diff --git a/api.nkode.tech b/api.nkode.tech new file mode 100644 index 0000000..8d3af1c --- /dev/null +++ b/api.nkode.tech @@ -0,0 +1,38 @@ +server { + listen 443 ssl http2; + server_name api.nkode.tech; + + ssl_certificate /etc/letsencrypt/live/api.nkode.tech/fullchain.pem; + ssl_certificate_key /etc/letsencrypt/live/api.nkode.tech/privkey.pem; + ssl_protocols TLSv1.2 TLSv1.3; + ssl_prefer_server_ciphers on; + ssl_dhparam /etc/ssl/certs/dhparam.pem; + ssl_ciphers 'ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384'; + ssl_session_cache shared:SSL:10m; + ssl_session_timeout 10m; + ssl_stapling on; + ssl_stapling_verify on; + resolver 8.8.8.8 8.8.4.4 valid=300s; + resolver_timeout 5s; + + add_header X-Content-Type-Options nosniff; + add_header X-Frame-Options DENY; + add_header X-XSS-Protection "1; mode=block"; + add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always; + + location / { + proxy_pass http://127.0.0.1:8080; # Your application port + proxy_set_header Host $host; + proxy_set_header X-Real-IP $remote_addr; + proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; + proxy_set_header X-Forwarded-Proto $scheme; + } +} + +server { + listen 80; + server_name api.nkode.tech; + + # Redirect all HTTP traffic to HTTPS + return 301 https://$host:443$request_uri; +}