|
@@ -1,36 +1,7 @@
|
|
|
-# HTTP server - 重定向到 HTTPS
|
|
|
server {
|
|
|
listen 80;
|
|
|
- server_name www.1919com.com 1919com.com;
|
|
|
- return 301 https://www.1919com.com$request_uri;
|
|
|
-}
|
|
|
-
|
|
|
-server {
|
|
|
- listen 443 ssl;
|
|
|
- server_name 1919com.com;
|
|
|
- return 301 https://www.1919com.com$request_uri;
|
|
|
-}
|
|
|
-
|
|
|
-server {
|
|
|
- listen 443 ssl;
|
|
|
- server_name 1919com.com;
|
|
|
-
|
|
|
- # SSL 证书配置
|
|
|
- ssl_certificate /etc/nginx/certs/9b482160a208df4e.crt;
|
|
|
- ssl_certificate_key /etc/nginx/certs/9b482160a208df4e.key;
|
|
|
- ssl_trusted_certificate /etc/nginx/certs/9b482160a208df4e.pem;
|
|
|
-
|
|
|
- # SSL 参数优化
|
|
|
- ssl_protocols TLSv1.2 TLSv1.3;
|
|
|
- ssl_prefer_server_ciphers on;
|
|
|
- ssl_ciphers ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384;
|
|
|
- ssl_session_cache shared:SSL:10m;
|
|
|
- ssl_session_timeout 10m;
|
|
|
-
|
|
|
- # HSTS (可选,但推荐)
|
|
|
- add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always;
|
|
|
-
|
|
|
- # Proxy settings
|
|
|
+ server_name 1919com.com www.1919com.com;
|
|
|
+
|
|
|
location / {
|
|
|
proxy_pass http://match-vote-nextjs-nextjs-1:3000; # 使用完整的容器名称
|
|
|
proxy_http_version 1.1;
|
|
@@ -74,6 +45,6 @@ server {
|
|
|
gzip_types text/plain text/css text/xml application/json application/javascript application/rss+xml application/atom+xml image/svg+xml;
|
|
|
|
|
|
# 日志格式
|
|
|
- access_log /var/log/nginx/match.dzhhzy.com.access.log;
|
|
|
- error_log /var/log/nginx/match.dzhhzy.com.error.log;
|
|
|
+ access_log /var/log/nginx/1919com.com.access.log;
|
|
|
+ error_log /var/log/nginx/1919com.com.error.log;
|
|
|
}
|