Gitea Actions Runner Test / test-job (push) Successful in 0s
CI / check (push) Successful in 30s
CI / tests-integration (push) Successful in 1m51s
CI / tests-unit (push) Successful in 1m54s
CI / tests-ui (push) Successful in 2m44s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 20s
- cloudflare-ips.conf (new): geo $cms_trusted_edge + set_real_ip_from from live CF IPv4/IPv6 ranges plus Traefik bridge and loopback - nginx-cms.conf: forward real client IP only from trusted peers, strip incoming CF-Connecting-IP, 403 any other peer that presents one (spoof gate); direct game clients on :9443 stay unaffected - cf-ips-sync.sh (new): fetch cloudflare.com/ips-v4/-v6, regenerate the nginx snippet and Traefik websecure.forwardedHeaders.trustedIPs - nginx-sync.sh: install the cloudflare-ips.conf snippet - cms_upstream_servers.conf: point default at the live green slot 3003
55 lines
1.9 KiB
Nginx Configuration File
55 lines
1.9 KiB
Nginx Configuration File
# Canonical nginx config for the EpicNabbo CMS edge.
|
|
# Source of truth: repository deployment/proxy/nginx-cms.conf (the site block)
|
|
# and this file. Installed/synced by scripts/nginx-sync.sh so it cannot be
|
|
# lost again while nginx keeps running on an in-memory copy.
|
|
#
|
|
# Traffic path: Cloudflare -> Traefik (:443) -> nginx (:9443) -> CMS (:3002),
|
|
# with direct Cloudflare-origin and game-client (ws.epicnabbo.nl) connections
|
|
# also terminating on :9443.
|
|
# nginx is the last layer that can still rewrite Cache-Control, so it owns the
|
|
# headers it adds explicitly; everything proxied to the CMS is passed through
|
|
# untouched unless this file says otherwise.
|
|
|
|
user www-data;
|
|
worker_processes auto;
|
|
pid /run/nginx.pid;
|
|
|
|
error_log /var/log/nginx/error.log warn;
|
|
|
|
events {
|
|
worker_connections 2048;
|
|
use epoll;
|
|
}
|
|
|
|
http {
|
|
include /etc/nginx/mime.types;
|
|
default_type application/octet-stream;
|
|
|
|
# Compression is done once, at the edge (Traefik / Cloudflare). Enabling
|
|
# gzip here too would double-compress proxied responses and fight Vary.
|
|
gzip off;
|
|
|
|
sendfile on;
|
|
tcp_nopush on;
|
|
server_tokens off;
|
|
keepalive_timeout 30s;
|
|
|
|
client_max_body_size 64m;
|
|
client_body_buffer_size 16k;
|
|
client_header_buffer_size 1k;
|
|
large_client_header_buffers 4 8k;
|
|
|
|
# Blue/green cutover: ci-deploy.sh writes the active upstream here, and
|
|
# `proxy_pass http://cms_app` below follows it via graceful nginx -s reload.
|
|
upstream cms_app {
|
|
include /etc/nginx/snippets/cms_upstream_servers.conf;
|
|
}
|
|
|
|
# Cache policy maps and server blocks live in the site file so they are
|
|
# synced together and can never drift apart.
|
|
include /etc/nginx/sites-enabled/*.conf;
|
|
|
|
# Trusted edge / real-IP handling (regenerated by scripts/cf-ips-sync.sh
|
|
# from the live Cloudflare ranges; installed via scripts/nginx-sync.sh).
|
|
include /etc/nginx/conf.d/cloudflare-ips.conf;
|
|
} |