fix: harden node upgrades and prepare 1.9.0-alpha
This commit is contained in:
@@ -1,3 +1,42 @@
|
||||
# BEGIN ARCHIPELAGO MANAGEMENT SOURCE GUARD
|
||||
# Use the original socket peer, before any real_ip / forwarded-header rewrite.
|
||||
geo $realip_remote_addr $archy_management_private_source {
|
||||
default 0;
|
||||
127.0.0.0/8 1;
|
||||
169.254.0.0/16 1;
|
||||
10.0.0.0/8 1;
|
||||
172.16.0.0/12 1;
|
||||
192.168.0.0/16 1;
|
||||
100.64.0.0/10 1;
|
||||
::1/128 1;
|
||||
fc00::/7 1;
|
||||
fe80::/10 1;
|
||||
}
|
||||
# A configured trusted proxy may have rewritten remote_addr. Require both
|
||||
# the original peer and the validated effective client to be private.
|
||||
geo $remote_addr $archy_management_private_client {
|
||||
default 0;
|
||||
127.0.0.0/8 1;
|
||||
169.254.0.0/16 1;
|
||||
10.0.0.0/8 1;
|
||||
172.16.0.0/12 1;
|
||||
192.168.0.0/16 1;
|
||||
100.64.0.0/10 1;
|
||||
::1/128 1;
|
||||
fc00::/7 1;
|
||||
fe80::/10 1;
|
||||
}
|
||||
map $http_x_archipelago_public_ingress $archy_management_public_ingress {
|
||||
default 1;
|
||||
'' 0;
|
||||
}
|
||||
map "$archy_management_private_source:$archy_management_private_client:$archy_management_public_ingress:$uri" $archy_management_denied {
|
||||
default 1;
|
||||
~^1:1:0: 0;
|
||||
"~^[01]:[01]:[01]:/\.well-known/acme-challenge/[A-Za-z0-9_-]+$" 0;
|
||||
}
|
||||
# END ARCHIPELAGO MANAGEMENT SOURCE GUARD
|
||||
|
||||
# Rate limit zones
|
||||
limit_req_zone $binary_remote_addr zone=rpc:10m rate=20r/s;
|
||||
limit_req_zone $binary_remote_addr zone=auth:10m rate=3r/s;
|
||||
@@ -8,6 +47,8 @@ resolver 1.1.1.1 8.8.8.8 valid=300s ipv6=off;
|
||||
resolver_timeout 5s;
|
||||
|
||||
server {
|
||||
if ($archy_management_denied) { return 404; }
|
||||
|
||||
listen 80 default_server;
|
||||
# IPv6 listener is REQUIRED: companion phones reach this node over the
|
||||
# FIPS mesh at its fips0 ULA (http://[fdxx:…]) — without [::]:80 that
|
||||
@@ -48,7 +89,7 @@ server {
|
||||
# Serve Nginx Proxy Manager HTTP-01 challenge files before the SPA fallback.
|
||||
location ^~ /.well-known/acme-challenge/ {
|
||||
default_type text/plain;
|
||||
root /var/lib/archipelago/nginx-proxy-manager/data/letsencrypt-acme-challenge;
|
||||
root /var/lib/archipelago/nginx-proxy-manager/letsencrypt-acme-challenge;
|
||||
try_files $uri =404;
|
||||
}
|
||||
|
||||
@@ -1021,6 +1062,8 @@ server {
|
||||
|
||||
# HTTPS - required for PWA install (Add to Home Screen) from dev servers
|
||||
server {
|
||||
if ($archy_management_denied) { return 404; }
|
||||
|
||||
listen 443 ssl default_server;
|
||||
listen [::]:443 ssl default_server;
|
||||
server_name _;
|
||||
@@ -1035,6 +1078,12 @@ server {
|
||||
include snippets/archipelago-pwa.conf;
|
||||
|
||||
# Same CA download over HTTPS — see the note in the HTTP block above.
|
||||
location ^~ /.well-known/acme-challenge/ {
|
||||
default_type text/plain;
|
||||
root /var/lib/archipelago/nginx-proxy-manager/letsencrypt-acme-challenge;
|
||||
try_files $uri =404;
|
||||
}
|
||||
|
||||
location = /ca.crt {
|
||||
alias /etc/archipelago/ssl/ca-download.crt;
|
||||
default_type application/x-x509-ca-cert;
|
||||
|
||||
Reference in New Issue
Block a user