security fixes

This commit is contained in:
bee
2026-04-27 17:03:44 +02:00
parent 56d73c7c6f
commit 66149543a9
10 changed files with 50 additions and 16 deletions
@@ -1,4 +1,3 @@
## Redirect all HTTP traffic to HTTPS
server {
listen 80;
server_name git.secretbee.buzz;
@@ -12,7 +11,9 @@ server {
listen 443 ssl;
server_name git.secretbee.buzz;
add_header Strict-Transport-Security "max-age=31536000" always;
limit_req zone=mylimit burst=20;
add_header Strict-Transport-Security "max-age=31536000, includeSubDomains" always;
ssl_certificate /etc/letsencrypt/live/git.secretbee.buzz/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/git.secretbee.buzz/privkey.pem;
@@ -17,10 +17,12 @@ server {
}
server {
listen 443;
listen 443 ssl;
server_name grafana.secretbee.buzz;
add_header Strict-Transport-Security "max-age=31536000" always;
limit_req zone=mylimit burst=20;
add_header Strict-Transport-Security "max-age=31536000, includeSubDomains" always;
ssl_certificate /etc/letsencrypt/live/grafana.secretbee.buzz/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/grafana.secretbee.buzz/privkey.pem;
@@ -1,4 +1,3 @@
## Redirect all HTTP traffic to HTTPS
server {
listen 80;
server_name lounge.secretbee.buzz;
@@ -12,7 +11,9 @@ server {
listen 443 ssl;
server_name lounge.secretbee.buzz;
add_header Strict-Transport-Security "max-age=31536000" always;
limit_req zone=mylimit burst=20;
add_header Strict-Transport-Security "max-age=31536000, includeSubDomains" always;
ssl_certificate /etc/letsencrypt/live/lounge.secretbee.buzz/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/lounge.secretbee.buzz/privkey.pem;
+1 -1
View File
@@ -18,7 +18,7 @@ server {
root /var/www;
add_header Strict-Transport-Security "max-age=31536000" always;
add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always;
ssl_certificate /etc/letsencrypt/live/secretbee.buzz/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/secretbee.buzz/privkey.pem;