myurls.conf 1.8 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849
  1. server {
  2. listen 80;
  3. server_name s.ops.ci;
  4. return 301 https://s.ops.ci$request_uri;
  5. }
  6. server {
  7. listen 443 ssl;
  8. server_name s.ops.ci;
  9. index index.php index.html index.htm;
  10. gzip on;
  11. ssl_certificate /usr/local/nginx/conf/ssl/ops.ci.cer;
  12. ssl_certificate_key /usr/local/nginx/conf/ssl/ops.ci.key;
  13. ssl_trusted_certificate /usr/local/nginx/conf/ssl/ops.ci.cer;
  14. ssl_stapling on;
  15. ssl_stapling_verify on;
  16. ssl_protocols TLSv1.1 TLSv1.2 TLSv1.3;
  17. ssl_prefer_server_ciphers on;
  18. ssl_ciphers ECDHE-RSA-AES256-GCM-SHA384:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-RSA-AES256-SHA384:ECDHE-RSA-AES128-SHA256:ECDHE-RSA-AES256-SHA:ECDHE-RSA-AES128-SHA:ECDHE-RSA-DES-CBC3-SHA:AES256-GCM-SHA384:AES128-GCM-SHA256:AES256-SHA256:AES128-SHA256:AES256-SHA:AES128-SHA:DES-CBC3-SHA:!aNULL:!eNULL:!EXPORT:!DES:!MD5:!PSK:!RC4;
  19. ssl_ecdh_curve secp384r1;
  20. ssl_session_timeout 10m;
  21. ssl_session_cache builtin:1000 shared:SSL:10m;
  22. ssl_session_tickets off;
  23. resolver 8.8.8.8 8.8.4.4 valid=60s ipv6=off;
  24. resolver_timeout 5s;
  25. add_header Strict-Transport-Security "max-age=63072000" always;
  26. location / {
  27. proxy_redirect off;
  28. proxy_pass http://127.0.0.1:8080;
  29. add_header 'Access-Control-Allow-Origin' '*';
  30. proxy_set_header Host $http_host;
  31. proxy_set_header X-Real-IP $remote_addr;
  32. proxy_set_header X-Forwarded-Ssl on;
  33. proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
  34. proxy_set_header X-Forwarded-Proto $scheme;
  35. proxy_set_header X-Frame-Options SAMEORIGIN;
  36. client_max_body_size 100m;
  37. client_body_buffer_size 128k;
  38. }
  39. access_log /home/wwwlogs/s.ops.ci.access.log main;
  40. error_log /home/wwwlogs/s.ops.ci.error.log warn;
  41. }