Files
2026-10-02 00:28:37 +08:00

67 lines
2.3 KiB
Nginx Configuration File
Raw Permalink Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# ------------------------------------------------------------
# 自律公约网站反代配置
# 域名:nurture.ppuc.lssa.fun
# ------------------------------------------------------------
server {
listen 443 ssl;
listen [::]:443 ssl;
http2 on;
server_name nurture.ppuc.lssa.fun;
# SSL 证书
ssl_certificate /etc/ssl/acme/ppuc.lssa.fun.fullchain.crt;
ssl_certificate_key /etc/ssl/acme/ppuc.lssa.fun.key;
# TLS 安全配置
ssl_protocols TLSv1.2 TLSv1.3;
ssl_ciphers ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305;
ssl_prefer_server_ciphers on;
ssl_session_timeout 10m;
# 基础安全头
add_header X-Content-Type-Options "nosniff" always;
add_header X-Frame-Options "SAMEORIGIN" always;
add_header X-XSS-Protection "1; mode=block" always;
# --------------------------------------------------------
# 1. 前端页面(Vue SPA)
# --------------------------------------------------------
location / {
proxy_pass http://127.0.0.1:4431/;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
# WebSocket 支持(Vite HMR 或未来实时功能预留)
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "upgrade";
}
# --------------------------------------------------------
# 2. 后端 API
# --------------------------------------------------------
location /api/ {
proxy_pass http://127.0.0.1:44310/;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
# 传递用户真实 IP 给后端(如需日志)
proxy_set_header X-Forwarded-Host $host;
}
}
# ------------------------------------------------------------
# HTTP → HTTPS 重定向
# ------------------------------------------------------------
server {
listen 80;
listen [::]:80;
server_name nurture.ppuc.lssa.fun;
return 301 https://$host$request_uri;
}