about summary refs log tree commit diff
path: root/nanobox/nginx-stream.conf.erb
diff options
context:
space:
mode:
authorDan Hunsaker <danhunsaker@gmail.com>2019-06-14 06:52:32 -0600
committerEugen Rochko <eugen@zeonfederated.com>2019-06-14 14:52:31 +0200
commit54192a9b6f8ee68114e3bc9ebf241099456e85f6 (patch)
tree35f64980c020d48e45ad92d8af590a82e165f7eb /nanobox/nginx-stream.conf.erb
parentc9eeb2e832b5b36a86028bbec7a353c32be510a7 (diff)
Resync Nanobox files with the 2.9.0 release (#11083)
Diffstat (limited to 'nanobox/nginx-stream.conf.erb')
-rw-r--r--nanobox/nginx-stream.conf.erb17
1 files changed, 13 insertions, 4 deletions
diff --git a/nanobox/nginx-stream.conf.erb b/nanobox/nginx-stream.conf.erb
index 12bcc8ca5..4ea6e30fc 100644
--- a/nanobox/nginx-stream.conf.erb
+++ b/nanobox/nginx-stream.conf.erb
@@ -10,10 +10,13 @@ http {
     sendfile on;
 
     gzip on;
-    gzip_http_version 1.1;
+    gzip_disable "MSIE [1-6]\.";
+    gzip_vary on;
     gzip_proxied any;
+    gzip_comp_level 6;
+    gzip_buffers 16 8k;
     gzip_min_length 500;
-    gzip_disable "MSIE [1-6]\.";
+    gzip_http_version 1.1;
     gzip_types text/plain text/xml text/javascript text/css text/comma-separated-values application/xml+rss application/xml application/x-javascript application/json application/javascript application/atom+xml;
 
     # Proxy upstream to the node process
@@ -31,11 +34,13 @@ http {
         # Listen on port 8080
         listen 8080;
 
-        add_header Strict-Transport-Security "max-age=31536000";
-        # add_header Content-Security-Policy "style-src 'self' 'unsafe-inline'; script-src 'self'; object-src 'self'; img-src data: https:; media-src data: https:; connect-src 'self' wss://<%= ENV["LOCAL_DOMAIN"] %>; upgrade-insecure-requests";
+        keepalive_timeout    70;
+        client_max_body_size 80M;
 
         root /app/public;
 
+        add_header Strict-Transport-Security "max-age=31536000";
+
         location / {
             try_files $uri @node;
         }
@@ -43,6 +48,10 @@ http {
         # Proxy connections to node
         location @node {
             proxy_set_header Host $host;
+            proxy_set_header X-Real-IP $remote_addr;
+            proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
+            proxy_set_header X-Forwarded-Proto https;
+            proxy_set_header Proxy "";
 
             proxy_pass http://node;
             proxy_buffering off;