2023-08-04 14:06:37 +02:00
|
|
|
map $host $upstream_acme_challenge_host {
|
2023-10-28 02:14:44 +02:00
|
|
|
cloud.hamburg.ccc.de 172.31.17.143:31820;
|
|
|
|
pad.hamburg.ccc.de 172.31.17.141:31820;
|
2023-08-08 01:18:44 +02:00
|
|
|
id.hamburg.ccc.de 172.31.17.144:31820;
|
|
|
|
keycloak-admin.hamburg.ccc.de 172.31.17.144:31820;
|
2023-08-11 00:39:55 +02:00
|
|
|
aes.ccchh.net 172.31.17.145:31820;
|
2023-08-11 01:59:34 +02:00
|
|
|
wiki.ccchh.net 172.31.17.146:31820;
|
2023-08-27 20:02:53 +02:00
|
|
|
onlyoffice.hamburg.ccc.de 172.31.17.147:31820;
|
2023-09-21 19:13:56 +02:00
|
|
|
netbox.hamburg.ccc.de 172.31.17.149:31820;
|
2023-10-06 05:06:56 +02:00
|
|
|
matrix.hamburg.ccc.de 172.31.17.150:31820;
|
2023-10-07 05:17:01 +02:00
|
|
|
element.hamburg.ccc.de 172.31.17.151:31820;
|
2023-10-07 05:17:25 +02:00
|
|
|
branding-resources.hamburg.ccc.de 172.31.17.151:31820;
|
2023-10-25 02:19:53 +02:00
|
|
|
next.hamburg.ccc.de 172.31.17.151:31820;
|
2023-08-04 14:06:37 +02:00
|
|
|
default "";
|
|
|
|
}
|
|
|
|
|
|
|
|
server {
|
|
|
|
listen 80 default_server;
|
|
|
|
|
|
|
|
location /.well-known/acme-challenge/ {
|
|
|
|
proxy_pass http://$upstream_acme_challenge_host;
|
|
|
|
proxy_set_header Host $host;
|
|
|
|
proxy_set_header X-Real-IP $remote_addr;
|
|
|
|
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
|
|
|
# This is http in any case.
|
|
|
|
proxy_set_header X-Forwarded-Proto http;
|
|
|
|
}
|
|
|
|
|
|
|
|
# Better safe than sorry.
|
|
|
|
# Don't do a permanent redirect to avoid acme challenge pain (even tho 443
|
|
|
|
# still should work).
|
|
|
|
location / {
|
|
|
|
return 307 https://$host$request_uri;
|
|
|
|
}
|
|
|
|
}
|