From 2223682de4842153e4ccf9f1d04323377d5d7017 Mon Sep 17 00:00:00 2001 From: Alexander Dietrich Date: Wed, 8 Apr 2020 21:48:28 +0200 Subject: [PATCH] Remove nginx role --- roles/nginx/defaults/main.yml | 9 --- roles/nginx/files/error-pages/502.html | 10 --- roles/nginx/files/error-pages/bad_gateway.png | Bin 20660 -> 0 bytes roles/nginx/files/error-pages/style.css | 4 - roles/nginx/files/openssl.cnf | 10 --- roles/nginx/files/snippets/autoindex.conf | 3 - roles/nginx/files/snippets/error-pages.conf | 5 -- roles/nginx/files/snippets/header-hsts.conf | 4 - .../nginx/files/snippets/header-security.conf | 8 -- .../files/snippets/location-acme-srv01.conf | 6 -- roles/nginx/files/snippets/location-acme.conf | 5 -- .../nginx/files/snippets/no-unsafe-files.conf | 8 -- roles/nginx/handlers/main.yml | 10 --- roles/nginx/tasks/main.yml | 43 ---------- roles/nginx/templates/nginx.conf | 76 ------------------ 15 files changed, 201 deletions(-) delete mode 100644 roles/nginx/defaults/main.yml delete mode 100644 roles/nginx/files/error-pages/502.html delete mode 100644 roles/nginx/files/error-pages/bad_gateway.png delete mode 100644 roles/nginx/files/error-pages/style.css delete mode 100644 roles/nginx/files/openssl.cnf delete mode 100644 roles/nginx/files/snippets/autoindex.conf delete mode 100644 roles/nginx/files/snippets/error-pages.conf delete mode 100644 roles/nginx/files/snippets/header-hsts.conf delete mode 100644 roles/nginx/files/snippets/header-security.conf delete mode 100644 roles/nginx/files/snippets/location-acme-srv01.conf delete mode 100644 roles/nginx/files/snippets/location-acme.conf delete mode 100644 roles/nginx/files/snippets/no-unsafe-files.conf delete mode 100644 roles/nginx/handlers/main.yml delete mode 100644 roles/nginx/tasks/main.yml delete mode 100644 roles/nginx/templates/nginx.conf diff --git a/roles/nginx/defaults/main.yml b/roles/nginx/defaults/main.yml deleted file mode 100644 index ad4e28b..0000000 --- a/roles/nginx/defaults/main.yml +++ /dev/null @@ -1,9 +0,0 @@ ---- -nginx_access_log: "off" -nginx_ciphers: "ECDH+aRSA+CHACHA20:ECDH+aRSA+AESGCM" -nginx_curves: "X25519:secp521r1:secp384r1" -nginx_error_log: "/dev/null error" -nginx_packages: [nginx] -nginx_tls_versions: TLSv1.2 TLSv1.3 -nginx_worker_connections: 512 -nginx_worker_processes: auto diff --git a/roles/nginx/files/error-pages/502.html b/roles/nginx/files/error-pages/502.html deleted file mode 100644 index 16fdca7..0000000 --- a/roles/nginx/files/error-pages/502.html +++ /dev/null @@ -1,10 +0,0 @@ - - - - - 502 Bad Gateway - - - - Bad Gateway Sign - diff --git a/roles/nginx/files/error-pages/bad_gateway.png b/roles/nginx/files/error-pages/bad_gateway.png deleted file mode 100644 index 1bfdffa8c80d9b8533ead4a68efdb2aae32cc9c7..0000000000000000000000000000000000000000 GIT binary patch literal 0 HcmV?d00001 literal 20660 zcmc$`WmJ?=`{+H)z|bJlAc7!*w19-93P^Xiq;xYhGa?4vU5a$a&@rIoP|`ghB`qLb z@2$`OIcvS|d%m1chqYL<=AJ!!U%RjPUGqs@^%XGz9RUagB36)>(FB3O`XCV28$2lR zB>Ye44)B8Q@j^ix5BLkfv-$|U$9I)C@Bm(>|Ndk3DF-K{|| z7>vix*}=o|wW~Fci@R<5o;V!