Add MapMil Apache vhost to repo (ca-frontend by name, not IP)

Keeps the reverse-proxy config versioned; hardcoded container IP caused
503 after every stack rebuild.
This commit is contained in:
2026-09-13 20:23:27 +00:00
parent 8e18324f08
commit 396e4ee4b9
2 changed files with 94 additions and 0 deletions
+42
View File
@@ -0,0 +1,42 @@
# ========== HTTPS VirtualHost для mapmil.deepfishing.ru ==========
#
# Источник истины для vhost Apache (контейнер `apache2`).
# Применение: см. deploy/apache/README.md
#
# ВАЖНО: бэкенд адресуется ПО ИМЕНИ `ca-frontend`, а не по IP контейнера.
# IP меняется при каждом пересоздании стека → хардкод IP даёт 503.
# Контейнер `apache2` подключён к сети `mapmil_default`, поэтому имя резолвится.
<VirtualHost *:443>
ServerName mapmil.deepfishing.ru
SSLEngine on
SSLCertificateFile /etc/letsencrypt/live/deepfishing.ru/fullchain.pem
SSLCertificateKeyFile /etc/letsencrypt/live/deepfishing.ru/privkey.pem
SSLProtocol -all +TLSv1.2 +TLSv1.3
SSLCipherSuite ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384
SSLHonorCipherOrder on
SSLCompression off
ProxyPreserveHost On
RequestHeader set X-Forwarded-Proto "https"
RequestHeader set X-Forwarded-Host %{HTTP_HOST}e
AllowEncodedSlashes NoDecode
Header set X-Content-Type-Options "nosniff"
Header set X-XSS-Protection "1; mode=block"
# WebSocket support
RewriteEngine On
RewriteCond %{HTTP:Upgrade} websocket [NC]
RewriteCond %{HTTP:Connection} upgrade [NC]
RewriteRule ^/(.*)$ ws://ca-frontend:80/$1 [P,L]
ProxyPass / http://ca-frontend:80/
ProxyPassReverse / http://ca-frontend:80/
ErrorLog /usr/local/apache2/logs/mapmil-error.log
CustomLog /usr/local/apache2/logs/mapmil-access.log combined
LogLevel warn
</VirtualHost>