|
|
@@ -0,0 +1,50 @@
|
|
|
+# git service
|
|
|
+
|
|
|
+server {
|
|
|
+ server_name git.zhixinghe1.top;
|
|
|
+
|
|
|
+ gzip on;
|
|
|
+
|
|
|
+
|
|
|
+ location / {
|
|
|
+ proxy_redirect off;
|
|
|
+ proxy_pass http://localhost:10880;
|
|
|
+
|
|
|
+ proxy_set_header Host $http_host;
|
|
|
+ proxy_set_header X-Real-IP $remote_addr;
|
|
|
+ proxy_set_header X-Forwarded-Ssl on;
|
|
|
+ proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
|
|
+ proxy_set_header X-Forwarded-Proto $scheme;
|
|
|
+ proxy_set_header X-Frame-Options SAMEORIGIN;
|
|
|
+
|
|
|
+ client_max_body_size 100m;
|
|
|
+ client_body_buffer_size 128k;
|
|
|
+
|
|
|
+ proxy_buffer_size 4k;
|
|
|
+ proxy_buffers 4 32k;
|
|
|
+ proxy_busy_buffers_size 64k;
|
|
|
+ proxy_temp_file_write_size 64k;
|
|
|
+
|
|
|
+ }
|
|
|
+
|
|
|
+ listen 443 ssl; # managed by Certbot
|
|
|
+ ssl_certificate /etc/letsencrypt/live/git.zhixinghe1.top/fullchain.pem; # managed by Certbot
|
|
|
+ ssl_certificate_key /etc/letsencrypt/live/git.zhixinghe1.top/privkey.pem; # managed by Certbot
|
|
|
+ include /etc/letsencrypt/options-ssl-nginx.conf; # managed by Certbot
|
|
|
+ ssl_dhparam /etc/letsencrypt/ssl-dhparams.pem; # managed by Certbot
|
|
|
+
|
|
|
+}
|
|
|
+
|
|
|
+
|
|
|
+server {
|
|
|
+ if ($host = git.zhixinghe1.top) {
|
|
|
+ return 301 https://$host$request_uri;
|
|
|
+ } # managed by Certbot
|
|
|
+
|
|
|
+
|
|
|
+ listen 80;
|
|
|
+ server_name git.zhixinghe1.top;
|
|
|
+ return 404; # managed by Certbot
|
|
|
+
|
|
|
+
|
|
|
+}
|