Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- server {
- listen 443 ssl;
- server_name artifactory.docker.ac-mpr.ru;
- ssl_certificate /etc/letsencrypt/live/ac-mpr.ru/fullchain.pem;
- ssl_certificate_key /etc/letsencrypt/live/ac-mpr.ru/privkey.pem;
- # Recommendations from https://raymii.org/s/tutorials/Strong_SSL_Security_On_nginx.html
- ssl_protocols TLSv1.1 TLSv1.2;
- ssl_ciphers 'EECDH+AESGCM:EDH+AESGCM:AES256+EECDH:AES256+EDH';
- ssl_prefer_server_ciphers on;
- ssl_session_cache shared:SSL:10m;
- client_max_body_size 0;
- chunked_transfer_encoding on;
- location /v2/ {
- if ($http_user_agent ~ "^(docker\/1\.(3|4|5(?!\.[0-9]-dev))|Go ).*$" ) {
- return 404;
- }
- proxy_pass http://somehost:5001;
- proxy_set_header Host $http_host; # required for docker client's sake
- proxy_set_header X-Real-IP $remote_addr; # pass on real client's IP
- proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
- proxy_set_header X-Forwarded-Proto $scheme;
- proxy_read_timeout 900;
- }
- }
Add Comment
Please, Sign In to add comment