{!~{~1d9Lk~vAY2Cp_rJ${k@+bC;h8csbW-29+&Jn zihu(zjF|JwPf|)8?e9@xc;2NsIhtQT{xQu{(2({ce1Hwce|UN0Hh_Ml+*l*lEY^G; zl*Ja^ASUJ^oVpcs^NfUyj4U>qA1edf zm4@fud-}Ph?q@RQnI#e=Gj5;?2;-^vsw`2{19IVxP*srP><=bpX67$U&j^-ap!Oy4 zAdh3|VqvkWd*+S7J;;x!5YQfW3?@C~E>LSI+zNzYx=U{2R5j60mYW0ZUYACdIeVU>qKLj)?$p!nrZt@0BQ z+uF~s;cKQJ-@7j3f^>Eq8GsfvdfhEazqmGQ2q_7p+<7~XT`f7_*ol_bO$e!5=;R*u zy&Q%DLqIa9ls?#MkgIoEN%7f(0K^*Yhw#; zhRhl#s+=cu6E;4(M_}@n{uC5%izSc*>4{IEmz9x`S!I_c1hpDMPQ4*%Q<{DXP-B`U z`)C(;NjIIp5^gVb27s#M{Eb^^Y0hyfJ;N0-0D+7 zIdgHMw7Dtr-Xp{#wgBDy)C2W$1~ApS(n1glU|;Tm8wL`z{!%K@Davu*<(WgA$RZRj2GD7I>~dBQgj7 zQ~rDfVZDNI;M{av>b~zO?UhXE+-Ht_uJ;RDFV%UeT#v^1?_}(G3sL?OhBkN_*g~j_ zEgn3>GB9~Z<|FT7%XkegoqZk5@^2UhPp(l$V?;t96H@xuvOctY?4|{2h}Jh|U}^6V z-jmD=S}K&!aUfqx+J@&pMG&yUTYS0dvi?q-n&ucB(v!z`@y8mKF(KV#s;l@i_6qg6 zNIHvVuwX0}7bo{lsLcpoIcRAraq?|R6fxqIF|oK1m@*kv3P!?lc3vqM40c7yYio2y(!X!rkoS->DMQ9P6QcS z{QgQ<#=P``ymdp*QAg}n%xv8!+dKyi|5xm^Si%Gj60nCFyC9q+ECz~P37`}+ zn}aDKyOFY!(Sm+oBr_S@8=jc(rS52!67jJlDdOJ>QSqwKnBzGp9U|w!uOxUQksM&^ zw1IO}ABX7J{7tHR3Q3Z0L&%#A7TEd9O8eC z1@-6uN^Xm-AMtkt*dzG<*1%j%i`z*4-@g3+h5C=gRs#R+3k(1MM<|(@s_>Y)Mi903X^qXM3WlKmSn8KD)LzXQ&kF3J+}znQ52447m0 zlYh+#dB{Qkr< zd#W9k>Y*3J^A&PXCEX^HQd=zZ->EjDx2p6Pp13}yzvOu6w0v>4<<@@cIV-sp#{|F}Pp}H$x zsM&q%RP}9?8^uLcqh5Bk}AF&axzKcwrIQ9opE89sbu zrx0O5S-e|IILr9C}_QZnMk z^D%loT>@{Vj~~GwEGr$|U*Q(H@0P84 zj84?=(^Q_jEV;jjUHUq3@DTeZ!1w_IXhwr zmXnOLlRo^8r4f7gj8O$!_ZEk1cJ=xRAfWge$?tFBi}kS|*|kOf?U+u*7vdu&$g8WC zd%vV~-}2~~4dR-%n)?bGqu^V^e^u7+1$CaVolOyt3<11?NzlA93`KW2ps2b+?{uRR6Y1@ zu6Deu=T_Efyb?k?S;regogz%~Mgx6nnamC4^3|hassDMr-)QrIEL7O0@-5@7hd&DJ3CmniJ;zC~{VyZNe>VdkkMDX7|)v znAFP~T6>NsJ_(?ru1EJ0w3(hM&Ke>k2H@c*=R_n?HAVcBs-b8cqP;!L2}pW3Ogg;@ zRb6I3$BQ8_hLyECiDW(8u+t=nImD>Qy;B+*YtX0d(XV=_{=L)ovGG?k=#41Rjwn}l z=n-|EscD;t!S!;Q=Hf61>urB8c2q{(+g95lEb7sn@?C8HFt+A`|&|-c^GV_;Nf#_HcNJF%qH@OWR!de^ji%DHTkMyC=YB%HUzm(0m4|Bb5*pN{ zz%B=>z1eRLMP#hvE2a&jwiiQgnIq8)*9P`9{r7%b7 z=X97a^{}20ORF|N#8Pg5B7J-lM_FTJPxl)&C!O9?R)I-b8&PN^Z@n>i{C?B3IF%0N z_e7oT@{(^Ph<)Uk*1RwKWMb@@hbqrd=6kHc5AU408zF3PF*&sVncJshg4--ACuoxt zu4e$jbeq|=7qFe9Pir)7z7K>79x#~r6 zymJJ`{@L@Q2B{}56N|a1-CTGUODPVX+>Hbeb-Y5&PUG~D5$<@a-ri8gK>vP)g#s|G zF>M*Rf(>RoGB>sByg3uOsLD@mIP3@^Um*|Zf>4L}`58BkY=lf?Am6tIRPGfPKNjc4v(o08;7jwkF zitE}ZK@=dDIEk1E&;qDnmROrDIOQTq9bc|$8Id%DUFKN zDs4$|XP11g3oEF}){|OJbf{nsh7%Q@Emr@tArUy_p`PuBPhE$%*QwQ;8x}@YJkUy` zPAgU$yo&G7ZtAb}%tdzZ@_D|s>WS!fv))`VbZRewO;6b*?r7&5wH@tLx~I>c|8nnZ zsx}Q70uRpO!nfeS~N|m9L-L)#`PVZ{PcQ;)37YMdG`Rf-l+SFgv1Z2%Tt}E zPWTkp=lkZZC)~fUY&%3xhS7*uJ-8dw9CwHNRk~qV{SB%nM4rCg;+4N_*P-%|!(|d1>fSIX_k%y(5|-A`==NQ& zH?jeo2)mn>8;1|=gT^@Gw|1^`d~W#>ES_m!DK>Ry8`vs)Oxkq1ZD_5le_9~6DP8{T z{Cad{8GpgG4d|cowgFQ4TW6fDj*CiW(^8KHieF)-OpjNFqU_1zZbX^MDR=lS8?n(g z7P$zc@|yjI8`KkhlKM9SBdgD8ZNGkbfp0(}+x0XL-u%oTBh=h-lR2soSa( z$(?FXLcUdr6({Wv9EDI0xl*eMQyF2O zz>)#?&VCv+&JiUYQ6org3SF|j6}sitypzDCcZ&BDwSIt6E)|e(mr&uk)+6|d?0Lt1 z)WxTn;0u_>+=f=Y>GfmA|QFNGo_%L#Zn3YiF(WH~O_pDYD=I%5k~;EWgH zQS`Fm$P%t5!hc&lb3J?b`;;v8*)5vDA(XHE#$>CgFoRHv=OAca2hnn9icW6ems}kX zRq$|`E70v7e(bIU$B}=~KLv%T*!N1GQe-~=!ELYLHb;eIg(P@It%t`?87n6{{w@#U zXE{x#oP1;$(2APHz8kEdka!@VDv%~77T>End+En)YS zLdsfM+5VI|D&*=skI_zlV@2`a1q*s&z$UPfTw92Sym7vue2b8W;QiNC`u)kV|vES9~vqiRgb&hy}vEmXor z?X9;#_1ig3*{_AaLnN$p&uZewIkq6034*rpL^fzcYi7iA!J}`?7zo$IUWcU9csK0_ z2vq;Mb_tkoEx4K@tRid`cReDpxp1m2@%g*<*1ZKoH;q^nYTKGi0sU&cUx{nZ{=T`1 za&i@8vBj6wQx7AtBd4P-EEp`w{^+zlul?O8twN}NEZIdzRqF7DVqH(RY2(za=HsXR z5C=(YXjD9*!;A&$@L-ba#c_ zu+sagM0YaZ-L5aCWNTK&+0!LRA?UPh8+_E`EBr3k@ySv;S#@z|y4GO5S-ld!Y1NMz zM#d2xZq$Wak*9;dzl2m8JKChk^Q2tvO8=pJ;*fN0| zdUcaeL9Mg7r6x(LY{Zqimk~ytApN>8d;Lh_~HHUTDT1*?)w!UJ2?wMOCIh@fJaTU{Y zB^nrGk5`n|W%m1S@jBQ0-8t+JY%}{vr=w+d6|hNl{d}Tzt}u{F2STmZHUz!u`?)>F zlWMyH>Z_e@{D|b;($knz-Jfr3u9?{mP$7gucc`LRCHx6!09c2m*ddYX|Kit>777=`#OH z9fnjln-8}8>T`P*O{F5A^R9xA+XhPKSOqS%oo?o?^0yDtBeSzxXJ;!zDCex!Yf~4U zGUDwt&Tnx34DVKVjq`Wuc5C=*5)atxR@%0>u>+nDnf5ZAtp&E4unevj%Ul`;7qU@3lo`X*C$1WER|18&nm(IbAiIN$J3^S*Wvk+ukPLy>EjoPJT(<5bYJ`fHFGNGSK%9<+ zB)ELVsjI{jj=#x5W(}V9qc=u(BnoXldf(^6=;=P`r#GUBHn{c*H4LmFxBY4~svMm( ziB=IY3E*;d5L+4(?VhvNvDC{9_+p6DX6@7`zYaKpnL?L#(gr=3-eu$*P4@NKu7S_n z)!;&2nVG%^vQ0ntJBJ9BGs8YJm|I)*pFs;Ea3Ab5=(4|xVUy!9nJY4OL+%c2Egaif z-ly0V;|Ooiduot7%;leWCzv(d)6!$5|Fl30-W8l?yG2#1M+nVO-^DOOJ)e?Rf;Jy% zx85)Ie!SkjLx}>Rz1PCgwX-)S@E;+7{r7N0(`}RA6_bw2&Yp%nm&gQX$j2S16~wjD zkHz~;X4Mr!)4i2lhJHFkvIbYVe+bw-oWQ~UrjSoB;wu+aJ*4I0hZblZxR2ZaV{Cm+ z=2ahf%Ujdrgk$0%YHI-s=+@^!>lMPJl>^;oUUmW2P^Z@Z_0(URN`nxt#2v#n5r4KG z<0h`u8m+!K21QAiKt?%}dfnP`mM*QqM^wsYkGAL20$*KwVC%P|uNr=6Om5S@Cxq$; zX%_(oc(`;VFZ_qrxM_`3HWzH!>3ep7sU(wt9=OCC)I-rW4v~EtqEq}au!qaZveKqN z8e2d5&x!McSz5GphkNj|0L8tajZ&=1-9LMslm>E6iukZTj3^V{g43Czs~CF+CPFHB0)g8j-j=Qrz@{5(dd{VKb`A~-f$w~y!EK%GRsh7J? za|`rID^&|Xx$SYGCBryw98F{sPxM2dQe_?M9=tu-MXTyUxLiCPwidQe7>>>0$HQbx z=fhw7TN00HUYcC2{iacyYDS)yZgizb_Q<4KR{(k|v8ava;&i77>Y2BpB42G$$@NuT zp#8SM1;4-Rxvu&5g2^NZVQsS*gg5ZDsqX77i%W3nya=FA+LA$g8*r`qYr`^eODUN% z8wm;*&7l2aPaDAF0{T@#JlJ$DZnTloRTSo-&zXLDqeB}{r29tJ^Op$tvR*JMYIn0` zs^I9-2Lz|$=nvYP23n4PMx4iq$gMPKH{n|5wsOY0Jy4l+XxYQJ#nppbG3nUI59vE! z1-5SI%)Uds^D!9aueX3xGWlA-pM;Fp>zT-2hh!ttvq+so?R9`dT1?OI)XTfDT_3+P zj+?^8^NX^u>+PIo)I(!1amnbtQI*w_BrkYe=wSU=$yU%qGX2(XXGnt@T#2<$PZ)h9 zEK_foyc0ns9+vocrSg)bo!Hn<+o_pD0NjFdrzRF~?DlrrHu% z)ehUZuBGtVxgI$;FPW^XKDzd)`SX%Vzi%{C^}tN5Hf8Y9(bq%az-57@_?g9ewtFJS z;SlVwL(e}`QzUiaK@-0O z8-O!2wM|CZpY@BApP~ttkS>8PT7`rK200vv-uDZ$!cdzvT8;!z`2?-vkJd(C=?diS z+T1`pF5qR&;*PBEvs>NJjA9#K4UcC+5Abr<3JlGimQW6IYxK4qzWN-7r3*)v=hm6z z(@)#G-X*1RxCa;2i1;bnJp@v+UZ^r>Pf-h;3y!|5U@%nWfa=@8I)D(w^9SDKOT6CR z{U%*W>A(1^a$urso?@Mzda` zl3HhK%sEynF4(O+#apiuVH<{4*yxhaAZ)7^#hY*@KPG#hcI? zN(p2kPJrlqOL1W3pMB=U^TBNhiNCsa zHgPeyy?t$di2zibfMxhN0{>*^?&@sFBp-@^uclc-LU@PDJP)RJ+cl*KRmee^gZE&9TxdB7g z)c#0+cspsj3#Rsc4FoL>9L3TbJcXwV5Y$sTvtAAd!jr?-jkw&8g>*hl5zrtVXDx@5 z!^U{EGr6#Vt$*Dtx6nw4(qb%f!4#$)e3|DUr1!5;{gO2(LW|+?v@c)fN8(OFG`E2-|X@{Onm%Dj#|=XT1Uayi|)@Rg~HKg z|0Z=Y32~{4<&9^Q?;{kwv+(bc=4#cP;x>ke(}Fms8vea5Wp?dmJ>tqBhC>iw!egTlJ<=Rbi>25v_&eEsDGGw&eGo)<4FX!%o3kZ z5n5q62x!D=W+AWvnPy-VJ`*n%5*|IR-6zqRq^qrISU(Tn3S}GAH}IKJ)GNN9Sar8U zyENw*IlSj+*f^fTgQg~Na;(cpct&~BB>Yg0~SSzF46k?`{S1^e(==$vI>sZ(|wfhV1f zn)jZ?vyt1U+liC7UII6F2g!5mD0(>Pn_YFfyQT-X&S|L~vJUzVN0U#6@>RqM=TGwo zc522{$^x&|s>FRv2-^tOev*pXn>b`sPS%AYu zO3V%V=JsJ_x5WtH9@y>C*&}&02p*aqx3;iN)<(K-%{ea+2Jn4rUioU4^px)9^AFI; z9*2i{AckykR_1CT)-<<2!doqEiogG{B$ZEH#kn`f#wNYgv@jgj?e2d9DKu+nEvm{- zs}fJc`*ZKLlZm`UGYNR`gFLmz(F4@8kQbS{iR{?5rMq*I&f5B5wgP_H3Bug1s#yuV z!pte!R8+c@KBhitT+ks;tA&jA!CF87CFAzOzF@`^)M5M)^%_{yHs+YOb{z?yr9@_H zHI9j-;mu#C?XQTCWNRwbl-TP}%*H)<$)+!L(?}?d`GM-+oiwFZ-j}clRQMF3Y(9Sq zINzI~{mA$Uj$fh%w87Rr+tof}d!6{RYaZ@& zQVeGruLt5%PYZDK9bW~9&b+g6w$Dpy98wA35#0LvOlfh}WBQ`{Ue>%bZAvB(bTi^v zV5TNbyz%4yM$C`R?ErC66TtM8>PT&)HO?D}$Un~9!Y>!O7|0n*r0#VNL~^f6_~m+%aUDx zkM7-{wimXS%gl8qL=ICz6&1gp^E(rbvJH};Czd2_v)YlBc zO?Acx!5G0eqB|JBCpRaD5^0(^0yN;M zn#8w&8|L5rQz)@9IFAYtt;;KY{sVlMDBmpZGaj%(&~?3VtD5u(W#QigJ=NZr57GYh zf*MH#tg9|{uj`MeiW7`S#v0NnT#jw*%1p~zvp1(o5`Ez~z0(sLk09CCk5;JWrjn0j zwy#ZxVos}^q$>ZYrB>Nm>sBy8J&z?(9EQ^6Dha>=fcq&L=aIPcJyEvr5SV8SX;~OB zO=#akNbd)+;HyMI*rD%C_Ykd#+(oU1k(IX6ENhXIWgd-9;m2?sfC~@|?Dg%^U}1q* zyr<`ljMo~Y<99Xi`qI%SfHKlr!;L9_e{~RdJm87;^}Bgt-cMay%8m75tLgn^v`L^O zW?WGURcuN^;T-ifGEm|h_s3jkNHAVKbFQzCr+**5Icer^B!+qW$F&Ox zgB%{H=h)yJ?PhHkWGVD+zDV=z+mYaq`UC)g##nKoe#dPn2Hu2(#{>g@I<4UxcZ_)q z#zxbBB3Ul|gXcY{ACAoXYrjqYnt+;k-%oAZLKMT0)qdIk_It<4C3GnyJ8Lv^z?or?FWU&9i-(TTK_lW{uU4Cn{anKLFfl^ zr2OUFt3`^mOO0aJbN7R{=CB&_oGOi$l>tR1e9>EuI~9-m_f0NpX>YN$P0s;?%Z!UA zuRnv``W}G<%ycSD_taqC;G2z=Q-whSd*KgRbh;Ca)j5jRh+i3gwY8E(4-3d(b``Z` zTiW&(YuZH#w=VK80P}_k*keyZ;2ZnZCrumsagx{S$D3o)+~H=ui>@znEOY><5Q!yZVD+0nj<`P3tn*vqT>;NW6iD*emY>uts2`~JrtPONCdDY1j-w{NBE z{Y3qf+1wi8`&p;KFsI4=CNns%CK=BXvg5AtdD>u~#Z%YK*IM3V{UYT7Zql}d;idF; z#tXCGNnH#Ei7uEq?lz2BRH>KDZ9F2XeEZdx+x%M(zxjeu=v_DlgI(S{+2+0W=j5BT zuaq?tM-p~Yn?q|@P1t15B}W^FO^I z$hZ9R^`6346~v3AVrv9#?)7amZvrSl0IYwdYTj+F!%cW~Q0FE}<04pEoK?nU^1Utn zCFe>*)6?T1AO?4z8*bKpR&k?M#H`u*Fs9U#T&R?88pJmaXsMNod2rqj5Kc^efkTcu znD3T2^}=a`L7ZtJCZuVmc{rn=Djw7IQew9;gf|1E>`Rhzm2kVy1?gA=-*2a#K2F4r z^uCR(iE?`>fM41zwPhl~Auxf)a$uV_+Z4TMUn*Ac@;^<_Q!z1LdDy3WHs>|fuQGKR zJ=1P3#)P5d#Xzn^XD+s|IE;CY+g)J1#r4~d&5W<#qoVdYGRj>DN>iCu*mkvRL42pj zC^f$#kH`xZUfgNjmFr@zm2%gdhWFQL*ba5IHDSr|&c-yunDW=cdTy4^9n)0Np zQhV_*e&+5Wd<{KQy0!2DKK$BW@(R?+TtwO&+z{(@ZBk`Do!0)i@>E^U3jIc&zC6>T<`d6W?te{bBk?lqXjC9L%<>fa>p`R$Nn83Pe5df`}j58XxD}}kz^)d1)@gd7O$Hv8k62et; zOfcF()i*;&ljzxaj_@#QPIk)cOYa1(j~jzBp93`YdO!B_vl%k8SY>FpM^*0(bVj;6 zKgvpEt`H5Mzo0Aamg$Sszvbc23m&2qUB58te!6PRlVkiO$4&)*s7WyCXA5Gqy3RA* zgs(7FLE;LMf^5U` z4;nw>ZK`q_=r^7@?2n3NilZ6az(-2Ia{2i99t*%~HF!3>OK|idA$C}1ElKTha69d0iduwr>3Bd;kw3HufgJPdkKVP^CY#t zMEY$yPM2Z^+Vgj*=m4~yz>?k@5^vMj&TEons29wrOFy2KC(BI*t_%Ao7tNgiA4T|D z8Ji2hJ2v7s;{kxK{1m_%ES7~VgpGUy{RNsmTg7B1k*p2@B$dV)8UPnfk#tdub2N~gx7os^>P)=q)qLs| z{3ErGMjGhY%7CcI-*Khc9>>$iuuqru2L2bm{x6#RPxM}!|66Y*arJq`44(tDx_XC) z{w@7~uxQ8b|I1?i9}R~_hcoDWYKsBY5kEV8Y>y*zM8pIJm7Wudxc=Pg0iamJ3H$*6 zkL)ITM z!9Aj0^-*{%J=$2p7#)S(Pe~f!-|Gvw^lb%)VyEBaDE~m!e{e4VwAyLA-3{O(XLjrj zQ~&i_6jlA8mxce&qUX{YZ$(gxpQw33_e#QL#5EOQEtN33s8a&RKG0<27=Vlplg$q2 z4L}dOaOxyhCB*pkcbNa?