Created
April 2, 2019 14:48
-
-
Save jonahbohlmann/8f5467ad24107a92aba51b5415c7a5bf to your computer and use it in GitHub Desktop.
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
upstream https_backend__plesk_domain_com { | |
server 10.0.1.11:8443; | |
} | |
server { | |
listen *:80; allow all; | |
server_name reseller.domain.com; | |
location ^~ /.well-known/acme-challenge/ { | |
alias /var/www/acme-challenge/; | |
} | |
if ($host = reseller.domain.com) { | |
return 301 https://$host$request_uri; | |
} | |
} | |
server { | |
ssl on; | |
ssl_certificate /etc/letsencrypt/live/reseller.domain.com/fullchain.pem; # managed by Certbot | |
ssl_certificate_key /etc/letsencrypt/live/reseller.domain.com/privkey.pem; # managed by Certbot | |
ssl_stapling on; | |
ssl_stapling_verify on; | |
listen *:443 ssl http2; allow all; | |
server_name reseller.domain.com; | |
access_log /var/log/nginx/access.log; | |
error_log /var/log/nginx/error.log; | |
location / { | |
send_timeout 3600; | |
proxy_ssl_verify off; | |
proxy_read_timeout 3600; | |
proxy_set_header Host $host; | |
proxy_set_header X-Real-IP $remote_addr; | |
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; | |
proxy_set_header X-LB-Server $hostname; | |
proxy_set_header X-Forwarded-Proto $scheme; | |
proxy_set_header X-SSL 1; | |
proxy_set_header HTTPS ON; | |
proxy_pass https://https_backend__plesk_domain_com; | |
} | |
} |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment