You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
 
 
 
 
 
 

62 regels
2.0 KiB

  1. ServerName {{ FQDN }}
  2. TransferLog /dev/stdout
  3. ErrorLog /dev/stderr
  4. <VirtualHost *:80>
  5. ServerName www.{{ FQDN }}
  6. ServerAlias {{ FQDN }}
  7. # Redirect permanent / https://www.{{ FQDN }}/
  8. Redirect / https://www.{{ FQDN }}/
  9. </VirtualHost>
  10. <VirtualHost *:443>
  11. ServerName {{ FQDN }}
  12. ProxyPass /api/ http://backend:8000/api/
  13. ProxyPassReverse /api/ http://backend:8000/api/
  14. SSLEngine on
  15. SSLCertificateFile {{ SSL_CERTIFICATE_FILE }}
  16. SSLCertificateKeyFile {{ SSL_CERTIFICATE_KEY_FILE }}
  17. </VirtualHost>
  18. <VirtualHost *:443>
  19. ServerName api.{{ FQDN }}
  20. ProxyPass / http://backend:8000/api/
  21. ProxyPassReverse / http://backend:8000/api/
  22. SSLEngine on
  23. SSLCertificateFile {{ SSL_CERTIFICATE_FILE }}
  24. SSLCertificateKeyFile {{ SSL_CERTIFICATE_KEY_FILE }}
  25. </VirtualHost>
  26. <VirtualHost *:443>
  27. ServerName www.{{ FQDN }}
  28. ServerAlias {{ FQDN }}
  29. ProxyPass / http://frontend:8080/
  30. ProxyPassReverse / http://frontend:8080/
  31. SSLEngine on
  32. SSLCertificateFile {{ SSL_CERTIFICATE_FILE }}
  33. SSLCertificateKeyFile {{ SSL_CERTIFICATE_KEY_FILE }}
  34. </VirtualHost>
  35. <VirtualHost *:443>
  36. ServerName profiles.{{ FQDN }}
  37. ProxyPass / http://profiles:8108/
  38. ProxyPassReverse / http://profiles:8108/
  39. SSLEngine on
  40. SSLCertificateFile {{ SSL_CERTIFICATE_FILE }}
  41. SSLCertificateKeyFile {{ SSL_CERTIFICATE_KEY_FILE }}
  42. </VirtualHost>
  43. SSLProtocol all -SSLv3 -TLSv1 -TLSv1.1
  44. SSLCipherSuite ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA384:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256
  45. SSLHonorCipherOrder on
  46. SSLCompression off
  47. SSLSessionTickets off
  48. {% if not DEBUG %}
  49. SSLUseStapling on
  50. SSLStaplingResponderTimeout 5
  51. SSLStaplingReturnResponderErrors off
  52. SSLStaplingCache shmcb:/var/run/ocsp(128000)
  53. {% endif %}