{Z!NbTcphC=l9HKV&zzXNA3h-FaFmw5&ebXV{u8`+5UdQ z^gmGhf3p&}1Qna29@9;i`dZbRiy7V1UhL8wP2_N`HDG zy*4Vn(TyS=Y^lJL^q}N(n3#x8X2*`8^I5yq(nN?lz|C|){v=AWziO4FtH9E^_R^>8 zhd1u!jEw*Zooj}SzV5Kpt5a(yx~kH+QJp)%dZmVb5>5@aPl!MDG4f{$Zh`GXTGVu<}WL0B7ZPPQVA_ zevri%xCKt$?(P=aHm5f9+7Ad3oiFxoc2iZaTP3x=%Ht-SgnUrzgT3%f2-pCK)A?Dd zH^wG)nf0o5IPl=;ZN|&0)0$v!dL77K`;X?+=bsTuYcb_tDeygO0mCj}23XKOzf8=> z?(a_Ri#{}y9u5Q(?eSpAB3jmaOdH5jnx=iy1vbi^&GIz2uqMkxP`@6dV1#RLW5<@Y zP~8&lKf+zHuAgDCT%vKlhY>d;gQF+<`}bMKhy%pQX%336hTNa|LZ=TZj0MruxN@Z6 z3s~dfRh#8SZ~^Q?Z}P=}4r+xFbQxvZs`ArdsUjFbi$>T!>ccrp6i9B=sj_;#jWt=#jar@2lUn?YaDyk79;Ej3H#B4GZ+l~rwiA|OypDww9v?1l zR3uC9w(X%xPHAy>*@i&hB;!Ks1o)BlqFE0S+iFUPf=8f`Cael#D8c#|rXq=vs!uc- zP++7p%}wRs@6WRK@z(_@OSxXS;j8=S z%!~hWir2cZHvg&YyO8m8%SpKA++}7X`Dk1cLnsW6ybrp0W^P8$-U6i4_^y4+MzBe0 z6RL{uNlx0eNpUM9~qvu&#QnhLQ2R^YO00m_wJFj6&_|( zH4R6ce{t4UlH;z=3fAuFHNX)&<*o{BMzVZzU*TJ(-Z$O1+cwQP8k?LuG$+lm@x?@| z4Sjo&OCcC<>(6Lx2GGoME@-lt2uu{PP){ELVY8Y~rUXEe)Cy4O z-SIlT&888LpAp#KI8u>Z?WLfL7WReuHj!YmU#A3><{>VZ_z8VA2-2X*pmM+(o_Zo3 z;AlQ)CF~-3?C7Nbhqjw@I~ z+b}G*8-{}M%G>OnobYQvK)SbiQVL5`dT^0wg?p?7=dG!$5HSmS;I_!_l0%!=0|}qY zSN!b$=eo4H=Hr>a=M2qvReeoVy*RPFZZA&{on|YB(_h(e7U{PbKpVD-^zZsy+2mM4 zay&H}8}^^EFKEZxZo_cfPKfz(2whbkBfV)JYiW0HTA4hoyJDgJJa%gxBN;GX-!TIi zv-D|@V@}BVPpg5keR^x5lvweqCZAvqLRf_i`9)M5 z!1!)}9)Q}J&~r9__B0M_$#BnKtEuOhqLjhpo!op)pJpB0qW*T^qNSuJf}H-@bN`&90UdXQgURXE#@ok$ z>V5pyGjE-O_Q8Im!62$0jqyV!9WsidlOhx-2Mzr_aZBngZ9g_Y5bxY(( zZ1X+F@o|4k^kV9;=TWNbSWfYUe_xTI!O~a(au~VrVf9{MdA5YG_Nrrsto-wd8dkn- zo!upZ7_RZdgNw0ItiGJHxmX$Vwjt?5qgik^kpK^&dagKM@ccxFLXus09(s)ahX#t* z(rT+k*Wg`?FFbi4%d{QSd<{X73!`OUR$T9HLpY^CVf0poRB2b4Z5b7rWf87eTCYqQ zjMx6?Gp2f1Y!GIK+gCO$@I%#Hpu3mReH$$EM0+I4!3OP*=7Dq(-<3Z-ctPgsj60vR zP~X{(m7Y;3#yr3}UCe1G&AqU+vDd@a4J>5r)#K#Ez{<9Kf{FS~0(yn?4SoFIaqddM+oQF5`2%gAR z|FW=R>j`^y!2EfRxL?ygmN79Kjaf8p<(bi{$3k+vkrIZL)l{!l1m&6)IQf|2Q+29r zGHcqrSUdW{%AyrK`r`bjJ*3-&hgPHlCSdL*S6&ePVGHx_j&BGp*I|Dq!$f<;mR@YR z5I0-gRq*n7`qSxVBodK->NPd&$$i3)YN}6%RcIZntL>K4ao5*Q3@g9!3b7W2J#U}A z384Z<;w4j5PPhY^EvK)K1JB1QIP(TRB#DVBydHENuVA^e@lClm@YS(xvgG8ez$EJ% zpK~sI(YQjBq6Ov1!vSRt?;Yl^Id-;gmB_`Voj>T4!DnN+!XA}@5QodYblf)@Mwg1IB)=TVWV(3nHm*O=WX9V=C|B+bT9FX^HQeoeY zAt8njXB|j>Tk+JrO%kQW>D6u4imW?*bjM|R#h+!g^F{7zqJT1S3J7$E_V4cklzQRm zB#zM*P~u%i+ernfC~RLA=L-;Dy`zQ=$`Z<}uc#r;#5S*k&=knFdDXSii-jRMgIZ~k zOlI`bn?bAQdfrnX%d6uPN5hGbD zZ}OIk7OImv&Nn`u9DPvh?;OP;dgS@;nc1*jE7zMJU_D-Q=X`0?O^)#k$Lv#!&QH81 z*)o3m`G`)#ew=F_`I=NW-PQGBgy~Xz!WWaPF(ch%>*}!){O%2<3+tstVJjgUcHR#w zYJONr{hf=3hu?o;>q8f2WQqZsviG||<_^KkE8dqhJW0+P={N1(1#Yx&=T&)YD7LL_ zlzF#To%$%4o85@0LXqRO=JiZhdGCF@r7H-v(MQ>v(F*9@+NMA()ZFWjeyJ~7SMK1@ z3FuQycKVJ~Y5B}`k@w%<&NaFDIgevd9a>J6{p!-K%=*3dFYfwyy$ul=T@efJ7mq4? z`y!wfC(cfood+c~$DN-R_ZtB7LXG}1Dp&8F;7C@BY?uiUF7TrBNUK++Viz_vWEUPy zca1Ht87iQK>aTjXv=>zBK5V}!t$lTQR_DWy-@17jO8)hkw@72&ZerL9;2jKTR&VxM zAHlCyE%`22fkb}7I}?|4 zJjr%@qBBYM2Bew+5Cbh~J;B3i2=ZBW-gP1$21f^*54#O#)JT^9vWjtdZ}$Ujo|lhR z5LdRljaj*<2?^1;`<|VR#J!+WPpg1^`LGP(^r~T$^TJ1na=J;l(&-@C-r8DYPh8Zd zMPk%w(trH$nh{m1v(+N~mq?I%HtrN&3l(Ta~6xb}v3qaZKK<)2M-MU~{}J0M(T; z9+ef1;>a*};&?h1UeEUkSYJzWp4_Vr>X?Xs{q0%upaVFOh-X$9IU0Nm7<|Jjx?)j3 ze9ArvAQnChoW^?N`>b0cS8xEtFXy?=?uJbn7=U-?h9lNc{Fy|$M`>H(>9~d>UdbC! zASu4_t!YsxOTp?}i+q#79QC&+9xH9Qi`NQee}8)6{w?Ia3bx_@Q^uLcL%Ftbd=@jK z8fmhOCCjl?l(8qfI+i08k;X1Yyk$G0gfOWnA~i*eGZQVcgk%Y0D_b0<7`riPN@R=d z+k4N_`#JCX{`)+i=f3ajx}N9x-1qOguCI|C5ptc8Um|nN1|E?F*;qLlU<}TfD$-Dp zXbcanir68QWv@KKw46p>cbQ*!yV7_6dQDE4g-&)(O$y0@*|-U<+&*5jF^B-$*7gbM zwvb~d*GE@CJ?f-d^!mu(CYwFzg&69E$ybSXPU$gK_$v<%Kb!`|X3mEQCI#OWv~6(p z7D6{Y$a|1tT{f$_Ws>2uzcW{SzsO~W^}N~?Q~P?B(mzxiboNWpP`ttpe1+Nir7Oh) z{VkLrmDOaJjWoQt$S5GO8opBUV?(v@`rAfx&Xkb{f6XI7E-6;h*}jE3jBq3}kS6!~L8mwN?&umx(f#OeD9-USm{T1eL1CiY|u~?SCZe?F%}CCk!a- z58f4f5+Jy`E+hR*DPT?B)pR2?c+?RCX5=X{CR^x%yAGj`k3zfmriZdPjcs>tfIK?TD6#~3hB zE4msjJ%(WCcgnJI0&R#VWb{_OMEwA8U~U*<=^7{c4}KFo%Bodfx&P{!)ha zm>AUb^Mt>aT06!6ZG~HH;I&>tbWkuZ{3b=Q@*ZC3 ztkj-abuo#~(D<#6R&5lwe<#=p+}a@yZ4(nfkA*$GU0U|CQnXjg5;w@;v$%W2(rjAS z+b2)d2P>o~(taUo`yjnQ7Measb^Vh$s=gwm_h@&F0XXV-j@;>nKgmR}G!I@PX%;sX3~sAhOqkXY z7d8Ox7`s@~UuVC5AeVSAP^H8lZ#w4=`Ky0eSv@WyDG)W2PIzpTA+Nc#J%bMy-q!x! z>0d6#9G--Z8hn&Ye{;OiRfU1x_2GUh{%H~+FVGJedWMkSebhB+A+jT=GyQS;-ng2g z1`~OlW26ToDJTbj9Cta$h(Agl93HmgslP`aaI+SsRp4m(;=%S->*L=}gDsHdv6h46 zj?wqJAuLkAZswxX2bYnCW_>|;#8CYnbz=->#yV>Y2Y_VIaxp@#Y3D&4 zmiD9~FLlYbV_(3{#aXJU`8e5XBU|-L2vqRrEwefR2Y9A>=g%|FI#b|XIi-ESNUyw- zV3q%#d~$WYK`A;2{{t^0es8A5U%Y3z10&nuja2BdM#tb5W%`Gqo%bMRRR8KYLFqer zFuQ{XqmD#_+GRvp_#tt@&wr=sx~WX=EL`Ld9?v6r?0p0wDJg$9YaH)-C6_vO@3?@4 zkfP^)dxz+xBk(JkBnKtmTO>I}@!5u!$UMiRF?D`&l{QYEuIE%*pFCG!_SBk}V zE}bNf#|R-wan$|Zb)d#23cS0PNN037~*&&>+m2-~bo9a?z7J zDlwf)Q{l;~g2~yecHCj0on}sO@60lj4oy{;5!s{V@pRPxUmV<*LvGRCp~(e{aC0dv zB9|PpD}j@0kP`%em1PDX1;}L<0(up@i*xnvV* z9yf-!Vz4eWj~lafAJ3*>b7Z0tJBN|!|H~}ydZh7wBw#@EFLDc$%Y;FB@mvcSEB|dG zL6bM>qYq}yMu-0~`&k!vf;OYxuF8DNgv6)qHq zB=tXw>g9zT$=#BpKY?~g- zs)G_nx#cjjo+K2|A`H*jSe9f2ZMX#Jvt43aXsKTM<{4?qepQ}XZA$%wf*XlpuxQa2}Z@}-W(7xSi`A#zv*9)l9VtQ ztCzu)C(t1{Kf{=_F0#tUCrvz5A^k>B|Ng8}L$+Il{D%dBx@Z09MJcrvG5EoKam?Y- zJ7>VQ!k#i3{FYZj2c6|F66um-A<%$vSXn9DnT}LWgU&YP)^Gq*XE6jB~0vTdVIy**!aL%`+XefRdei1WSz*ZD|l3MlRb?;cNPHpsOau5%Z?_{DQLbrUx*%YGWP3Dt%Ilbyzib-I+q~Jlz_N^j zV7tetrRU8&`@$)2qKD<#G3@oT6~WIFg+;XsC0f<$=7_o7#Ph1AS2r)`c|}A5VYbRp zKy1M{F}9+oQSVH}10N(G2m@3kFgq*psOJEz4I<$08t8X62YbYs8M{A1Q|MpzQ~g z0LzyYCo8~wJJ|f6*H+4rY*dfc{k4w$(UvlSTB)$JLt8z3AwNI9clEhWi-bX3rGB6^f>kIraBwTr_3hOY!C6Ii z!H9G|JcK!(1V4B+Irx-Vtm%LR$4b4UP_Y||ev{(~F>MD9OvtshPBkPmNj%UVnW* z@Wf?^coKSV&tin>XM;1cLi3O=xUFQMa6CFm6(VaKi}y(R9e9gyM+?$&OA!Y6cU#Jf p1aNCxn8zUcZj*oZrNP%^4i=E;BCr-`Kp2ErnjJNLdD!#vzXA74ru6^- diff --git a/roles/nginx/files/error-pages/style.css b/roles/nginx/files/error-pages/style.css deleted file mode 100644 index 8652fc6..0000000 --- a/roles/nginx/files/error-pages/style.css +++ /dev/null @@ -1,4 +0,0 @@ -img.singleton { - display: block; - margin: 10px auto; -} diff --git a/roles/nginx/files/openssl.cnf b/roles/nginx/files/openssl.cnf deleted file mode 100644 index 38a7328..0000000 --- a/roles/nginx/files/openssl.cnf +++ /dev/null @@ -1,10 +0,0 @@ -openssl_conf = default_conf - -[default_conf] -ssl_conf = ssl_sect - -[ssl_sect] -system_default = system_default_sect - -[system_default_sect] -Ciphersuites = TLS_CHACHA20_POLY1305_SHA256:TLS_AES_256_GCM_SHA384:TLS_AES_128_GCM_SHA256 diff --git a/roles/nginx/files/snippets/autoindex.conf b/roles/nginx/files/snippets/autoindex.conf deleted file mode 100644 index bc6ab74..0000000 --- a/roles/nginx/files/snippets/autoindex.conf +++ /dev/null @@ -1,3 +0,0 @@ -autoindex on; -autoindex_exact_size on; -autoindex_localtime off; diff --git a/roles/nginx/files/snippets/error-pages.conf b/roles/nginx/files/snippets/error-pages.conf deleted file mode 100644 index aecc17c..0000000 --- a/roles/nginx/files/snippets/error-pages.conf +++ /dev/null @@ -1,5 +0,0 @@ -error_page 502 /_error-pages/502.html; - -location ^~ /_error-pages { - root /var/www; -} diff --git a/roles/nginx/files/snippets/header-hsts.conf b/roles/nginx/files/snippets/header-hsts.conf deleted file mode 100644 index a9abbb9..0000000 --- a/roles/nginx/files/snippets/header-hsts.conf +++ /dev/null @@ -1,4 +0,0 @@ -add_header Expect-CT "max-age=86400, enforce" always; -add_header Strict-Transport-Security "max-age=31536000" always; -proxy_hide_header Expect-CT; -proxy_hide_header Strict-Transport-Security; diff --git a/roles/nginx/files/snippets/header-security.conf b/roles/nginx/files/snippets/header-security.conf deleted file mode 100644 index bad6060..0000000 --- a/roles/nginx/files/snippets/header-security.conf +++ /dev/null @@ -1,8 +0,0 @@ -add_header Referrer-Policy same-origin always; -add_header X-Content-Type-Options nosniff always; -add_header X-Frame-Options sameorigin always; -add_header X-XSS-Protection "1; mode=block" always; -proxy_hide_header Referrer-Policy; -proxy_hide_header X-Content-Type-Options; -proxy_hide_header X-Frame-Options; -proxy_hide_header X-XSS-Protection; diff --git a/roles/nginx/files/snippets/location-acme-srv01.conf b/roles/nginx/files/snippets/location-acme-srv01.conf deleted file mode 100644 index fed6e58..0000000 --- a/roles/nginx/files/snippets/location-acme-srv01.conf +++ /dev/null @@ -1,6 +0,0 @@ -location ^~ /.well-known/acme-challenge { - proxy_set_header Host $host; - proxy_set_header X-Forwarded-Proto $scheme; - proxy_pass http://srv01.hamburg.freifunk.net$request_uri; - access_log off; -} diff --git a/roles/nginx/files/snippets/location-acme.conf b/roles/nginx/files/snippets/location-acme.conf deleted file mode 100644 index fca5835..0000000 --- a/roles/nginx/files/snippets/location-acme.conf +++ /dev/null @@ -1,5 +0,0 @@ -location ^~ /.well-known/acme-challenge { - root /var/www/_acme-challenge; - try_files $uri $uri/ =404; - access_log off; -} diff --git a/roles/nginx/files/snippets/no-unsafe-files.conf b/roles/nginx/files/snippets/no-unsafe-files.conf deleted file mode 100644 index 5a6df31..0000000 --- a/roles/nginx/files/snippets/no-unsafe-files.conf +++ /dev/null @@ -1,8 +0,0 @@ -disable_symlinks if_not_owner from=$document_root; - -# Do not serve dotfiles. -location ~ /\. { - deny all; - access_log off; - log_not_found off; -} diff --git a/roles/nginx/handlers/main.yml