Skip to content

Instantly share code, notes, and snippets.

@zshanabek
Last active August 18, 2021 10:03
Show Gist options
  • Save zshanabek/59d0da6e89e083bbc93ef64f072088cb to your computer and use it in GitHub Desktop.
Save zshanabek/59d0da6e89e083bbc93ef64f072088cb to your computer and use it in GitHub Desktop.
nginx config for vps
server {
listen 80;
server_name akv.kz www.akv.kz;
return 301 https://$server_name$request_uri;
}
server{
keepalive_timeout 5;
client_max_body_size 126m;
access_log /root/akv-backend/logs/nginx-access.log;
error_log /root/akv-backend/logs/nginx-error.log;
location = /favicon.ico { access_log off; log_not_found off; }
location /static/ {
root /var/www;
}
location /media/ {
root /var/www;
}
location / {
include proxy_params;
proxy_pass http://unix:/run/gunicorn.sock;
}
location /ws {
proxy_pass http://0.0.0.0:8007;
proxy_http_version 1.1;
proxy_read_timeout 86400;
proxy_redirect off;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "Upgrade";
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Host $server_name;
}
proxy_headers_hash_max_size 512;
listen 443 ssl; # managed by Certbot
ssl_certificate /etc/letsencrypt/live/akv.kz/fullchain.pem; # managed by Certbot
ssl_certificate_key /etc/letsencrypt/live/akv.kz/privkey.pem; # managed by Certbot
include /etc/letsencrypt/options-ssl-nginx.conf; # managed by Certbot
ssl_dhparam /etc/letsencrypt/ssl-dhparams.pem; # managed by Certbot
}
server {
if ($host = www.akv.kz) {
return 301 https://$host$request_uri;
} # managed by Certbot
if ($host = akv.kz) {
return 301 https://$host$request_uri;
} # managed by Certbot
listen 80 default_server;
server_name akv.kz www.akv.kz;
return 404; # managed by Certbot
}
# for frontend
server {
listen 80;
server_name akv.kz www.akv.kz;
location / {
proxy_pass http://localhost:3000;
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Host $host;
proxy_set_header Connection 'upgrade';
proxy_cache_bypass $http_upgrade;
}
}
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment