worker_processes 1; events { worker_connections 1024; } # required for non root pid /tmp/nginx.pid; http { # required for non root client_body_temp_path /tmp/client_temp; proxy_temp_path /tmp/proxy_temp_path; fastcgi_temp_path /tmp/fastcgi_temp; uwsgi_temp_path /tmp/uwsgi_temp; scgi_temp_path /tmp/scgi_temp; # disable server version display server_tokens off; client_max_body_size 1m; # set larger name bucket for large domain names server_names_hash_bucket_size 64; map $status $status_category { "~^(?(?(?[1-5])[0-9])[0-9])$" "$category"; } map $status $status_prefix { "~^(?(?(?[1-5])[0-9])[0-9])$" "$prefix"; } map $server_name $server_domain { "~(?[a-zA-Z0-9-]*)(\.[a-z]*)$" "$domain_name"; } # websocket upgrade mapping map $http_upgrade $connection_upgrade { default upgrade; '' close; } server { listen 8080 default_server; # prevent redirecting to 8080 port # (e.g. when trailing slash is missed) port_in_redirect off; # letsencrypt location /.well-known/acme-challenge/ { root /service/html/certbot; } location /check { # set alias (instead of root) to not append /check to path alias /service/html/check; } location / { return 302 https://$host$request_uri; } } # catch all non domains server { listen 8443 ssl; # prevent redirecting to 8080 port # (e.g. when trailing slash is missed) port_in_redirect off; server_name ""; ssl_certificate /service/ssl/nixdomain/fullchain.pem; ssl_certificate_key /service/ssl/nixdomain/privkey.pem; location / { deny all; return 403; } } # the following variable is automatically populated via entrypoint.sh # }