Commit 2cd824e0 authored by Pepijn Boers's avatar Pepijn Boers
Browse files

update repo docker-compose

parent e5bec266
......@@ -10,7 +10,7 @@ services:
- app-dnt
volumes:
- ./nginx/nginx.conf:/etc/nginx/nginx.conf:z
- ./matomo/cert-stuff/ssl:/etc/ssl/private:Z
- ./keys:/etc/ssl/private:z
ports:
- 80:80
- 443:443
......
# Main context
worker_processes auto;
error_log logs/error.log;
pid logs/nginx.pid;
events {
# Maximum number of simultaneous connections that can be opened by a worker process.
worker_connections 1000;
}
http {
# Listen to port 80 and redirect to 443 (SSL)
server {
listen 80 default_server;
server_name matomo.science.ru.nl www.matomo.science.ru.nl;
# redirects both www and non-www to https
return 301 https://matomo.science.ru.nl$request_uri;
}
# Listen to port 443 (SSL)
server {
listen 443 ssl;
server_name matomo.science.ru.nl www.matomo.science.ru.nl;
ssl_certificate /etc/ssl/private/matomo.science.ru.nl.crt;
ssl_certificate_key /etc/ssl/private/matomo.science.ru.nl.key;
ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
ssl_ciphers HIGH:!aNULL:!MD5;
# Admin page main Matomo server
location / {
# Set proxy headers to compensate for proxy pipe.
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_set_header Host $http_host;
proxy_set_header X-NginX-Proxy true;
proxy_redirect off;
proxy_pass http://app;
}
# Redirect /dnt to /dnt/ for consistency
location /dnt {
return 302 https://matomo.science.ru.nl/dnt/;
}
# Admin page of second DNT Matomo server
location /dnt/ {
# Set proxy headers to compensate for proxy pipe.
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_set_header Host $http_host;
proxy_set_header X-NginX-Proxy true;
# We do not want to send requests to app-dnt/dnt but to app-dnt/, so rewrite!
rewrite ^/dnt(.*) /$1 break;
proxy_set_header X-Forwarded-Uri "/dnt";
proxy_pass http://app-dnt;
}
# Javascript snippet requests
location /matomo.php {
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_set_header Host $http_host;
proxy_set_header X-NginX-Proxy true;
# mirror request to /mirror
mirror /mirror;
proxy_pass http://app;
}
# Javascript snippet mirror request location
location = /mirror {
internal;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_set_header Host $http_host;
proxy_set_header X-NginX-Proxy true;
# $request_uri is "/something" for url "https://example.com/something"
proxy_pass http://app-dnt$request_uri;
}
}
}
\ No newline at end of file
Markdown is supported
0% or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment