Zoey
6548a7aea6
fix stream/allow editing modsec conf/readme changes/dep updates
...
Signed-off-by: Zoey <zoey@z0ey.de >
2023-11-11 19:04:55 +01:00
renovate[bot]
8987ff9c6d
dep updates/header changes/tls changes
...
Signed-off-by: Zoey <zoey@z0ey.de >
- dep updates
- upodate nginx/certbot
- improve headers
- change NPM to NPMplus in launch.sh
- when using https backend, only TLSv1 to TLSv1.3 is now allowed, whith secure ciphers
2023-10-25 22:54:11 +02:00
Zoey
efcca74d67
fix security headers and sockets
...
Signed-off-by: Zoey <zoey@z0ey.de >
2023-10-10 19:55:42 +02:00
Zoey
dec9dc990f
renewer certbot certs after launch/load env from file/listen on socket/disable http in AIO mode
...
Signed-off-by: Zoey <zoey@z0ey.de >
2023-10-10 15:52:14 +02:00
Zoey
fb0bb721f7
rebrand to NPMplus/improve security headers/upsteam changes/dockerlint
...
Signed-off-by: Zoey <zoey@z0ey.de >
2023-10-09 20:32:37 +02:00
Zoey
f3775aad21
merge upstream
...
Signed-off-by: Zoey <zoey@z0ey.de >
2023-08-02 15:02:30 +02:00
Zoey
da025cedaa
Merge branch 'develop-o' into develop
2023-08-02 10:40:13 +02:00
renovate[bot]
cd058f1382
dep updates/nginxbeautifier/fix quic/http3
...
Signed-off-by: Zoey <zoey@z0ey.de >
2023-06-15 22:27:17 +02:00
Zoey
cabf78faa8
support connection drop
...
Inspired by #2942 (original NPM)
2023-05-30 18:29:13 +02:00
Zoey
7e6612467f
add modsec
...
Signed-off-by: Zoey <zoey@z0ey.de >
Update Dockerfile
2023-05-29 20:45:08 +02:00
Will Rouesnel
2dd4434ceb
Add support for nginx 444 default response
...
The default nginx 444 response drops the inbound connection without
sending any response to the client.
2023-05-22 11:59:50 +10:00
renovate[bot]
24db873c34
fix access list/dep updates
...
Update dependency @babel/core to v7.21.5
2023-04-30 15:04:07 +02:00
Zoey
1d9c7b0570
Merge branch 'developo' into develop
2023-03-18 11:30:42 +01:00
Jamie Curnow
fec36834f7
- Updated objection, knex, liquidjs, signale and sqlite3 packages
...
- Changes for objection migration
- Moved common access template code to an include
- Fixed access rules configuration generation
2023-03-17 14:18:51 +10:00
Zoey
bdae896baf
rename ssl to tls/dep updates
...
Signed-off-by: Zoey <zoey@z0ey.de >
Update dependency sqlite3 to v5.1.6
Update dependency style-loader to v3.3.2
Update dependency @babel/core to v7.21.3
2023-03-15 18:41:19 +01:00
Zoey
309e81747e
upstream changes (npm/nginx/dependencies) + add eslint
...
Signed-off-by: Zoey <zoey@z0ey.de >
2023-03-09 20:57:13 +01:00
Zoey
45895ac53e
enable ssl_early_data, default enable http2, option to enable brotli, fix shellcheck
...
Signed-off-by: Zoey <zoey@z0ey.de >
2023-01-26 18:01:25 +01:00
Zoey
e0be3a5ea3
allow to change dummycert
...
Signed-off-by: Zoey <zoey@z0ey.de >
2023-01-14 17:13:17 +01:00
Zoey
5a89e9e8e8
change paths and make quic be enabled sepperat
2023-01-06 18:06:49 +01:00
Zoey
6c56070a46
rebrand SSL to TLS
...
Signed-off-by: Zoey <zoey@z0ey.de >
2023-01-03 01:09:44 +01:00
Zoey
d7db5527d9
changes on ssl
...
Signed-off-by: Zoey <zoey@z0ey.de >
2022-12-31 21:24:54 +01:00
Zoey
920bce627a
add php
...
Signed-off-by: Zoey <zoey@z0ey.de >
2022-12-27 22:44:01 +01:00
Zoey
19a304d9ce
init
...
Signed-off-by: Zoey <zoey@z0ey.de >
2022-12-17 14:25:32 +01:00
jc21
adc5a2020a
Merge pull request #1666 from TobiasKneidl/patch-1
...
