Repository navigation
Expand file tree
/
Copy pathvhost-reverse-proxy.conf
More file actions
75 lines (56 loc) · 2.76 KB
/
Copy pathvhost-reverse-proxy.conf
File metadata and controls
75 lines (56 loc) · 2.76 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
<VirtualHost *:80>
ServerName replacewithdomain
Redirect / https://replacewithdomain/
</VirtualHost>
<VirtualHost *:443>
ServerName replacewithdomain
ProxyPreserveHost On
ProxyRequests Off
ProxyVia Off
ProxyStatus On
SSLEngine on
SSLProtocol all -SSLv2
SSLHonorCipherOrder on
SSLCipherSuite "ECDH+AESGCM:DH+AESGCM:ECDH+AES256:DH+AES256:ECDH+AES128:DH+AES:ECDH+3DES:DH+3DES:RSA+AESGCM:RSA+AES:RSA+3DES:!aNULL:!MD5:!DSS"
Header add Strict-Transport-Security: "max-age=15768000;includeSubdomains"
SSLCompression Off
<IfModule mod_headers.c>
RequestHeader set X-Forwarded-Proto https
Header always set Strict-Transport-Security "max-age=15552000; includeSubDomains"
</IfModule>
RewriteEngine On
RewriteRule ^/\.well-known/carddav https://%{SERVER_NAME}/remote.php/dav/ [R=301,L]
RewriteRule ^/\.well-known/caldav https://%{SERVER_NAME}/remote.php/dav/ [R=301,L]
# Encoded slashes need to be allowed
AllowEncodedSlashes NoDecode
# Container uses a unique non-signed certificate
SSLProxyEngine On
SSLProxyVerify None
SSLProxyCheckPeerCN Off
SSLProxyCheckPeerName Off
# static html, js, images, etc. served from coolwsd
# browser is the client part of LibreOffice Online
ProxyPass /browser http://replacewithcollaboracontainer:9980/browser retry=0
ProxyPassReverse /browser http://replacewithcollaboracontainer:9980/browser
# WOPI discovery URL
ProxyPass /hosting/discovery http://replacewithcollaboracontainer:9980/hosting/discovery retry=0
ProxyPassReverse /hosting/discovery http://replacewithcollaboracontainer:9980/hosting/discovery
# Main websocket
ProxyPassMatch "/cool/(.*)/ws$" ws://replacewithcollaboracontainer:9980/cool/$1/ws nocanon
# Admin Console websocket
ProxyPass /cool/adminws ws://replacewithcollaboracontainer:9980/cool/adminws
# Download as, Fullscreen presentation and Image upload operations
ProxyPass /cool http://replacewithcollaboracontainer:9980/cool
ProxyPassReverse /cool http://replacewithcollaboracontainer:9980/cool
# Endpoint with information about availability of various features
ProxyPass /hosting/capabilities http://replacewithcollaboracontainer:9980/hosting/capabilities retry=0
ProxyPassReverse /hosting/capabilities http://replacewithcollaboracontainer:9980/hosting/capabilities
ProxyPass / http://replacewithcontainer/
ProxyPassReverse / http://replacewithcontainer/
Header set X-Frame-Options: "ALLOW-FROM https://replacewithdomain/"
ErrorLog ${APACHE_LOG_DIR}/nextcloud-collabora-error.log
CustomLog ${APACHE_LOG_DIR}/nextcloud-collabora-access.log combined
SSLCertificateFile /etc/letsencrypt/live/replacewithdomain/fullchain.pem
SSLCertificateKeyFile /etc/letsencrypt/live/replacewithdomain/privkey.pem
Include /etc/letsencrypt/options-ssl-apache.conf
</VirtualHost>