worker_processes 2; ## Default: 1 error_log /var/log/nginx/error.log; pid /var/run/nginx.pid; include /usr/share/nginx/modules/*.conf; # See /usr/share/doc/nginx/README.dynamic. events { worker_connections 1024; ## Default: 1024 use epoll; # http://nginx.org/en/docs/events.html multi_accept on; # http://nginx.org/en/docs/ngx_core_module.html#multi_accept } # Core Modules Docs: # http://nginx.org/en/docs/http/ngx_http_core_module.html http { # include mime.types; default_type application/octet-stream; keepalive_timeout 65; keepalive_requests 100000; tcp_nopush on; tcp_nodelay on; # lua_ settings # lua_package_path '/usr/local/openresty/lualib/?.lua;;'; lua_shared_dict discovery 1m; # cache for discovery metadata documents lua_shared_dict jwks 1m; # cache for JWKs # lua_ssl_trusted_certificate /etc/ssl/certs/ca-certificates.crt; variables_hash_max_size 2048; server_names_hash_bucket_size 128; server_tokens off; resolver 8.8.8.8 valid=30s ipv6=off; resolver_timeout 11s; log_format main '$remote_addr - $remote_user [$time_local] "$request" ' '$status $body_bytes_sent "$http_referer" ' '"$http_user_agent" "$http_x_forwarded_for"'; # No idea what this is doing # https://stackoverflow.com/a/5877989/1867984 # upstream upstream_server { # # server 10.100.4.200:1010 max_fails=3 fail_timeout=30s; # server 127.0.0.1: # } # Nginx `listener` block server { listen 80 default_server; # listen 443 ssl; # Domain to protect server_name localhost 127.0.0.1; # mydomain.com; proxy_intercept_errors off; # ssl_certificate /etc/letsencrypt/live/mydomain.co.uk/fullchain.pem; # ssl_certificate_key /etc/letsencrypt/live/mydomain.co.uk/privkey.pem; server_tokens off; gzip on; gzip_types text/css application/javascript application/json image/svg+xml; gzip_comp_level 9; etag on; lua_code_cache off; access_log /var/logs/nginx/mydomain.access.log; error_log /var/logs/nginx/mydomain.error.log; # Static content to serve root /var/www/html; index index.html index.htm; # Single Page App # Try files, fallback to index.html # location / { try_files $uri $uri/ /index.html; } # DO NOT CACHE # This is where we would pick up on a new version/service-worker # location /index.html { add_header Cache-Control no-cache; } # [PROTECTED] Reverse Proxy for `orthanc` # location /pacs/ { set $session_check_ssi off; set $session_secret Eeko7aeb6iu5Wohch9Loo1aitha0ahd1; set $session_storage cookie; # Sample configurations: # https://github.com/zmartzone/lua-resty-openidc#sample-configuration-for-google-signin # https://gist.github.com/alhafoudh/e87392ee60cf14bb33962847f5a84b24 # https://www.jerney.io/secure-apis-kong-keycloak-1/ access_by_lua_block { local opts = { redirect_uri = "http://127.0.0.1/callback", discovery = "http://127.0.0.1/auth/realms/master/.well-known/openid-configuration", client_id = "pacs", client_secret = "cd2b3a3c-a6c6-4a37-a15d-b2e5598735b6" # accept_none_alg = true, # ssl_verify = "no", # redirect_uri_scheme = "http", # logout_path = "/logout", # redirect_after_logout_uri = "http://localhost:8080/auth/realms/internal/protocol/openid-connect/logout", # edirect_after_logout_with_id_token_hint = false, # session_contents = {id_token=true} } # Call introspect for OAuth 2.0 Bearer Access Token validation local res, err = require("resty.openidc").authenticate(opts) if err then # Helpful for debugging errors: # ngx.print(err) # ngx.log(ngx.ERR, err) ngx.status = 403 ngx.say(err) ngx.exit(ngx.HTTP_FORBIDDEN) end ngx.req.set_header("X-User", res.id_token.sub) } proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $remote_addr; proxy_set_header Host $host; expires 0; add_header Cache-Control private; proxy_pass http://orthanc:8042/; # By default, this endpoint is protected by CORS (cross-origin-resource-sharing) # You can add headers to allow other domains to request this resource. # See the "Updating CORS Settings" example below } # Keycloak # location /auth/ { proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header Host $http_host; proxy_pass http://keycloak:8080/auth/; } # EXAMPLE: Reverse Proxy, no auth # [UNPROTECTED] reverse proxy for `orthanc` # # location /pacs/ { # proxy_set_header X-Real-IP $remote_addr; # proxy_set_header X-Forwarded-For $remote_addr; # proxy_set_header Host $host; # # proxy_pass http://orthanc:8042/; # # # OR # # rewrite ^/pacs(.*) /$1 break; # # proxy_pass http://orthanc:8042; # } # EXAMPLE: Modifying headers to allow requests from other domains # IE. Updating CORS settings # # location / { # if ($request_method = 'OPTIONS') { # add_header 'Access-Control-Allow-Origin' '*'; # add_header 'Access-Control-Allow-Methods' 'GET, POST, OPTIONS'; # # # # Custom headers and headers various browsers *should* be OK with but aren't # # # add_header 'Access-Control-Allow-Headers' 'DNT,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range'; # # # # Tell client that this pre-flight info is valid for 20 days # # # add_header 'Access-Control-Allow-Headers' 'Authorization'; # add_header 'Access-Control-Allow-Credentials' true; # add_header 'Access-Control-Max-Age' 1728000; # add_header 'Content-Length' 0; # return 204; # } # if ($request_method = 'POST') { # add_header 'Access-Control-Allow-Origin' '*'; # add_header 'Access-Control-Allow-Methods' 'GET, POST, OPTIONS'; # add_header 'Access-Control-Allow-Headers' 'DNT,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range'; # add_header 'Access-Control-Expose-Headers' 'Content-Length,Content-Range'; # } # if ($request_method = 'GET') { # add_header 'Access-Control-Allow-Origin' '*'; # add_header 'Access-Control-Allow-Methods' 'GET, POST, OPTIONS'; # add_header 'Access-Control-Allow-Headers' 'DNT,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range'; # add_header 'Access-Control-Expose-Headers' 'Content-Length,Content-Range'; # add_header 'Access-Control-Allow-Headers' 'Authorization'; # add_header 'Access-Control-Allow-Credentials' true; # } # # # proxy_http_version 1.1; # # # proxy_set_header Host $host; # # proxy_set_header X-Real-IP $remote_addr; # # proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; # # proxy_set_header X-Forwarded-Proto $scheme; # # proxy_pass http://orthanc:8042; # } # EXAMPLE: Redirect server error pages to the static page /40x.html # # error_page 404 /404.html; # location = /40x.html { # } # EXAMPLE: Redirect server error pages to the static page /50x.html # # error_page 500 502 503 504 /50x.html; # location = /50x.html { # } } }