add nginx, sshd, ssl roles
This commit is contained in:
@@ -0,0 +1,37 @@
|
||||
user www-data;
|
||||
worker_processes auto;
|
||||
worker_cpu_affinity auto;
|
||||
pid /run/nginx.pid;
|
||||
error_log /var/log/nginx/error.log;
|
||||
include /etc/nginx/modules-enabled/*.conf;
|
||||
events {
|
||||
worker_connections 768;
|
||||
}
|
||||
stream {
|
||||
upstream haproxy_http {
|
||||
server 127.0.0.1:10080;
|
||||
}
|
||||
upstream haproxy_backend {
|
||||
server 127.0.0.1:10443;
|
||||
}
|
||||
upstream stunnel_tun0_backend {
|
||||
server 127.0.0.1:8443;
|
||||
}
|
||||
upstream stunnel_tap0_backend {
|
||||
server 127.0.0.1:8444;
|
||||
}
|
||||
map $ssl_preread_server_name $backend {
|
||||
liqueur.oyacoi.ru stunnel_tun0_backend;
|
||||
absinthe.oyacoi.ru stunnel_tap0_backend;
|
||||
default haproxy_backend;
|
||||
}
|
||||
server {
|
||||
listen {{ container_ip }}:80;
|
||||
proxy_pass haproxy_http;
|
||||
}
|
||||
server {
|
||||
listen {{ container_ip }}:443;
|
||||
proxy_pass $backend;
|
||||
ssl_preread on;
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user