Polish up configuration for web1, seems we're mostly live

This commit is contained in:
Salt 2020-12-18 06:25:00 -06:00
parent 516a42972d
commit ba868fa76c

View File

@ -87,20 +87,16 @@
- proxy_http.load - proxy_http.load
- rewrite.load - rewrite.load
apache_vhosts: apache_vhosts:
- servername: web1.desu.ltd - servername: nc.desu.ltd
serveralias: "*"
extra_parameters: | extra_parameters: |
RewriteEngine On Redirect permanent / https://nc.desu.ltd
RewriteRule "^http\:" "^https:" [R=302,L] - servername: desu.ltd
apache_vhosts_ssl: extra_parameters: |
Redirect permanent / https://desu.ltd
- servername: git.desu.ltd - servername: git.desu.ltd
extra_parameters: | extra_parameters: |
ProxyPreserveHost On Redirect permanent / https://git.desu.ltd
ProxyRequests Off apache_vhosts_ssl:
ProxyPass / http://127.0.0.1:3000/ nocanon retry=1
certificate_file: /etc/letsencrypt/live/desu.ltd/fullchain.pem
certificate_key_file: /etc/letsencrypt/live/desu.ltd/privkey.pem
certificate_chain_file: /etc/letsencrypt/live/desu.ltd/chain.pem
- servername: nc.desu.ltd - servername: nc.desu.ltd
documentroot: /var/www/html/nextcloud documentroot: /var/www/html/nextcloud
certificate_file: /etc/letsencrypt/live/desu.ltd/fullchain.pem certificate_file: /etc/letsencrypt/live/desu.ltd/fullchain.pem
@ -111,6 +107,14 @@
certificate_file: /etc/letsencrypt/live/desu.ltd/fullchain.pem certificate_file: /etc/letsencrypt/live/desu.ltd/fullchain.pem
certificate_key_file: /etc/letsencrypt/live/desu.ltd/privkey.pem certificate_key_file: /etc/letsencrypt/live/desu.ltd/privkey.pem
certificate_chain_file: /etc/letsencrypt/live/desu.ltd/chain.pem certificate_chain_file: /etc/letsencrypt/live/desu.ltd/chain.pem
- servername: git.desu.ltd
extra_parameters: |
ProxyPreserveHost On
ProxyRequests Off
ProxyPass / http://127.0.0.1:3000/ nocanon retry=1
certificate_file: /etc/letsencrypt/live/desu.ltd/fullchain.pem
certificate_key_file: /etc/letsencrypt/live/desu.ltd/privkey.pem
certificate_chain_file: /etc/letsencrypt/live/desu.ltd/chain.pem
become: yes become: yes
tags: [ web, apache ] tags: [ web, apache ]
- role: certbot - role: certbot
@ -180,13 +184,13 @@
gitea_app_name: "Git Desu" gitea_app_name: "Git Desu"
# Core config # Core config
gitea_db_type: postgres gitea_db_type: postgres
gitea_db_host: 192.168.122.169:5432 gitea_db_host: 192.168.164.156:5432
gitea_db_name: gitea gitea_db_name: gitea
gitea_db_user: gitea gitea_db_user: gitea
gitea_db_password: "{{ secret_gitea_db_pass }}" gitea_db_password: "{{ secret_gitea_db_pass }}"
gitea_http_domain: git.desu.ltd gitea_http_domain: git.desu.ltd
gitea_oauth2_enabled: no gitea_oauth2_enabled: no
gitea_root_url: http://git.desu.ltd gitea_root_url: https://git.desu.ltd
gitea_shell: "/bin/bash" gitea_shell: "/bin/bash"
gitea_ssh_domain: git.desu.ltd gitea_ssh_domain: git.desu.ltd
gitea_ssh_port: 22 gitea_ssh_port: 22