Skip to content

Instantly share code, notes, and snippets.

@chixq
Created January 15, 2014 05:36
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save chixq/8431346 to your computer and use it in GitHub Desktop.
Save chixq/8431346 to your computer and use it in GitHub Desktop.
user nobody;
worker_processes 1;
error_log /var/log/nginx/error.log;
pid /var/run/nginx.pid;
events {
worker_connections 1024;
# multi_accept on;
}
http {
include /etc/nginx/mime.types;
access_log /var/log/nginx/access.log;
sendfile on;
#tcp_nopush on;
#keepalive_timeout 0;
keepalive_timeout 65;
tcp_nodelay on;
#gzip on;
#gzip_disable "MSIE [1-6]\.(?!.*SV1)";
# enable reverse proxy
#proxy_redirect off;
#proxy_set_header Host $http_host;
#proxy_set_header X-Real-IP $remote_addr;
#proxy_set_header X-Forwared-For $proxy_add_x_forwarded_for;
#client_max_body_size 10m;
#client_body_buffer_size 128k;
#client_header_buffer_size 64k;
#proxy_connect_timeout 90;
#proxy_send_timeout 90;
#proxy_read_timeout 90;
#proxy_buffer_size 16k;
#proxy_buffers 32 16k;
#proxy_busy_buffers_size 64k;
# web cluster nodes
# in this setup we have three local application servers
upstream web-cluster {
server 10.101.1.226;
server 10.101.1.150;
hash $request_uri;
}
# force redirect of http to https
# application will be available only over https
server {
listen 80 default;
server_name *.samsungcloud.org;
rewrite ^ https://ops.samsungcloud.org permanent;
}
# https server
# example domain is www.secured.com
# traffic is going to local web servers over normal http
# front nginx proxy server will hold ssl session
server {
listen 443;
server_name ops.samsungcloud.org;
ssl on;
ssl_certificate /etc/ssl/ops.samsungcloud.org.crt;
ssl_certificate_key /etc/ssl/ops.samsungcloud.org.key;
location / {
proxy_pass http://web-cluster;
}
}
}
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment