Block MS from the public entry
Build docker image and push to registry.bitdeals.org / main-build-job (push) Successful in 40s
Build docker image and push to registry.bitdeals.org / main-build-job (push) Successful in 40s
This commit is contained in:
@@ -26,6 +26,11 @@ frontend http
|
|||||||
acl certbot path_beg /.well-known/acme-challenge/
|
acl certbot path_beg /.well-known/acme-challenge/
|
||||||
use_backend certbot if certbot
|
use_backend certbot if certbot
|
||||||
|
|
||||||
|
# # Fool-proof: MS has no auth — never expose /ms publicly.
|
||||||
|
# acl is_ms path -i /ms
|
||||||
|
# acl is_ms path_beg -i /ms/
|
||||||
|
# http-request deny deny_status 404 if is_ms
|
||||||
|
|
||||||
frontend https
|
frontend https
|
||||||
bind *:443 ssl crt /usr/local/etc/haproxy/certificates/site.pem
|
bind *:443 ssl crt /usr/local/etc/haproxy/certificates/site.pem
|
||||||
http-request add-header X-Forwarded-Proto https
|
http-request add-header X-Forwarded-Proto https
|
||||||
@@ -34,6 +39,11 @@ frontend https
|
|||||||
acl certbot path_beg /.well-known/acme-challenge/
|
acl certbot path_beg /.well-known/acme-challenge/
|
||||||
use_backend certbot if certbot
|
use_backend certbot if certbot
|
||||||
|
|
||||||
|
# # Fool-proof: MS has no auth — never expose /ms publicly.
|
||||||
|
# acl is_ms path -i /ms
|
||||||
|
# acl is_ms path_beg -i /ms/
|
||||||
|
# http-request deny deny_status 404 if is_ms
|
||||||
|
|
||||||
backend default-backend-http
|
backend default-backend-http
|
||||||
http-request set-header X-Forwarded-Proto https if { ssl_fc }
|
http-request set-header X-Forwarded-Proto https if { ssl_fc }
|
||||||
server main nginx:80 check
|
server main nginx:80 check
|
||||||
|
|||||||
Reference in New Issue
Block a user