Various fixes that prevented production deployment
This commit is contained in:
parent
591845a25d
commit
459e86e25a
8 changed files with 134 additions and 279 deletions
|
|
@ -24,10 +24,6 @@ proxy_cache_path /var/cache/nginx levels=1:2 keys_zone=my_cache:10m max_size=10g
|
|||
|
||||
log_format proxy '[$time_local] Cache: $upstream_cache_status $upstream_addr $upstream_response_time $status $bytes_sent $remote_addr $request_uri "$http_referer" "$http_user_agent" $scheme';
|
||||
|
||||
# Performance
|
||||
passenger_max_pool_size 8;
|
||||
passenger_max_request_queue_size 200;
|
||||
|
||||
limit_req_zone $binary_remote_addr zone=one:20m rate=5r/s;
|
||||
|
||||
# Frontend caching and static asset delivery
|
||||
|
|
@ -37,7 +33,7 @@ server {
|
|||
ssl_certificate /etc/letsencrypt/live/screenshots.debian.net/fullchain.pem;
|
||||
ssl_certificate_key /etc/letsencrypt/live/screenshots.debian.net/privkey.pem;
|
||||
|
||||
root /opt/debshots/public;
|
||||
#root /opt/debshots/public;
|
||||
server_name _;
|
||||
access_log /var/log/nginx/cache-access.log proxy;
|
||||
|
||||
|
|
@ -62,7 +58,7 @@ server {
|
|||
location /json/ {
|
||||
try_files /maintenance.html @backend;
|
||||
proxy_cache my_cache;
|
||||
proxy_pass http://127.0.0.1:8888/;
|
||||
proxy_pass http://127.0.0.1:3000/;
|
||||
proxy_cache_lock on;
|
||||
proxy_cache_use_stale updating;
|
||||
add_header X-Coffee front-json;
|
||||
|
|
@ -74,12 +70,17 @@ server {
|
|||
|
||||
location @backend {
|
||||
proxy_cache my_cache;
|
||||
proxy_pass http://127.0.0.1:8888;
|
||||
proxy_set_header x_debian_sso_dn $ssl_client_s_dn;
|
||||
proxy_pass http://127.0.0.1:3000;
|
||||
|
||||
# Avoid cache stampede - rather update once and deliver stale content
|
||||
proxy_cache_lock on;
|
||||
proxy_cache_use_stale updating;
|
||||
add_header X-Coffee front-rails;
|
||||
|
||||
# Use sendfile mechanism to deliver files directly
|
||||
proxy_set_header X-Sendfile-Type X-Accel-Redirect;
|
||||
proxy_set_header X-Accel-Mapping /opt/debshots/public/=/__send_file_accel/;
|
||||
}
|
||||
|
||||
location /assets/ {
|
||||
|
|
@ -105,49 +106,46 @@ server {
|
|||
}
|
||||
|
||||
# Backend rails application
|
||||
server {
|
||||
listen 127.0.0.1:8888;
|
||||
# server {
|
||||
# listen 127.0.0.1:3000;
|
||||
|
||||
root /opt/debshots/public;
|
||||
# root /opt/debshots/public;
|
||||
|
||||
server_name _;
|
||||
access_log /var/log/nginx/rails-access.log;
|
||||
# server_name _;
|
||||
# access_log /var/log/nginx/rails-access.log;
|
||||
|
||||
passenger_enabled on;
|
||||
passenger_ruby /opt/debshots/.rbenv/versions/2.4.1/bin/ruby;
|
||||
# # Send thumbnails using X-Sendfile / X-Accel-Redirect
|
||||
# # The correct thumbnail is computed by the Rails application so it cannot be served directly.
|
||||
# location /thumbnail/ {
|
||||
# expires 1h;
|
||||
# proxy_cache_valid 404 15m;
|
||||
# add_header X-Coffee back-thumbnail;
|
||||
# limit_req zone=one burst=30;
|
||||
# }
|
||||
|
||||
# # Send public assets using X-Sendfile / X-Accel-Redirect (e.g. public/images/dummy/...)
|
||||
# location /public/ {
|
||||
# expires 1h;
|
||||
# add_header X-Coffee back-public;
|
||||
|
||||
# Send thumbnails using X-Sendfile / X-Accel-Redirect
|
||||
# The correct thumbnail is computed by the Rails application so it cannot be served directly.
|
||||
location /thumbnail/ {
|
||||
expires 1h;
|
||||
proxy_cache_valid 404 15m;
|
||||
add_header X-Coffee back-thumbnail;
|
||||
limit_req zone=one burst=30;
|
||||
}
|
||||
# # passenger_set_header X-Sendfile-Type X-Accel-Redirect;
|
||||
# # passenger_env_var HTTP_X_ACCEL_MAPPING /opt/debshots/public/=/__send_file_accel/;
|
||||
# # passenger_pass_header X-Accel-Redirect;
|
||||
# }
|
||||
|
||||
# Send public assets using X-Sendfile / X-Accel-Redirect (e.g. public/images/dummy/...)
|
||||
location /public/ {
|
||||
expires 1h;
|
||||
add_header X-Coffee back-public;
|
||||
# # Deliver static files directly from Nginx. See https://mattbrictson.com/accelerated-rails-downloads
|
||||
# location /__send_file_accel/ {
|
||||
# internal;
|
||||
# alias /opt/debshots/public/;
|
||||
# add_header X-Coffee back-accel;
|
||||
# expires 1d;
|
||||
# more_clear_headers 'Set-Cookie';
|
||||
# }
|
||||
|
||||
passenger_set_header X-Sendfile-Type X-Accel-Redirect;
|
||||
passenger_env_var HTTP_X_ACCEL_MAPPING /opt/debshots/public/=/__send_file_accel/;
|
||||
passenger_pass_header X-Accel-Redirect;
|
||||
}
|
||||
|
||||
location /__send_file_accel/ {
|
||||
internal;
|
||||
alias /opt/debshots/public/;
|
||||
add_header X-Coffee back-accel;
|
||||
expires 1d;
|
||||
more_clear_headers 'Set-Cookie';
|
||||
}
|
||||
|
||||
location /secretstatus {
|
||||
stub_status;
|
||||
access_log off;
|
||||
allow all;
|
||||
add_header X-Coffee back-status;
|
||||
}
|
||||
}
|
||||
# location /secretstatus {
|
||||
# stub_status;
|
||||
# access_log off;
|
||||
# allow all;
|
||||
# add_header X-Coffee back-status;
|
||||
# }
|
||||
# }
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue