File tree 13 files changed +6
-78
lines changed
ooni-orchestrate/templates
13 files changed +6
-78
lines changed Original file line number Diff line number Diff line change 6
6
group : root
7
7
mode : 0644
8
8
notify : restart nginx
9
-
10
- - name : delete letsencrypt nginx config
11
- file :
12
- state : absent
13
- path : " /etc/nginx/sites-enabled/letsencrypt-http"
14
- notify : restart nginx
Original file line number Diff line number Diff line change 42
42
user : " {{ user_group_id.stdout }}"
43
43
restart_policy : unless-stopped
44
44
45
- - name : delete letsencrypt nginx config
46
- file :
47
- state : absent
48
- path : " /etc/nginx/sites-enabled/letsencrypt-http"
49
- notify : reload nginx
50
45
...
Original file line number Diff line number Diff line change 51
51
- " /srv/github-webhooks:/srv/github-webhooks"
52
52
restart_policy : unless-stopped
53
53
54
- - name : delete letsencrypt nginx config
55
- file :
56
- state : absent
57
- path : " /etc/nginx/sites-enabled/letsencrypt-http"
58
- notify : reload nginx
59
54
...
Original file line number Diff line number Diff line change 2
2
# Generated by ansible
3
3
# roles/letsencrypt/templates/letsencrypt-http
4
4
5
- {% for domain in letsencrypt_domains %}
6
-
7
- # Domain: {{ domain }}
8
5
server {
6
+ # Listen on port 80 for *any* domain
9
7
listen 80;
10
- server_name {{ domain }} ;
8
+ server_name _ ;
11
9
10
+ # Serve ACME challenge from disk
12
11
location /.well-known/acme-challenge {
13
12
root /var/www/letsencrypt;
14
13
try_files $uri $uri/ =404;
15
14
}
15
+
16
+ # Redirect everything else to port 443 regardless of domain
17
+ return 301 https://$host$request_uri;
16
18
}
17
- {% endfor %}
Original file line number Diff line number Diff line change @@ -36,10 +36,4 @@ server {
36
36
location / {
37
37
proxy_pass http://127.0.0.1:{{ bouncer_port }};
38
38
}
39
-
40
- location /.well-known/acme-challenge {
41
- default_type "text/plain";
42
- root /var/www/letsencrypt;
43
- try_files $uri $uri/ =404;
44
- }
45
39
}
Original file line number Diff line number Diff line change @@ -37,10 +37,4 @@ server {
37
37
location / {
38
38
proxy_pass http://127.0.0.1:{{ collector_port }};
39
39
}
40
-
41
- location /.well-known/acme-challenge {
42
- default_type "text/plain";
43
- root /var/www/letsencrypt;
44
- try_files $uri $uri/ =404;
45
- }
46
40
}
Original file line number Diff line number Diff line change 59
59
command : " gunicorn --config python:measurements.gunicorn_config --bind 0.0.0.0:{{ oomsm_backend_port }} --workers 20 --timeout 60 measurements.wsgi"
60
60
# user: "oomsmweb:oomsmweb" XXX-UID
61
61
restart_policy : unless-stopped
62
-
63
- - name : delete letsencrypt nginx config
64
- file :
65
- state : absent
66
- path : " /etc/nginx/sites-enabled/letsencrypt-http"
67
- notify :
68
- - test API nginx config
69
- - reload API nginx
Original file line number Diff line number Diff line change @@ -18,15 +18,3 @@ server {
18
18
proxy_read_timeout 900;
19
19
}
20
20
}
21
-
22
- server {
23
- server_name _;
24
-
25
- listen 80;
26
-
27
- location /.well-known/acme-challenge {
28
- default_type "text/plain";
29
- root /var/www/letsencrypt;
30
- try_files $uri $uri/ =404;
31
- }
32
- }
Original file line number Diff line number Diff line change 48
48
group : root
49
49
mode : 0644
50
50
notify : restart nginx
51
-
52
- - name : delete letsencrypt nginx config
53
- file :
54
- state : absent
55
- path : " /etc/nginx/sites-enabled/letsencrypt-http"
56
- notify : restart nginx
Original file line number Diff line number Diff line change 54
54
group : root
55
55
mode : 0644
56
56
notify : restart nginx
57
-
58
- - name : delete letsencrypt nginx config
59
- file :
60
- state : absent
61
- path : " /etc/nginx/sites-enabled/letsencrypt-http"
62
- notify : restart nginx
Original file line number Diff line number Diff line change 11
11
template : src=probe-services-nginx dest=/etc/nginx/sites-enabled/probe-services
12
12
notify : reload nginx
13
13
14
- - name : delete letsencrypt nginx config
15
- file :
16
- state : absent
17
- path : " /etc/nginx/sites-enabled/letsencrypt-http"
18
- notify : reload nginx
19
-
20
14
- name : mkdir for config and data
21
15
file :
22
16
path : " {{ item }}"
Original file line number Diff line number Diff line change 3
3
{% import 'common.j2' as c %}
4
4
5
5
server {
6
- listen 80;
7
6
listen 443 ssl;
8
7
{{ c.ssl_letsencrypt(probe_services_domain) }}
9
8
Original file line number Diff line number Diff line change 40
40
group : root
41
41
mode : 0644
42
42
notify : restart nginx
43
-
44
- - name : delete letsencrypt nginx config
45
- file :
46
- state : absent
47
- path : " /etc/nginx/sites-enabled/letsencrypt-http"
48
- notify : reload nginx
You can’t perform that action at this time.
0 commit comments