1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95
| upstream jenkins { keepalive 32; server 127.0.0.1:8080; }
map $http_upgrade $connection_upgrade { default upgrade; '' close; }
server {
server_name deploy.example.com local.example.com;
access_log /var/log/nginx/jenkins.access.log; error_log /var/log/nginx/jenkins.error.log;
ignore_invalid_headers off;
location ~ "^/static/[0-9a-fA-F]{8}\/(.*)$" { rewrite "^/static/[0-9a-fA-F]{8}\/(.*)" /$1 last; }
location /userContent { root /var/lib/jenkins/; if (!-f $request_filename){ rewrite (.*) /$1 last; break; } sendfile on; } location / {
sendfile off; proxy_pass http://jenkins; proxy_redirect default; proxy_http_version 1.1; proxy_set_header Connection $connection_upgrade; proxy_set_header Upgrade $http_upgrade; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; proxy_max_temp_file_size 0; client_max_body_size 10m; client_body_buffer_size 128k; proxy_connect_timeout 90; proxy_send_timeout 90; proxy_read_timeout 90; proxy_buffering off; proxy_request_buffering off; proxy_set_header Connection ""; }
listen 443 ssl; ssl_certificate /etc/letsencrypt/live/repo.example.com/fullchain.pem; ssl_certificate_key /etc/letsencrypt/live/repo.example.com/privkey.pem; include /etc/letsencrypt/options-ssl-nginx.conf; ssl_dhparam /etc/letsencrypt/ssl-dhparams.pem;
}
server { if ($host = deploy.example.com) { return 301 https://$host$request_uri; }
if ($host = local.example.com) { return 301 https://$host$request_uri; }
listen 80;
server_name deploy.example.com local.example.com; return 404;
}
|