File tree Expand file tree Collapse file tree
roles/user-content-pixel/templates Expand file tree Collapse file tree Original file line number Diff line number Diff line change @@ -15,5 +15,6 @@ docker_container_run_opts: >
1515 -v /etc/nginx/sites-available/:/etc/nginx/sites-enabled/:ro
1616 -v /etc/nginx/ssl/dhparam.pem:/etc/nginx/ssl/dhparam.pem:ro
1717 -v /etc/ssl/certs/{{ domain }}:/etc/ssl/certs/{{ domain }}:ro
18+ -v /etc/ssl/certs/{{ user_content_domain }}:/etc/ssl/certs/{{ user_content_domain }}:ro
1819 -v /etc/ssl/private:/etc/ssl/private:ro
1920 -v /var/log/nginx:/var/log/nginx
Original file line number Diff line number Diff line change 11server {
2- listen 80 ;
2+ listen 443 ssl ;
33 server_name blue.{{ user_content_domain }};
4+ gzip off;
5+
6+ ssl on;
7+ ssl_certificate /etc/ssl/certs/{{ user_content_domain }}/{{ user_content_domain }}.chained.crt;
8+ ssl_certificate_key /etc/ssl/private/{{ user_content_domain }}.key;
9+ ssl_trusted_certificate /etc/ssl/certs/{{ user_content_domain }}/ca.pem;
10+
11+ ssl_session_cache shared:SSL:10m;
12+ ssl_session_timeout 10m;
13+
14+ ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
15+ ssl_ciphers 'EECDH+AESGCM:EDH+AESGCM:AES256+EECDH:AES256+EDH';
16+ ssl_prefer_server_ciphers on;
17+ ssl_dhparam /etc/nginx/ssl/dhparam.pem;
18+
19+ ssl_stapling on;
20+ ssl_stapling_verify on;
21+ resolver 8.8.8.8 8.8.4.4 valid=300s;
22+ resolver_timeout 5s;
423
524 location = /pixel.gif {
625 add_header Set-Cookie "isModerating=1; Domain=.{{ user_content_domain }}; Path=/; HttpOnly; Secure;";
You can’t perform that action at this time.
0 commit comments