| 12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576 |
- upstream chuji_safe_server_http {
- server 137.220.142.147:9503;
- }
- upstream chuji_safe_server_ws {
- server 137.220.142.147:9601;
- }
- server {
- listen 80;
- listen [::]:80;
- client_max_body_size 1M;
-
- # listen 443 ssl;
- # listen [::]:443 ssl;
- # ssl_certificate /etc/nginx/ssl/nurftlg.cn/fullchain.cer;
- # ssl_certificate_key /etc/nginx/ssl/nurftlg.cn/nurftlg.cn.key;
- # ssl_verify_client off;
- # ssl_prefer_server_ciphers on;
- # ssl_protocols TLSv1 TLSv1.1 TLSv1.2 TLSv1.3;
- # ssl_ciphers HIGH:!aNULL:!MD5:ECDHE-RSA-AES256-GCM-SHA512:DHE-RSA-AES256-GCM-SHA512:ECDHE-RSA-AES256-GCM-SHA384:DHE-RSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-SHA384;
- # ssl_session_cache shared:SSL:20m;
- # ssl_session_tickets off;
- server_name cj.v259.pwljspt.cn;
- access_log /var/log/nginx/cj.v259.pwljspt.cn.access.log;
- error_log /var/log/nginx/cj.v259.pwljspt.cn.access.error.log;
- real_ip_header X-Forwarded-For;
- set_real_ip_from 0.0.0.0/0;
- # 跨域
- set $cors_credentials '';
- set $cors_content_type '';
- set $cors_content_length '';
- if ($http_origin ~ '.+') {
- set $cors_credentials 'true';
- }
- if ($request_method = OPTIONS) {
- set $cors_content_type 'text/plain';
- set $cors_content_length '0';
- }
- add_header Access-Control-Allow-Origin $http_origin always;
- add_header Access-Control-Allow-Credentials $cors_credentials always;
- add_header Access-Control-Allow-Methods $http_access_control_request_method always;
- add_header Access-Control-Allow-Headers $http_access_control_request_headers always;
- add_header Content-Type $cors_content_type;
- add_header Content-Length $cors_content_length;
- if ($request_method = OPTIONS) {
- return 204;
- }
- location / {
- proxy_set_header Host $host;
- proxy_set_header X-Real-IP $remote_addr;
- proxy_set_header X-Forwarded-For $remote_addr;
- proxy_set_header REMOTE_ADD $remote_addr;
- proxy_set_header Upgrade $http_upgrade;
- proxy_pass http://chuji_safe_server_http; #后端api容器地址
- proxy_redirect off;
- }
- location /ws {
- proxy_pass http://chuji_safe_server_ws;
- proxy_set_header X-Real-IP $remote_addr;
- proxy_set_header Host $host;
- proxy_set_header X-Forwarded-For $remote_addr;
- proxy_http_version 1.1;
- proxy_set_header Upgrade $http_upgrade;
- proxy_set_header Connection "upgrade";
- rewrite /ws/(.*) /$1 break;
- proxy_redirect off;
- }
- }
|