Created
May 22, 2020 12:29
-
-
Save mxrch/6de0ae3c5335ac8eb6489eb94daf4a02 to your computer and use it in GitHub Desktop.
Matomo NGINX config, but it's working for NGINX 1.18.X
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
server { | |
if ($host = yourwebsite.com) { | |
return 301 https://$host$request_uri; | |
} # managed by Certbot | |
listen 80; | |
server_name yourwebsite.com; | |
# Redirect all HTTP requests to HTTPS with a 301 Moved Permanently response. | |
location / { | |
return 301 https://$host$request_uri; | |
} | |
} | |
server { | |
listen 443 ssl http2; | |
server_name yourwebsite.com; # list all domains Matomo should be reachable from | |
access_log /var/log/nginx/matomo.access.log; | |
error_log /var/log/nginx/matomo.error.log; | |
## uncomment if you want to enable HSTS with 6 months cache | |
## ATTENTION: Be sure you know the implications of this change (you won't be able to disable HTTPS anymore) | |
#add_header Strict-Transport-Security max-age=15768000 always; | |
add_header Referrer-Policy origin always; # make sure outgoing links don't show the URL to the Matomo instance | |
add_header X-Content-Type-Options "nosniff" always; | |
add_header X-XSS-Protection "1; mode=block" always; | |
root /var/www/matomo/; # replace with path to your matomo instance | |
index index.php; | |
## only allow accessing the following php files | |
location ~ ^/(index|matomo|piwik|js/index|plugins/HeatmapSessionRecording/configs)\.php { | |
include fastcgi_params; # if your Nginx setup doesn't come with a default fastcgi-php config, you can fetch it from https://github.com/nginx/nginx/blob/master/conf/fastcgi.conf | |
try_files $fastcgi_script_name =404; # protects against CVE-2019-11043. If this line is already included in your snippets/fastcgi-php.conf you can comment it here. | |
#fastcgi_param HTTP_PROXY ""; # prohibit httpoxy: https://httpoxy.org/ | |
fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name; | |
fastcgi_pass unix:/var/run/php/php7.4-fpm.sock; #replace with the path to your PHP socket file | |
#fastcgi_pass 127.0.0.1:9000; # uncomment if you are using PHP via TCP sockets (e.g. Docker container) | |
} | |
## deny access to all other .php files | |
location ~* ^.+\.php$ { | |
deny all; | |
return 403; | |
} | |
## serve all other files normally | |
location / { | |
try_files $uri $uri/ =404; | |
} | |
## disable all access to the following directories | |
location ~ /(config|tmp|core|lang) { | |
deny all; | |
return 403; # replace with 404 to not show these directories exist | |
} | |
location ~ /\.ht { | |
deny all; | |
return 403; | |
} | |
location ~ js/container_.*_preview\.js$ { | |
expires off; | |
add_header Cache-Control 'private, no-cache, no-store'; | |
} | |
location ~ \.(gif|ico|jpg|png|svg|js|css|htm|html|mp3|mp4|wav|ogg|avi|ttf|eot|woff|woff2|json)$ { | |
allow all; | |
## Cache images,CSS,JS and webfonts for an hour | |
## Increasing the duration may improve the load-time, but may cause old files to show after an Matomo upgrade | |
expires 1h; | |
add_header Pragma public; | |
add_header Cache-Control "public"; | |
} | |
location ~ /(libs|vendor|plugins|misc/user) { | |
deny all; | |
return 403; | |
} | |
## properly display textfiles in root directory | |
location ~/(.*\.md|LEGALNOTICE|LICENSE) { | |
default_type text/plain; | |
} | |
ssl_certificate /etc/letsencrypt/live/yourwebsite.com/fullchain.pem; # managed by Certbot | |
ssl_certificate_key /etc/letsencrypt/live/yourwebsite.com/privkey.pem; # managed by Certbot | |
add_header Strict-Transport-Security "max-age=31536000" always; # managed by Certbot | |
ssl_trusted_certificate /etc/letsencrypt/live/yourwebsite.com/chain.pem; # managed by Certbot | |
} | |
# vim: filetype=nginx |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment