2020-12-06 13:22:54 +01:00
|
|
|
<VirtualHost {{ ansible_default_ipv4.address }}:80 [{{ ansible_default_ipv6.address }}]:80>
|
2020-11-23 16:25:40 +01:00
|
|
|
ServerAdmin {{ server_admin }}
|
|
|
|
ServerName {{ site_name }}
|
|
|
|
ServerAlias {{ site_name }}
|
|
|
|
ErrorLog /var/log/apache2/{{ site_name }}-error.log
|
|
|
|
CustomLog /var/log/apache2/{{ site_name }}-access.log common
|
|
|
|
|
2020-12-04 18:54:21 +01:00
|
|
|
Alias /.well-known/acme-challenge /usr/local/etc/dehydrated/challenge
|
|
|
|
|
2020-11-23 16:25:40 +01:00
|
|
|
<ifmodule mod_rewrite.c>
|
|
|
|
RewriteEngine On
|
|
|
|
RewriteCond %{REQUEST_URI} !^/\.well\-known/acme\-challenge/
|
|
|
|
RewriteRule (.*) https://%{HTTP_HOST}%{REQUEST_URI} [R=301,L]
|
|
|
|
</ifmodule>
|
|
|
|
</VirtualHost>
|
|
|
|
|
2022-07-04 14:01:33 +02:00
|
|
|
<IfFile /usr/local/etc/dehydrated/certs/{{ site_name }}/cert.pem>
|
|
|
|
<IfFile /usr/local/etc/dehydrated/certs/{{ site_name }}/privkey.pem>
|
|
|
|
<IfFile /usr/local/etc/dehydrated/certs/{{ site_name }}/chain.pem>
|
2020-12-06 13:22:54 +01:00
|
|
|
<VirtualHost {{ ansible_default_ipv4.address }}:443 [{{ ansible_default_ipv6.address }}]:443>
|
2020-11-23 16:25:40 +01:00
|
|
|
ServerAdmin {{ server_admin }}
|
|
|
|
ServerName {{ site_name }}
|
|
|
|
ServerAlias {{ site_name }}
|
|
|
|
|
|
|
|
ErrorLog /var/log/apache2/{{ site_name }}-error.log
|
|
|
|
CustomLog /var/log/apache2/{{ site_name }}-access.log common
|
|
|
|
|
|
|
|
SSLEngine on
|
|
|
|
SetEnvIf User-Agent ".*MSIE.*" nokeepalive ssl-unclean-shutdown
|
|
|
|
SSLCertificateFile /usr/local/etc/dehydrated/certs/{{ site_name }}/cert.pem
|
|
|
|
SSLCertificateKeyFile /usr/local/etc/dehydrated/certs/{{ site_name }}/privkey.pem
|
|
|
|
SSLCertificateChainFile /usr/local/etc/dehydrated/certs/{{ site_name }}/chain.pem
|
|
|
|
|
2022-07-01 16:17:24 +02:00
|
|
|
ProxyPass / http://{{ backend_host | default("localhost") }}:{{proxy_port}}/
|
2022-07-04 13:59:13 +02:00
|
|
|
RequestHeader set "X-Forwarded-Proto" expr=%{REQUEST_SCHEME}
|
|
|
|
RequestHeader set "X-Forwarded-SSL" expr=%{HTTPS}
|
|
|
|
|
2022-07-04 14:01:09 +02:00
|
|
|
<ifmodule mod_rewrite.c>
|
|
|
|
# see documentation of wstunnel: This allwos generic websocket passthrough
|
|
|
|
RewriteEngine On
|
|
|
|
RewriteCond %{HTTP:Upgrade} websocket [NC]
|
|
|
|
RewriteCond %{HTTP:Connection} upgrade [NC]
|
|
|
|
RewriteRule ^/?(.*) "ws://{{ backend_host | default("localhost") }}:{{ proxy_port }}/$1" [P,L]
|
|
|
|
</ifmodule>
|
2020-11-23 16:25:40 +01:00
|
|
|
</VirtualHost>
|
2020-12-12 16:26:12 +01:00
|
|
|
</IfFile>
|
2022-07-04 14:01:33 +02:00
|
|
|
</IfFile>
|
|
|
|
</IfFile>
|