Update default.conf to follow the default site setting also for ipv6
2021-12-27 11:03:14 +10:00
Tobias Kneidl
bb422d4454
Update default.conf
2021-12-22 00:24:05 +01:00
chaptergy
1f879f67a9
Reverts back to proxy_pass without variables
2021-11-09 13:57:39 +01:00
Julian Reinhardt
c203d1a0d8
Requires ~() in location to remove $request_uri and removes $request_uri if it is just a slash
2021-11-06 13:38:02 +01:00
Julian Reinhardt
3d80759a21
Renames the $upstream variables and does not append $request_ui if capture group exists in location
2021-11-04 10:08:15 +01:00
Julian Reinhardt
bbde7a108a
Use variable with full uri in proxy pass
2021-10-25 14:48:22 +02:00
Julian Reinhardt
87731a8b5c
Revert "Utilise variable for custom locations proxy_pass"
...
This reverts commit 6c1ae77a2a
.
2021-10-25 14:27:37 +02:00
bergi9
f022e84979
Add SSL and HTTP2 into IPv6 on listen.conf
...
I can only server contents with IPv6 because I'm sitting behind CGN on IPv4. When enabling HTTP2 it still not serve contents with HTTP2 as there are missing arguments in the `listen`. But it still does the SSL encryption.
Previous to this commit it generates:
```
listen 80;
listen [::]:80;
listen 443 ssl http2;
listen [::]:443;
```
Now it generates:
```
listen 80;
listen [::]:80;
listen 443 ssl http2;
listen [::]:443 ssl http2;
```
2021-09-07 22:50:49 +02:00
jc21
ab40e4e2cf
Merge pull request #1036 from BjoernAkAManf/master
...
Allows hostname instead of ip for streams
2021-08-16 13:40:40 +10:00
jc21
66f86cf497
Merge pull request #1258 from nightah/fix-location-proxy_pass
...
Utilise variable for custom locations proxy_pass
2021-08-07 13:03:33 +10:00
chaptergy
d34691152c
Fixes renewal unused http certificates
2021-08-04 14:07:53 +02:00
Amir Zarrinkafsh
6c1ae77a2a
Utilise variable for custom locations proxy_pass
...
If a custom location is currently set to proxy to a DNS hostname this hostname is cached by nginx. When the underlying IP for the hostname changes this will be cached in nginx until it is restarted. This behaviour is somewhat undesirable if utilising containers.
This change sets the proxy_pass for custom locations into a variable and utilises said variable for routing to the upstream backend. This will ensure that nginx will utilise the resolver and resolve the hostname to the current IP instead of relying on the nginx cache.
2021-07-23 16:24:46 +10:00
chaptergy
56c317d223
All logs in single folder
...
nginx cannot create the folder structure for logs
2021-06-29 23:07:54 +02:00
chaptergy
fae848bd1b
Store host logs in subfolders
2021-06-29 20:40:36 +02:00
chaptergy
deca493912
Splits access and error logs for each host
2021-06-18 09:38:48 +02:00
jc21
f575400bc8
Merge pull request #1081 from vipergts450/vipergts450-custom_location-patch
...
Vipergts450 custom location patch
2021-06-07 12:46:23 +10:00
Jamie Curnow
ba45705571
Partial revert of 421934e
...
Keeping the server block of websocket definitions but also bringing back the
location block after discussions on #1067
2021-05-08 12:17:10 +10:00
vipergts450
4c76803f13
Rearrange _location.conf template
...
Allow more of the main host parameters into the custom location configuration and reorder to make more sense.
2021-05-06 22:30:45 -04:00
vipergts450
a3b896fa70
Update _location.conf
2021-05-06 14:48:38 -04:00
vipergts450
60347a90e9
Update _location.conf
2021-05-06 11:40:40 -04:00
Björn Heinrichs
389fd158ad
allows hostname instead of ip for streams
2021-04-24 01:09:01 +02:00
Daniel Porter
421934efed
Move 'Allow Websockets' definitions to host root configuration
...
This fixes issues with these settings not applying to custom locations
defined under hosts.
2021-04-13 20:04:35 +01:00
Daniel Porter
f056b9dc7f
Move 'Force SSL' definitions to host root configuration
...
This fixes issues with these settings not applying to custom locations
defined under hosts.
2021-04-13 19:59:49 +01:00
jc21
74db0004bd
Merge pull request #883 from baruffaldi/master
...
Forward scheme and http code added for redirection hosts
2021-03-17 11:30:26 +10:00
David Dosoudil
1c64252015
Update _hsts.conf template
...
I propose the change to max-age value of HSTS from 1 year to 2 years.
2021-03-13 12:40:47 +00:00
baruffaldi
6df7b72e08
Forward scheme and http code added for redirection hosts
...
You can now configure the forward_scheme and forward_http_code on user interface (section redirection hosts)
2021-02-09 11:23:15 +01:00
Shuro
d1fac583ea
Use configured default page also for IPv6
...
Just a small check for the ipv6 variable, similar to _listen.conf,
so that the configured default page is also delivered on ipv6 requests.
2021-01-25 01:28:50 +01:00