game.makeryang.com.conf 1.5 KB

1234567891011121314151617181920212223242526272829303132333435363738394041
  1. server {
  2. listen 80;
  3. listen [::]:80;
  4. listen 443 ssl http2;
  5. listen [::]:443 ssl http2;
  6. ssl_certificate /etc/nginx/ssl/game.makeryang.com.pem;
  7. ssl_certificate_key /etc/nginx/ssl/game.makeryang.com.key;
  8. ssl_protocols TLSv1 TLSv1.1 TLSv1.2 TLSv1.3;
  9. ssl_ciphers TLS13-AES-256-GCM-SHA384:TLS13-CHACHA20-POLY1305-SHA256:TLS13-AES-128-GCM-SHA256:TLS13-AES-128-CCM-8-SHA256:TLS13-AES-128-CCM-SHA256:EECDH+CHACHA20:EECDH+AES128:RSA+AES128:EECDH+AES256:RSA+AES256:EECDH+3DES:RSA+3DES:!MD5;
  10. ssl_prefer_server_ciphers on;
  11. ssl_session_timeout 10m;
  12. ssl_session_cache builtin:1000 shared:SSL:10m;
  13. ssl_buffer_size 1400;
  14. add_header Strict-Transport-Security max-age=15768000;
  15. ssl_stapling on;
  16. ssl_stapling_verify on;
  17. server_name game.makeryang.com;
  18. access_log off;
  19. if ($ssl_protocol = "") { return 301 https://$host$request_uri; }
  20. location / {
  21. client_max_body_size 100m;
  22. proxy_set_header X-Forwarded-Host $host;
  23. proxy_set_header X-Forwarded-Server $host;
  24. proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
  25. proxy_pass http://localhost:7000/;
  26. proxy_ignore_client_abort on;
  27. proxy_set_header Cookie $http_cookie;
  28. proxy_set_header Host $host;
  29. }
  30. location ~ .*\.(gif|jpg|jpeg|png|bmp|swf|flv|mp4|ico)$ {
  31. expires 60s;
  32. access_log off;
  33. }
  34. location ~ .*\.(js|css)?$ {
  35. expires 60s;
  36. access_log off;
  37. }
  38. location ~ /(\.user\.ini|\.ht|\.git|\.svn|\.project|LICENSE|README\.md) {
  39. deny all;
  40. }
  41. }