harbor/make/common/templates/nginx/nginx.https.conf

111 lines
3.1 KiB
Plaintext
Raw Normal View History

worker_processes auto;
events {
worker_connections 1024;
use epoll;
multi_accept on;
}
http {
tcp_nodelay on;
2017-03-16 09:09:05 +01:00
include /etc/nginx/conf.d/*.upstream.conf;
# this is necessary for us to be able to disable request buffering in all cases
proxy_http_version 1.1;
upstream registry {
server registry:5000;
}
upstream ui {
server ui:80;
}
2017-03-24 06:16:48 +01:00
log_format timed_combined '$$remote_addr - '
'"$$request" $$status $$body_bytes_sent '
'"$$http_referer" "$$http_user_agent" '
'$$request_time $$upstream_response_time $$pipe';
access_log /dev/stdout timed_combined;
2017-03-24 06:16:48 +01:00
include /etc/nginx/conf.d/*.server.conf;
server {
listen 443 ssl;
2016-10-14 11:13:15 +02:00
# server_name harbordomain.com;
# SSL
2016-10-14 11:13:15 +02:00
ssl_certificate $ssl_cert;
ssl_certificate_key $ssl_cert_key;
# Recommendations from https://raymii.org/s/tutorials/Strong_SSL_Security_On_nginx.html
ssl_protocols TLSv1.1 TLSv1.2;
2016-10-28 12:48:12 +02:00
ssl_ciphers '!aNULL:kECDH+AESGCM:ECDH+AESGCM:RSA+AESGCM:kECDH+AES:ECDH+AES:RSA+AES:';
ssl_prefer_server_ciphers on;
ssl_session_cache shared:SSL:10m;
# disable any limits to avoid HTTP 413 for large image uploads
client_max_body_size 0;
# required to avoid HTTP 411: see Issue #1486 (https://github.com/docker/docker/issues/1486)
chunked_transfer_encoding on;
location / {
proxy_pass http://ui/;
2016-10-14 11:13:15 +02:00
proxy_set_header Host $$http_host;
proxy_set_header X-Real-IP $$remote_addr;
proxy_set_header X-Forwarded-For $$proxy_add_x_forwarded_for;
# When setting up Harbor behind other proxy, such as an Nginx instance, remove the below line if the proxy already has similar settings.
2016-10-14 11:13:15 +02:00
proxy_set_header X-Forwarded-Proto $$scheme;
2016-04-14 12:29:18 +02:00
2016-11-04 17:08:37 +01:00
# Add Secure flag when serving HTTPS
proxy_cookie_path / "/; secure";
proxy_buffering off;
proxy_request_buffering off;
}
location /v1/ {
return 404;
}
location /v2/ {
2017-05-02 13:14:47 +02:00
proxy_pass http://ui/registryproxy/v2/;
2016-10-14 11:13:15 +02:00
proxy_set_header Host $$http_host;
proxy_set_header X-Real-IP $$remote_addr;
proxy_set_header X-Forwarded-For $$proxy_add_x_forwarded_for;
# When setting up Harbor behind other proxy, such as an Nginx instance, remove the below line if the proxy already has similar settings.
2016-10-14 11:13:15 +02:00
proxy_set_header X-Forwarded-Proto $$scheme;
2016-04-14 12:29:18 +02:00
2017-08-04 15:22:22 +02:00
proxy_buffer_size 4k;
proxy_buffers 4 32k;
proxy_busy_buffers_size 64k;
proxy_temp_file_write_size 64k;
}
location /service/ {
proxy_pass http://ui/service/;
2016-10-14 11:13:15 +02:00
proxy_set_header Host $$http_host;
proxy_set_header X-Real-IP $$remote_addr;
proxy_set_header X-Forwarded-For $$proxy_add_x_forwarded_for;
# When setting up Harbor behind other proxy, such as an Nginx instance, remove the below line if the proxy already has similar settings.
2016-10-14 11:13:15 +02:00
proxy_set_header X-Forwarded-Proto $$scheme;
2016-04-14 12:29:18 +02:00
proxy_buffering off;
proxy_request_buffering off;
}
location /service/notifications {
return 404;
}
}
server {
listen 80;
2016-10-14 11:13:15 +02:00
#server_name harbordomain.com;
return 301 https://$$host$$request_uri;
}
}