mirror of
https://github.com/kevinveenbirkenbach/computer-playbook.git
synced 2025-11-15 17:46:28 +00:00
- added new file roles/web-app-shopware/files/framework.yaml defining trusted_proxies and trusted_headers for Symfony - mounted framework.yaml into /var/www/html/config/packages/ in docker-compose - exposed new role vars SHOPWARE_FRAMEWORK_HOST/DOCKER for mounting path - rendered framework.yaml via Ansible copy task with proper permissions - adjusted env.j2 to set TRUSTED_PROXIES and TRUSTED_HOSTS dynamically from domains and networks - added SHOPWARE_DOMAIN var to vars/main.yml - removed inline framework.yaml creation from Dockerfile (now managed via mount) - updated proxy template (html.conf.j2) to include X-Forwarded-Ssl header - improved init.sh permission handling for shared volumes See ChatGPT conversation for implementation details and rationale: https://chatgpt.com/share/690d4fe7-2830-800f-8b6d-b868e7fe0e97
45 lines
1.6 KiB
Django/Jinja
45 lines
1.6 KiB
Django/Jinja
{% set location = location | default("/")%}
|
|
location {{location}}
|
|
{
|
|
{% if oauth2_proxy_enabled | default(false) | bool %}
|
|
{% include 'roles/web-app-oauth2-proxy/templates/following_directives.conf.j2'%}
|
|
{% endif %}
|
|
|
|
{% set _loc = location|trim %}
|
|
proxy_pass http://127.0.0.1:{{ http_port }}{{ (_loc|regex_replace('^(?:=|\\^~)\\s*','')) if not (_loc is match('^(@|~)')) else '' }};
|
|
|
|
# headers
|
|
proxy_set_header Host $host;
|
|
proxy_set_header Authorization $http_authorization;
|
|
proxy_set_header X-Real-IP $remote_addr;
|
|
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
|
proxy_set_header X-Forwarded-Proto $scheme;
|
|
proxy_set_header X-Forwarded-Port {{ WEB_PORT }};
|
|
proxy_set_header X-Forwarded-Ssl on;
|
|
proxy_pass_request_headers on;
|
|
|
|
{% include 'roles/sys-svc-proxy/templates/headers/content_security_policy.conf.j2' %}
|
|
|
|
{% include 'roles/sys-svc-proxy/templates/headers/access_control_allow.conf.j2' %}
|
|
|
|
# WebSocket specific header
|
|
proxy_http_version 1.1;
|
|
proxy_set_header Upgrade $http_upgrade;
|
|
proxy_set_header Connection "upgrade";
|
|
|
|
# timeouts
|
|
proxy_connect_timeout 5s;
|
|
proxy_send_timeout 900s;
|
|
proxy_read_timeout 900s;
|
|
send_timeout 900s;
|
|
|
|
{% set proxy_lua_enabled = proxy_lua_enabled | default(true) | bool %}
|
|
# Buffering needs to be activ, so that lua can do str replaces
|
|
proxy_buffering {{ 'on' if proxy_lua_enabled else 'off' }};
|
|
proxy_request_buffering {{ 'on' if proxy_lua_enabled else 'off' }};
|
|
|
|
{% if proxy_lua_enabled %}
|
|
proxy_set_header Accept-Encoding "";
|
|
{% include 'roles/sys-front-inj-all/templates/location.lua.j2'%}
|
|
{% endif %}
|
|
} |