Проект разделен на два репозитория
This commit is contained in:
@@ -0,0 +1,217 @@
|
||||
server {
|
||||
listen 8080;
|
||||
server_name _;
|
||||
location = /nginx-health/live { access_log off; return 200 "ok\n"; }
|
||||
}
|
||||
|
||||
server {
|
||||
listen 80;
|
||||
server_name ${PUBLIC_HOST};
|
||||
location ^~ /.well-known/acme-challenge/ {
|
||||
root /var/www/certbot;
|
||||
default_type text/plain;
|
||||
}
|
||||
location / { return 308 https://$host$request_uri; }
|
||||
}
|
||||
|
||||
server {
|
||||
listen 443 ssl;
|
||||
http2 on;
|
||||
server_name ${PUBLIC_HOST};
|
||||
ssl_certificate ${NGINX_TLS_CERTIFICATE};
|
||||
ssl_certificate_key ${NGINX_TLS_CERTIFICATE_KEY};
|
||||
ssl_protocols TLSv1.2 TLSv1.3;
|
||||
ssl_ciphers HIGH:!aNULL:!MD5:!3DES;
|
||||
ssl_session_cache shared:TLS:10m;
|
||||
ssl_session_timeout 1d;
|
||||
ssl_session_tickets off;
|
||||
|
||||
include /etc/nginx/generated/security-headers.conf;
|
||||
error_page 429 = @rate_limited;
|
||||
|
||||
location @rate_limited {
|
||||
add_header Retry-After "1" always;
|
||||
add_header X-Request-ID $edge_request_id always;
|
||||
include /etc/nginx/generated/security-headers.conf;
|
||||
return 429;
|
||||
}
|
||||
|
||||
location = /nginx-health/live { access_log off; return 200 "ok\n"; }
|
||||
location ^~ /internal/ { return 404; }
|
||||
location ^~ /_internal/ { return 404; }
|
||||
location = /metrics { return 404; }
|
||||
location = /nginx_status { return 404; }
|
||||
location ~* /(?:\.env|docker-compose|config\.(?:json|ya?ml))$ { return 404; }
|
||||
location ~ /\. { return 404; }
|
||||
|
||||
location = /api/v1/realtime {
|
||||
limit_req zone=ws_connect burst=5 nodelay;
|
||||
limit_conn connections 10;
|
||||
include /etc/nginx/snippets/proxy-common.conf;
|
||||
proxy_set_header Upgrade $http_upgrade;
|
||||
proxy_set_header Connection $connection_upgrade;
|
||||
proxy_set_header Sec-WebSocket-Protocol $http_sec_websocket_protocol;
|
||||
proxy_buffering off;
|
||||
proxy_cache off;
|
||||
proxy_read_timeout 90s;
|
||||
proxy_send_timeout 30s;
|
||||
proxy_pass http://api_backend;
|
||||
}
|
||||
|
||||
location ~ ^/api/v1/dialogs/[0-9a-fA-F-]+/messages$ {
|
||||
limit_req zone=api burst=20 nodelay;
|
||||
limit_req zone=polling burst=20 nodelay;
|
||||
include /etc/nginx/snippets/proxy-common.conf;
|
||||
proxy_read_timeout ${NGINX_MESSAGE_READ_TIMEOUT_SEC}s;
|
||||
proxy_pass http://api_backend;
|
||||
}
|
||||
|
||||
location = /api/v1/public/app-config {
|
||||
limit_req zone=public burst=20 nodelay;
|
||||
include /etc/nginx/snippets/proxy-common.conf;
|
||||
proxy_cache public_cache;
|
||||
proxy_cache_methods GET HEAD;
|
||||
proxy_cache_bypass $http_authorization;
|
||||
proxy_no_cache $http_authorization $upstream_http_set_cookie;
|
||||
proxy_cache_valid 200 1h;
|
||||
proxy_pass http://api_backend;
|
||||
}
|
||||
location = /api/v1/public/content {
|
||||
limit_req zone=public burst=20 nodelay;
|
||||
include /etc/nginx/snippets/proxy-common.conf;
|
||||
proxy_cache public_cache;
|
||||
proxy_cache_methods GET HEAD;
|
||||
proxy_cache_bypass $http_authorization;
|
||||
proxy_no_cache $http_authorization $upstream_http_set_cookie;
|
||||
proxy_cache_valid 200 1h;
|
||||
proxy_pass http://api_backend;
|
||||
}
|
||||
location = /api/v1/public/notifications {
|
||||
limit_req zone=notifications_public burst=20 nodelay;
|
||||
include /etc/nginx/snippets/proxy-common.conf;
|
||||
proxy_cache off;
|
||||
proxy_pass http://api_backend;
|
||||
}
|
||||
location = /api/v1/public/notification-types {
|
||||
limit_req zone=notifications_public burst=20 nodelay;
|
||||
include /etc/nginx/snippets/proxy-common.conf;
|
||||
proxy_cache public_cache;
|
||||
proxy_cache_methods GET HEAD;
|
||||
proxy_cache_bypass $http_authorization;
|
||||
proxy_no_cache $http_authorization $upstream_http_set_cookie;
|
||||
proxy_cache_valid 200 1h;
|
||||
proxy_pass http://api_backend;
|
||||
}
|
||||
location ~ ^/api/v1/notifications/[0-9a-fA-F-]+/documents/[0-9a-fA-F-]+/download-url$ {
|
||||
limit_req zone=downloads burst=10 nodelay;
|
||||
include /etc/nginx/snippets/proxy-common.conf;
|
||||
proxy_pass http://api_backend;
|
||||
}
|
||||
location ~ ^/api/v1/notifications/[0-9a-fA-F-]+/(?:read|hide|cta|buttons/[a-z0-9_-]+)$ {
|
||||
limit_req zone=notifications_action burst=20 nodelay;
|
||||
include /etc/nginx/snippets/proxy-common.conf;
|
||||
proxy_pass http://api_backend;
|
||||
}
|
||||
location ~ ^/api/v1/notifications(?:/[0-9a-fA-F-]+|/counter)?$ {
|
||||
limit_req zone=notifications_read burst=30 nodelay;
|
||||
include /etc/nginx/snippets/proxy-common.conf;
|
||||
proxy_pass http://api_backend;
|
||||
}
|
||||
location ~ ^/api/v1/uploads(?:/|$) {
|
||||
limit_req zone=notification_upload burst=10 nodelay;
|
||||
include /etc/nginx/snippets/proxy-common.conf;
|
||||
proxy_pass http://api_backend;
|
||||
}
|
||||
location ~ ^/api/v1/(?:documents|dialogs)/.+/download-url$ {
|
||||
limit_req zone=downloads burst=10 nodelay;
|
||||
include /etc/nginx/snippets/proxy-common.conf;
|
||||
proxy_pass http://api_backend;
|
||||
}
|
||||
location ^~ /api/ {
|
||||
limit_req zone=api burst=30 nodelay;
|
||||
include /etc/nginx/snippets/proxy-common.conf;
|
||||
proxy_pass http://api_backend;
|
||||
}
|
||||
|
||||
location = /auth/callback {
|
||||
root /usr/share/nginx/html;
|
||||
try_files /index.html =404;
|
||||
add_header Cache-Control "no-cache";
|
||||
include /etc/nginx/generated/security-headers.conf;
|
||||
}
|
||||
location ^~ /auth/resources/ {
|
||||
include /etc/nginx/snippets/proxy-keycloak.conf;
|
||||
proxy_pass http://keycloak_upstream;
|
||||
}
|
||||
location = /auth/realms/han-chat/protocol/openid-connect/auth {
|
||||
limit_req zone=auth burst=10;
|
||||
include /etc/nginx/snippets/proxy-keycloak.conf;
|
||||
include /etc/nginx/snippets/proxy-keycloak-captcha-csp.conf;
|
||||
proxy_read_timeout 60s;
|
||||
proxy_pass http://keycloak_upstream;
|
||||
}
|
||||
location = /auth/realms/han-chat/login-actions/authenticate {
|
||||
limit_req zone=auth burst=10;
|
||||
include /etc/nginx/snippets/proxy-keycloak.conf;
|
||||
include /etc/nginx/snippets/proxy-keycloak-captcha-csp.conf;
|
||||
proxy_read_timeout 60s;
|
||||
proxy_pass http://keycloak_upstream;
|
||||
}
|
||||
location ^~ /auth/realms/ {
|
||||
limit_req zone=auth burst=10;
|
||||
include /etc/nginx/snippets/proxy-keycloak.conf;
|
||||
proxy_read_timeout 60s;
|
||||
proxy_pass http://keycloak_upstream;
|
||||
}
|
||||
location /auth/ {
|
||||
limit_req zone=auth burst=10;
|
||||
include /etc/nginx/snippets/proxy-keycloak.conf;
|
||||
proxy_read_timeout 60s;
|
||||
proxy_pass http://keycloak_upstream;
|
||||
}
|
||||
|
||||
location = /callbacks/idgtl/sms {
|
||||
if ($request_method != POST) { return 405; }
|
||||
allow 185.203.96.7;
|
||||
deny all;
|
||||
limit_req zone=sms_callbacks burst=30 nodelay;
|
||||
client_max_body_size 256k;
|
||||
proxy_buffering off;
|
||||
proxy_cache off;
|
||||
include /etc/nginx/snippets/proxy-common.conf;
|
||||
proxy_read_timeout 15s;
|
||||
proxy_pass http://sms_service_upstream;
|
||||
}
|
||||
location ^~ /callbacks/idgtl/ { return 404; }
|
||||
|
||||
location = /bitrix/handler {
|
||||
limit_req zone=bitrix_callbacks burst=60 nodelay;
|
||||
include /etc/nginx/snippets/proxy-common.conf;
|
||||
proxy_read_timeout 60s;
|
||||
proxy_buffering off;
|
||||
proxy_pass http://bitrix_local;
|
||||
}
|
||||
location = /bitrix/install {
|
||||
limit_req zone=bitrix_callbacks burst=30 nodelay;
|
||||
include /etc/nginx/snippets/proxy-common.conf;
|
||||
proxy_read_timeout 60s;
|
||||
proxy_pass http://bitrix_local;
|
||||
}
|
||||
location = /bitrix/placement {
|
||||
limit_req zone=bitrix_callbacks burst=30 nodelay;
|
||||
proxy_http_version 1.1;
|
||||
proxy_set_header Host $host;
|
||||
proxy_set_header X-Real-IP $remote_addr;
|
||||
proxy_set_header X-Forwarded-For $remote_addr;
|
||||
proxy_set_header X-Forwarded-Proto https;
|
||||
proxy_set_header X-Request-ID $edge_request_id;
|
||||
add_header X-Request-ID $edge_request_id always;
|
||||
add_header X-Content-Type-Options "nosniff" always;
|
||||
add_header Referrer-Policy "strict-origin-when-cross-origin" always;
|
||||
add_header Content-Security-Policy "default-src 'self'; frame-ancestors ${BITRIX_FRAME_ANCESTORS}" always;
|
||||
proxy_pass http://bitrix_local;
|
||||
}
|
||||
location ^~ /bitrix/ { return 404; }
|
||||
|
||||
include /etc/nginx/generated/frontend-location.conf;
|
||||
}
|
||||
Reference in New Issue
Block a user