conf Normal file
View File

@@ -0,0 +1,30 @@
server {
listen 80;
server_name 2020.fet.at;
include snippets/letsencrypt.conf;
}
server {
listen 443 ssl http2;
server_name 2020.fet.at;
ssl_certificate /etc/letsencrypt/live/moses.2020.fet.at/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/moses.2020.fet.at/privkey.pem;
ssl_trusted_certificate /etc/letsencrypt/live/moses.2020.fet.at/chain.pem;
include snippets/ssl.conf;
include snippets/header.conf;
client_max_body_size 10M;
location /api {
return 403 "Contact bofh@fet.at if you really need to access this";
}
location / {
proxy_pass http://fetsite21:8001;
include snippets/proxy_header.conf;
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "upgrade";
}
}

26
fet.at/baroness.conf Normal file
View File

@@ -0,0 +1,26 @@
# -*-nginx-*-
server {
listen 80;
server_name baroness.fet.at;
include snippets/letsencrypt.conf;
}
server {
listen 443 ssl http2;
server_name baroness.fet.at;
ssl_certificate /etc/letsencrypt/live/baroness.fet.at/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/baroness.fet.at/privkey.pem;
ssl_trusted_certificate /etc/letsencrypt/live/baroness.fet.at/chain.pem;
include snippets/ssl.conf;
include snippets/ldap.conf;
include snippets/header.conf;
location / {
proxy_pass http://baroness;
include snippets/proxy_header.conf;
}
}

View File

@@ -17,7 +17,33 @@ server {
include snippets/header.conf;
location / {
return 302 https://www.fet.at/rubriken/5/neuigkeiten/509;
location / {
return 302 https://www.fet.at/rubriken/5/neuigkeiten/509;
}
location /anwesenheit {
proxy_pass http://proteus;
include snippets/proxy_header.conf;
}
location /da {
proxy_pass http://proteus;
include snippets/proxy_header.conf;
}
location /da/daten {
proxy_pass http://proteus;
include snippets/proxy_header.conf;
include snippets/ldap.conf;
}
location /LVA {
proxy_pass http://proteus;
include snippets/proxy_header.conf;
}
location /LVA/LVAs {
proxy_pass http://proteus;
include snippets/proxy_header.conf;
include snippets/ldap.conf;
}
}

View File

@@ -16,6 +16,7 @@ server {
include snippets/ssl.conf;
include snippets/header.conf;
client_max_body_size 1000M;
location / {
proxy_pass http://zyklon:3000;

View File

@@ -25,13 +25,7 @@ server {
# proxy_redirect https://$host:8000/ https://$host:443/;
include snippets/proxy_header.conf;
}
location /http {
index index.html;
rewrite_log on;
#rewrite ^/http(.*) $1 break;
alias /srv/www/mail/static;
}
location = / {
return 302 https://mail.fet.at/http/;
return 302 https://mail.fet.at/mail;
}
}

29
fet.at/ticket.conf Normal file
View File

@@ -0,0 +1,29 @@
# -*-nginx-*-
server {
listen 80;
server_name ticket.fet.at;
include snippets/letsencrypt.conf;
}
server {
listen 443 ssl http2;
server_name ticket.fet.at;
ssl_certificate /etc/letsencrypt/live/ticket.fet.at/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/ticket.fet.at/privkey.pem;
ssl_trusted_certificate /etc/letsencrypt/live/ticket.fet.at/chain.pem;
include snippets/ssl.conf;
location / {
proxy_pass http://proteus;
include snippets/proxy_header.conf;
}
location /pma {
proxy_pass http://proteus/pma;
include snippets/proxy_header.conf;
include snippets/ldap.conf;
}
}