Skip to content

Commit

Permalink
Update nginx.conf
Browse files Browse the repository at this point in the history
  • Loading branch information
genericdata authored Oct 25, 2024
1 parent 57bafcc commit 36160ce
Showing 1 changed file with 19 additions and 6 deletions.
25 changes: 19 additions & 6 deletions INSTALL/conf/nginx.conf
Original file line number Diff line number Diff line change
@@ -1,18 +1,18 @@
server {
listen 80;
server_name reform.bio.nyu.edu;
rewrite ^ https://$host$request_uri? permanent;
server_name reform.bio.nyu.edu;
rewrite ^ https://$host$request_uri? permanent;
}

server {
listen 443 ssl;
server_name reform.bio.nyu.edu;
ssl_certificate certs/bundle.cer;
ssl_certificate_key certs/reform.bio.nyu.edu.key;
ssl_certificate /etc/pki/tls/certs/reform_bio_nyu_edu_cert.cer;
ssl_certificate_key /etc/pki/tls/private/reform.bio.nyu.edu.key;

ssl_protocols TLSv1.2 TLSv1.3;# Requires nginx >= 1.13.0 else use TLSv1.2
ssl_prefer_server_ciphers on;
ssl_dhparam /etc/nginx/dhparam.pem; # openssl dhparam -out /etc/nginx/dhparam.pem 4096
#ssl_dhparam /etc/nginx/dhparam.pem; # openssl dhparam -out /etc/nginx/dhparam.pem 4096
ssl_ciphers EECDH+AESGCM:EDH+AESGCM;
ssl_ecdh_curve secp384r1; # Requires nginx >= 1.1.0
ssl_session_timeout 10m;
Expand All @@ -28,6 +28,19 @@ server {
add_header X-XSS-Protection "1; mode=block";

location / {
proxy_pass http://127.0.0.1:8000;
proxy_pass http://127.0.0.1:8000;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
}

location /dev {
rewrite ^/dev/?(.*)$ /$1 break;
proxy_pass http://127.0.0.1:9000;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
}
}

0 comments on commit 36160ce

Please sign in to comment.