You can not select more than 25 topics
Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
40 lines
1.0 KiB
40 lines
1.0 KiB
upstream backend {
|
|
ip_hash; # DONT CHANGE IT
|
|
{% for host in groups['vaultwarden'] %}
|
|
server {{ hostvars[host]['private_ip'] }}:{{ vaultwarden_port }} weight=5;
|
|
{% endfor %}
|
|
keepalive 64;
|
|
}
|
|
|
|
server {
|
|
listen 80;
|
|
server_name {{ vaultwarden_domain }};
|
|
location / {
|
|
return 301 https://$host$request_uri;
|
|
}
|
|
location /.well-known/acme-challenge/ {
|
|
root /var/www/certbot;
|
|
}
|
|
}
|
|
|
|
server {
|
|
listen 443 ssl;
|
|
listen [::]:443 ssl;
|
|
http2 on;
|
|
server_name {{ vaultwarden_domain }};
|
|
|
|
ssl_certificate /etc/letsencrypt/live/{{ vaultwarden_domain }}/fullchain.pem;
|
|
ssl_certificate_key /etc/letsencrypt/live/{{ vaultwarden_domain }}/privkey.pem;
|
|
|
|
location / {
|
|
proxy_http_version 1.1;
|
|
proxy_set_header Upgrade $http_upgrade;
|
|
|
|
proxy_set_header Host $host;
|
|
proxy_set_header X-Real-IP $remote_addr;
|
|
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
|
proxy_set_header X-Forwarded-Proto $scheme;
|
|
|
|
proxy_pass http://backend;
|
|
}
|
|
}
|
|
|