b/roles/nginx/handlers/main.yml deleted file mode 100644 index 15bc297..0000000 --- a/roles/nginx/handlers/main.yml +++ /dev/null @@ -1,10 +0,0 @@ ---- -- name: reload nginx - service: - name: nginx - state: reloaded - -- name: restart nginx - service: - name: nginx - state: restarted diff --git a/roles/nginx/tasks/main.yml b/roles/nginx/tasks/main.yml deleted file mode 100644 index c90aa40..0000000 --- a/roles/nginx/tasks/main.yml +++ /dev/null @@ -1,43 +0,0 @@ ---- -- name: install nginx - apt: - name: "{{ nginx_packages }}" - cache_valid_time: 86400 - -- name: create directories - file: - path: "{{ item }}" - state: directory - with_items: - - /var/www/_acme-challenge - - /var/www/_error-pages - -- name: copy error-pages - copy: - src: error-pages/ - dest: /var/www/_error-pages/ - -- name: copy snippets - copy: - src: snippets - dest: /etc/nginx/ - -- name: copy openssl.cnf - copy: - src: openssl.cnf - dest: /etc/ssl/ - backup: yes - notify: restart nginx - -- name: template nginx.conf - template: - src: nginx.conf - dest: /etc/nginx/ - backup: yes - notify: reload nginx - -- name: remove default site - file: - path: /etc/nginx/sites-enabled/default - state: absent - notify: reload nginx diff --git a/roles/nginx/templates/nginx.conf b/roles/nginx/templates/nginx.conf deleted file mode 100644 index 12032b6..0000000 --- a/roles/nginx/templates/nginx.conf +++ /dev/null @@ -1,76 +0,0 @@ -user www-data; -worker_processes {{ nginx_worker_processes }}; -pid /run/nginx.pid; -include /etc/nginx/modules-enabled/*.conf; - -events { - worker_connections {{ nginx_worker_connections }}; - # multi_accept on; -} - -http { - - ## - # Basic Settings - ## - - sendfile on; - tcp_nopush on; - tcp_nodelay on; - keepalive_timeout 65; - types_hash_max_size 2048; - server_tokens off; -{% if nginx_resolver is defined %} - resolver {{ nginx_resolver }}; -{% endif %} - - # server_names_hash_bucket_size 64; - # server_name_in_redirect off; - - include /etc/nginx/mime.types; - default_type application/octet-stream; - - ## - # SSL Settings - ## - - ssl_protocols {{ nginx_tls_versions }}; - ssl_ciphers {{ nginx_ciphers }}; - ssl_ecdh_curve {{ nginx_curves }}; - ssl_prefer_server_ciphers on; - ssl_session_cache shared:SSL:10M; - ssl_session_timeout 10m; - ssl_session_tickets off; -{% if nginx_resolver is defined %} - ssl_stapling on; - ssl_stapling_verify on; -{% endif %} - - ## - # Logging Settings - ## - - log_format privacy '$server_name:$server_port 127.0.0.1 - - [$time_local] "$request" $status $body_bytes_sent'; - access_log {{ nginx_access_log }}; - error_log {{ nginx_error_log }}; - - ## - # Gzip Settings - ## - - gzip on; - - # gzip_vary on; - # gzip_proxied any; - # gzip_comp_level 6; - # gzip_buffers 16 8k; - # gzip_http_version 1.1; - # gzip_types text/plain text/css application/json application/javascript text/xml application/xml application/xml+rss text/javascript; - - ## - # Virtual Host Configs - ## - - include /etc/nginx/conf.d/*.conf; - include /etc/nginx/sites-enabled/*; -}