Fixed nginx conf issue

This commit is contained in:
2024-08-08 14:30:22 -04:00
parent 07ff3a2e39
commit c49dcafc34
2 changed files with 98 additions and 136 deletions
+9 -26
View File
@@ -1,5 +1,5 @@
#user nobody; #user nobody;
worker_processes 8; worker_processes 4;
#error_log logs/error.log; #error_log logs/error.log;
#error_log logs/error.log notice; #error_log logs/error.log notice;
@@ -12,6 +12,7 @@ events {
worker_connections 1024; worker_connections 1024;
} }
http { http {
client_max_body_size 4g; client_max_body_size 4g;
@@ -25,20 +26,8 @@ http {
auto_ssl = (require "resty.auto-ssl").new() auto_ssl = (require "resty.auto-ssl").new()
auto_ssl:set("storage_adapter", "resty.auto-ssl.storage_adapters.redis") auto_ssl:set("storage_adapter", "resty.auto-ssl.storage_adapters.redis")
auto_ssl:set("allow_domain", function(domain) auto_ssl:set("allow_domain", function(domain)
ngx.log(ngx.ERR, "!!!!!!!! nginx.conf allow_domain !!!!!!!!!! ", domain, ngx.ctx.toAllow)
return ngx.ctx.toAllow
end)
auto_ssl:set("request_domain", function(ssl, ssl_options)
local json = require "cjson" local json = require "cjson"
local redis = require "resty.redis"
local socket = assert(require "socket.unix"()) local socket = assert(require "socket.unix"())
local domain, err = ssl.server_name()
ngx.log(ngx.ERR, "!!!!!! nginx.conf request_domain !!!!!!!", domain)
local function connect(path) local function connect(path)
assert(socket:settimeout(.1)) assert(socket:settimeout(.1))
local status,err = pcall(function() assert(socket:connect(path)) end) local status,err = pcall(function() assert(socket:connect(path)) end)
@@ -52,7 +41,9 @@ http {
return false return false
end end
local redis = require "resty.redis"
local red = redis:new() local red = redis:new()
red:set_timeout(1000) -- 1 second red:set_timeout(1000) -- 1 second
local ok, err = red:connect("127.0.0.1", 6379) local ok, err = red:connect("127.0.0.1", 6379)
@@ -61,7 +52,7 @@ http {
return ngx.exit(598) return ngx.exit(598)
end end
local res, err = red:hgetall("proxy_Host_"..domain) local res, err = red:hgetall("proxy_host_"..domain)
local res = red:array_to_hash(res) local res = red:array_to_hash(res)
if not res["ip"] then if not res["ip"] then
@@ -79,21 +70,13 @@ http {
end end
if not res["ip"] then if not res["ip"] then
ngx.say('The domain is not allowed on this server.') ngx.log(ngx.ERR, "no host found for key ", domain)
ngx.exit(406) -- ngx.exit(406)
return false return false
end end
ngx.ctx.targetInfo = res return true
ngx.ctx.toAllow = true;
if res['wildcard_parent'] then
return res['wildcard_parent'], err
end
return domain, err
end) end)
auto_ssl:init() auto_ssl:init()
} }
@@ -135,7 +118,7 @@ http {
#keepalive_timeout 0; #keepalive_timeout 0;
keepalive_timeout 65; keepalive_timeout 65;
gzip on; #gzip on;
include sites-enabled/*; include sites-enabled/*;
} }
+13 -34
View File
@@ -19,23 +19,13 @@ server {
set $target_port ''; set $target_port '';
set $header_host $host; set $header_host $host;
access_by_lua { access_by_lua '
local host = ngx.var.host
function getTargetInfo(domain, targetInfo) local uri = ngx.var.uri
if targetInfo then local scheme = ngx.var.scheme
ngx.log(ngx.ERR, "!!!!!!! getTargetInfo targetFound")
return targetInfo
end
local json = require "cjson" local json = require "cjson"
local redis = require "resty.redis"
local socket = assert(require "socket.unix"()) local socket = assert(require "socket.unix"())
local domain, err = ssl.server_name()
ngx.log(ngx.ERR, "!!!!!! nginx.conf request_domain !!!!!!!", domain)
local function connect(path) local function connect(path)
assert(socket:settimeout(.1)) assert(socket:settimeout(.1))
local status,err = pcall(function() assert(socket:connect(path)) end) local status,err = pcall(function() assert(socket:connect(path)) end)
@@ -43,13 +33,14 @@ server {
return false return false
end end
if not domain then if not host then
ngx.log(ngx.ERR, "no host header found") ngx.log(ngx.ERR, "no host header found")
ngx.exit(499) return ngx.exit(499)
return false
end end
local redis = require "resty.redis"
local red = redis:new() local red = redis:new()
red:set_timeout(1000) -- 1 second red:set_timeout(1000) -- 1 second
local ok, err = red:connect("127.0.0.1", 6379) local ok, err = red:connect("127.0.0.1", 6379)
@@ -58,12 +49,12 @@ server {
return ngx.exit(598) return ngx.exit(598)
end end
local res, err = red:hgetall("proxy_Host_"..domain) local res, err = red:hgetall("proxy_host_"..host)
local res = red:array_to_hash(res) local res = red:array_to_hash(res)
if not res["ip"] then if not res["ip"] then
if connect("/var/run/proxy_lookup.socket") then if connect("/var/run/proxy_lookup.socket") then
assert(socket:send(json.encode({domain = domain}))) assert(socket:send(json.encode({domain = host})))
while 1 do while 1 do
local s, status, partial = socket:receive() local s, status, partial = socket:receive()
if partial then if partial then
@@ -76,22 +67,10 @@ server {
end end
if not res["ip"] then if not res["ip"] then
ngx.say('The domain is not allowed on this server.') ngx.log(ngx.ERR, "no host found for key ", host)
ngx.exit(406) return ngx.exit(406)
return false
end end
ngx.ctx.targetInfo = res
ngx.ctx.toAllow = true;
end
local host = ngx.var.host
local uri = ngx.var.uri
local scheme = ngx.var.scheme
local res = getTargetInfo(host, ngx.ctx.targetInfo)
if scheme == "http" then if scheme == "http" then
if res["forcessl"] == "true" then if res["forcessl"] == "true" then
return ngx.redirect("https://"..host..uri, 301) return ngx.redirect("https://"..host..uri, 301)
@@ -108,7 +87,7 @@ server {
ngx.var.target = res["ip"] ngx.var.target = res["ip"]
ngx.var.target_port = res["targetPort"] ngx.var.target_port = res["targetPort"]
} ';
resolver 192.168.1.1 ipv6=off; #8.8.4.4; # use Google's open DNS server resolver 192.168.1.1 ipv6=off; #8.8.4.4; # use Google's open DNS server