Skip to content
Projects
Groups
Snippets
Help
Loading...
Help
Support
Keyboard shortcuts
?
Submit feedback
Contribute to GitLab
Sign in / Register
Toggle navigation
G
gitlab-ce
Project overview
Project overview
Details
Activity
Releases
Repository
Repository
Files
Commits
Branches
Tags
Contributors
Graph
Compare
Issues
0
Issues
0
List
Boards
Labels
Milestones
Merge Requests
0
Merge Requests
0
Analytics
Analytics
Repository
Value Stream
Wiki
Wiki
Snippets
Snippets
Members
Members
Collapse sidebar
Close sidebar
Activity
Graph
Create a new issue
Commits
Issue Boards
Open sidebar
Kazuhiko Shiozaki
gitlab-ce
Commits
70f30abd
Commit
70f30abd
authored
Nov 10, 2014
by
Marin Jankovski
Browse files
Options
Browse Files
Download
Plain Diff
Merge pull request #8273 from bbodenmiller/nginx-updates
Nginx updates
parents
6641341b
271a3520
Changes
2
Show whitespace changes
Inline
Side-by-side
Showing
2 changed files
with
15 additions
and
16 deletions
+15
-16
lib/support/nginx/gitlab
lib/support/nginx/gitlab
+5
-2
lib/support/nginx/gitlab-ssl
lib/support/nginx/gitlab-ssl
+10
-14
No files found.
lib/support/nginx/gitlab
View file @
70f30abd
## GitLab
## GitLab
##
Maintainer: @randx
##
Contributors: randx, yin8086, sashkab, orkoden, axilleas, bbodenmiller
##
##
## Lines starting with two hashes (##) are comments with information.
## Lines starting with two hashes (##) are comments with information.
## Lines starting with one hash (#) are configuration parameters that can be uncommented.
## Lines starting with one hash (#) are configuration parameters that can be uncommented.
...
@@ -26,6 +26,7 @@
...
@@ -26,6 +26,7 @@
## configuration ##
## configuration ##
###################################
###################################
##
##
## See installation.md#using-https for additional HTTPS configuration details.
upstream gitlab {
upstream gitlab {
server unix:/home/git/gitlab/tmp/sockets/gitlab.socket fail_timeout=0;
server unix:/home/git/gitlab/tmp/sockets/gitlab.socket fail_timeout=0;
...
@@ -43,6 +44,8 @@ server {
...
@@ -43,6 +44,8 @@ server {
## Or if you want to accept large git objects over http
## Or if you want to accept large git objects over http
client_max_body_size 20m;
client_max_body_size 20m;
## See app/controllers/application_controller.rb for headers set
## Individual nginx logs for this GitLab vhost
## Individual nginx logs for this GitLab vhost
access_log /var/log/nginx/gitlab_access.log;
access_log /var/log/nginx/gitlab_access.log;
error_log /var/log/nginx/gitlab_error.log;
error_log /var/log/nginx/gitlab_error.log;
...
...
lib/support/nginx/gitlab-ssl
View file @
70f30abd
## GitLab
## GitLab
## Contributors: randx, yin8086, sashkab, orkoden, axilleas
## Contributors: randx, yin8086, sashkab, orkoden, axilleas
, bbodenmiller
##
##
## Modified from nginx http version
## Modified from nginx http version
## Modified from http://blog.phusion.nl/2012/04/21/tutorial-setting-up-gitlab-on-debian-6/
## Modified from http://blog.phusion.nl/2012/04/21/tutorial-setting-up-gitlab-on-debian-6/
...
@@ -26,9 +26,8 @@
...
@@ -26,9 +26,8 @@
## [1] https://github.com/agentzh/chunkin-nginx-module#status
## [1] https://github.com/agentzh/chunkin-nginx-module#status
## [2] https://github.com/agentzh/chunkin-nginx-module
## [2] https://github.com/agentzh/chunkin-nginx-module
##
##
##
###################################
###################################
##
SSL configuration
##
##
configuration
##
###################################
###################################
##
##
## See installation.md#using-https for additional HTTPS configuration details.
## See installation.md#using-https for additional HTTPS configuration details.
...
@@ -37,24 +36,24 @@ upstream gitlab {
...
@@ -37,24 +36,24 @@ upstream gitlab {
server unix:/home/git/gitlab/tmp/sockets/gitlab.socket fail_timeout=0;
server unix:/home/git/gitlab/tmp/sockets/gitlab.socket fail_timeout=0;
}
}
##
Normal HTTP
host
##
Redirects all HTTP traffic to the HTTPS
host
server {
server {
listen 0.0.0.0:80;
listen 0.0.0.0:80;
listen [::]:80 default_server;
listen [::]:80 default_server;
server_name YOUR_SERVER_FQDN; ## Replace this with something like gitlab.example.com
server_name YOUR_SERVER_FQDN; ## Replace this with something like gitlab.example.com
server_tokens off; ## Don't show the nginx version number, a security best practice
server_tokens off; ## Don't show the nginx version number, a security best practice
return 301 https://$server_name$request_uri;
## Redirects all traffic to the HTTPS host
access_log /var/log/nginx/gitlab_access.log;
root /nowhere; ## root doesn't have to be a valid path since we are redirecting
error_log /var/log/nginx/gitlab_error.log;
rewrite ^ https://$server_name$request_uri? permanent;
}
}
## HTTPS host
## HTTPS host
server {
server {
listen 0.0.0.0:443 ssl;
listen 0.0.0.0:443 ssl;
listen [::]:443 ssl default_server;
listen [::]:443 ssl default_server;
server_name YOUR_SERVER_FQDN; ## Replace this with something like gitlab.example.com
server_name YOUR_SERVER_FQDN; ## Replace this with something like gitlab.example.com
server_tokens off;
server_tokens off;
## Don't show the nginx version number, a security best practice
root /home/git/gitlab/public;
root /home/git/gitlab/public;
## Increase this if you want to upload large attachments
## Increase this if you want to upload large attachments
...
@@ -72,12 +71,9 @@ server {
...
@@ -72,12 +71,9 @@ server {
ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
ssl_prefer_server_ciphers on;
ssl_prefer_server_ciphers on;
ssl_session_cache shared:SSL:10m;
ssl_session_cache shared:SSL:10m;
ssl_session_timeout 5m;
## [WARNING] The following header states that the browser should only communicate
## See app/controllers/application_controller.rb for headers set
## with your server over a secure connection for the next 24 months.
add_header Strict-Transport-Security max-age=63072000;
add_header X-Frame-Options SAMEORIGIN;
add_header X-Content-Type-Options nosniff;
## [Optional] If your certficate has OCSP, enable OCSP stapling to reduce the overhead and latency of running SSL.
## [Optional] If your certficate has OCSP, enable OCSP stapling to reduce the overhead and latency of running SSL.
## Replace with your ssl_trusted_certificate. For more info see:
## Replace with your ssl_trusted_certificate. For more info see:
...
...
Write
Preview
Markdown
is supported
0%
Try again
or
attach a new file
Attach a file
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Cancel
Please
register
or
sign in
to comment