diff options
| author | dumpfmprod <dumpfmprod@ubuntu.(none)> | 2010-05-18 14:10:44 -0400 |
|---|---|---|
| committer | dumpfmprod <dumpfmprod@ubuntu.(none)> | 2010-05-18 14:10:44 -0400 |
| commit | 9da4e621d664a2d470a16fe1fd7869edf41e31cf (patch) | |
| tree | df450226cb831009c8172c1afb3130252deaf108 | |
| parent | 58487f47597fc0daed05d9e3d885b0840cac926c (diff) | |
Commit nginx/iptables config info
| -rw-r--r-- | conf/iptables.rules | 33 | ||||
| -rw-r--r-- | conf/nginx.conf | 40 |
2 files changed, 54 insertions, 19 deletions
diff --git a/conf/iptables.rules b/conf/iptables.rules new file mode 100644 index 0000000..9eb55e6 --- /dev/null +++ b/conf/iptables.rules @@ -0,0 +1,33 @@ +# Generated by iptables-save v1.3.8 on Tue May 18 01:07:47 2010 +*raw +:PREROUTING ACCEPT [244582158:66961882286] +:OUTPUT ACCEPT [203811901:346352124993] +COMMIT +# Completed on Tue May 18 01:07:47 2010 +# Generated by iptables-save v1.3.8 on Tue May 18 01:07:47 2010 +*nat +:PREROUTING ACCEPT [39048:2606984] +:POSTROUTING ACCEPT [1021206:65956360] +:OUTPUT ACCEPT [1021206:65956360] +-A PREROUTING -i eth0 -p tcp -m tcp --dport 80 -j REDIRECT --to-ports 8080 +COMMIT +# Completed on Tue May 18 01:07:47 2010 +# Generated by iptables-save v1.3.8 on Tue May 18 01:07:47 2010 +*mangle +:PREROUTING ACCEPT [244582158:66961882286] +:INPUT ACCEPT [244582077:66961875069] +:FORWARD ACCEPT [0:0] +:OUTPUT ACCEPT [203811901:346352124993] +:POSTROUTING ACCEPT [203811901:346352124993] +COMMIT +# Completed on Tue May 18 01:07:47 2010 +# Generated by iptables-save v1.3.8 on Tue May 18 01:07:47 2010 +*filter +:INPUT ACCEPT [244579120:66961608666] +:FORWARD ACCEPT [0:0] +:OUTPUT ACCEPT [203811901:346352124993] +:fail2ban-ssh - [0:0] +-A INPUT -p tcp -m multiport --dports 22 -j fail2ban-ssh +-A fail2ban-ssh -j RETURN +COMMIT +# Completed on Tue May 18 01:07:47 2010 diff --git a/conf/nginx.conf b/conf/nginx.conf index bbab6f0..45a98eb 100644 --- a/conf/nginx.conf +++ b/conf/nginx.conf @@ -1,7 +1,6 @@ -user www-data; +user dumpfmprod; worker_processes 5; - -error_log /var/log/nginx/error.log; +error_log /home/dumpfmprod/prod/log/nginx/error.log; pid /var/run/nginx.pid; events { @@ -10,9 +9,8 @@ events { } http { - include /etc/nginx/mime.types; - - access_log /var/log/nginx/access.log; + include /etc/nginx/mime.types; + access_log /home/dumpfmprod/prod/log/nginx/error.log; sendfile on; #tcp_nopush on; @@ -27,20 +25,24 @@ http { include /etc/nginx/conf.d/*.conf; server { - listen 80; + listen 80; + server_name .dump.fm; - location ^~* ^/(avatars|images)/ { - root /home/ubuntu/dumpfm; - expires 30d; - } + location ~* /(avatars|images)/ { + root /home/dumpfmprod/prod; + expires 30d; + } - location ^~* ^/static/ { - root /home/ubuntu/dumpfm; - expires 30m; - } + location ~* /static/ { + root /home/dumpfmprod/prod; + expires 5m; + } - location / { - proxy_pass http://127.0.0.1:8080; - } + location / { + proxy_pass http://127.0.0.1:8080; + proxy_redirect off; + proxy_set_header Host $host; + proxy_set_header X-Real-IP $remote_addr; + } } -} +}
\ No newline at end of file |
