Add MapMil Apache vhost to repo (ca-frontend by name, not IP)
Keeps the reverse-proxy config versioned; hardcoded container IP caused 503 after every stack rebuild.
This commit is contained in:
@@ -0,0 +1,42 @@
|
||||
# ========== HTTPS VirtualHost для mapmil.deepfishing.ru ==========
|
||||
#
|
||||
# Источник истины для vhost Apache (контейнер `apache2`).
|
||||
# Применение: см. deploy/apache/README.md
|
||||
#
|
||||
# ВАЖНО: бэкенд адресуется ПО ИМЕНИ `ca-frontend`, а не по IP контейнера.
|
||||
# IP меняется при каждом пересоздании стека → хардкод IP даёт 503.
|
||||
# Контейнер `apache2` подключён к сети `mapmil_default`, поэтому имя резолвится.
|
||||
|
||||
<VirtualHost *:443>
|
||||
ServerName mapmil.deepfishing.ru
|
||||
|
||||
SSLEngine on
|
||||
SSLCertificateFile /etc/letsencrypt/live/deepfishing.ru/fullchain.pem
|
||||
SSLCertificateKeyFile /etc/letsencrypt/live/deepfishing.ru/privkey.pem
|
||||
|
||||
SSLProtocol -all +TLSv1.2 +TLSv1.3
|
||||
SSLCipherSuite ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384
|
||||
SSLHonorCipherOrder on
|
||||
SSLCompression off
|
||||
|
||||
ProxyPreserveHost On
|
||||
RequestHeader set X-Forwarded-Proto "https"
|
||||
RequestHeader set X-Forwarded-Host %{HTTP_HOST}e
|
||||
AllowEncodedSlashes NoDecode
|
||||
|
||||
Header set X-Content-Type-Options "nosniff"
|
||||
Header set X-XSS-Protection "1; mode=block"
|
||||
|
||||
# WebSocket support
|
||||
RewriteEngine On
|
||||
RewriteCond %{HTTP:Upgrade} websocket [NC]
|
||||
RewriteCond %{HTTP:Connection} upgrade [NC]
|
||||
RewriteRule ^/(.*)$ ws://ca-frontend:80/$1 [P,L]
|
||||
|
||||
ProxyPass / http://ca-frontend:80/
|
||||
ProxyPassReverse / http://ca-frontend:80/
|
||||
|
||||
ErrorLog /usr/local/apache2/logs/mapmil-error.log
|
||||
CustomLog /usr/local/apache2/logs/mapmil-access.log combined
|
||||
LogLevel warn
|
||||
</VirtualHost>
|
||||
Reference in New Issue
Block a user