55 lines
1.8 KiB
Plaintext
55 lines
1.8 KiB
Plaintext
# Reference config for the CENTRAL REVERSE PROXY MACHINE — not for this host.
|
|
# This stack publishes plain HTTP on <notes-host>:5233; TLS terminates here.
|
|
#
|
|
# Replace notes-host.lan with the LAN address of the machine running the
|
|
# markdown-to-caldav stack.
|
|
|
|
upstream mdcaldav {
|
|
server notes-host.lan:5233;
|
|
}
|
|
|
|
# --- Option A: its own hostname ---------------------------------------------
|
|
|
|
server {
|
|
listen 443 ssl;
|
|
http2 on;
|
|
server_name notes.example.com;
|
|
|
|
ssl_certificate /etc/letsencrypt/live/notes.example.com/fullchain.pem;
|
|
ssl_certificate_key /etc/letsencrypt/live/notes.example.com/privkey.pem;
|
|
|
|
# CalDAV bodies are small, but clients send large PROPFIND/REPORT XML.
|
|
client_max_body_size 100M;
|
|
|
|
location / {
|
|
proxy_pass http://mdcaldav;
|
|
proxy_set_header Host $host;
|
|
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
|
proxy_set_header X-Forwarded-Proto $scheme;
|
|
}
|
|
}
|
|
|
|
# --- Option B: share a hostname with an existing Radicale -------------------
|
|
#
|
|
# NOTE the absence of a trailing slash on proxy_pass. With a trailing slash
|
|
# nginx replaces the /notes/ prefix with /, Radicale then generates hrefs
|
|
# without the prefix, and clients walk to URLs that do not exist. Radicale
|
|
# strips script_name itself, so send it the full path.
|
|
#
|
|
# server {
|
|
# listen 443 ssl;
|
|
# server_name dav.example.com;
|
|
#
|
|
# location /notes/ {
|
|
# proxy_pass http://mdcaldav; # no trailing slash
|
|
# proxy_set_header X-Script-Name /notes;
|
|
# proxy_set_header Host $host;
|
|
# proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
|
# proxy_set_header X-Forwarded-Proto $scheme;
|
|
# }
|
|
#
|
|
# location / {
|
|
# proxy_pass http://existing-radicale.lan:5232;
|
|
# }
|
|
# }
|