Loading docker-compose.yml +4 −0 Original line number Diff line number Diff line Loading @@ -20,3 +20,7 @@ services: activemq: image: alfresco/alfresco-activemq:latest proxy: build: ./nginx-ingress image: local/nginx-ingress:base nginx-ingress/Dockerfile 0 → 100644 +8 −0 Original line number Diff line number Diff line FROM nginx:stable-alpine COPY nginx.conf /etc/nginx/nginx.conf COPY entrypoint.sh / RUN chmod +x /entrypoint.sh ENTRYPOINT [ "/entrypoint.sh" ] nginx-ingress/entrypoint.sh 0 → 100644 +11 −0 Original line number Diff line number Diff line #!/bin/sh if [[ $ACS_PLATFORM_URL ]]; then sed -i s%http:\/\/platform:8080%"$REPO_URL"%g /etc/nginx/nginx.conf fi if [[ $ACCESS_LOG ]]; then sed -i s%\#ENV_ACCESS_LOG%"access_log $ACCESS_LOG;"%g /etc/nginx/nginx.conf fi nginx -g "daemon off;" nginx-ingress/nginx.conf 0 → 100644 +51 −0 Original line number Diff line number Diff line worker_processes 1; events { worker_connections 1024; } http { server { listen *:8080; client_max_body_size 0; set $allowOriginSite *; proxy_pass_request_headers on; proxy_pass_header Set-Cookie; # External settings, do not remove #ENV_ACCESS_LOG proxy_next_upstream error timeout invalid_header http_500 http_502 http_503 http_504; proxy_redirect off; proxy_buffering off; proxy_set_header Host $host:$server_port; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_pass_header Set-Cookie; # Protect access to SOLR APIs location ~ ^(/.*/service/api/solr/.*)$ {return 403;} location ~ ^(/.*/s/api/solr/.*)$ {return 403;} location ~ ^(/.*/wcservice/api/solr/.*)$ {return 403;} location ~ ^(/.*/wcs/api/solr/.*)$ {return 403;} location ~ ^(/.*/proxy/alfresco/api/solr/.*)$ {return 403 ;} location ~ ^(/.*/-default-/proxy/alfresco/api/.*)$ {return 403;} # Protect access to Prometheus endpoint location ~ ^(/.*/s/prometheus)$ {return 403;} location / { proxy_pass http://platform:8080; } location /alfresco/ { proxy_pass http://platform:8080; # If using external proxy / load balancer (for initial redirect if no trailing slash) absolute_redirect off; } } } Loading
docker-compose.yml +4 −0 Original line number Diff line number Diff line Loading @@ -20,3 +20,7 @@ services: activemq: image: alfresco/alfresco-activemq:latest proxy: build: ./nginx-ingress image: local/nginx-ingress:base
nginx-ingress/Dockerfile 0 → 100644 +8 −0 Original line number Diff line number Diff line FROM nginx:stable-alpine COPY nginx.conf /etc/nginx/nginx.conf COPY entrypoint.sh / RUN chmod +x /entrypoint.sh ENTRYPOINT [ "/entrypoint.sh" ]
nginx-ingress/entrypoint.sh 0 → 100644 +11 −0 Original line number Diff line number Diff line #!/bin/sh if [[ $ACS_PLATFORM_URL ]]; then sed -i s%http:\/\/platform:8080%"$REPO_URL"%g /etc/nginx/nginx.conf fi if [[ $ACCESS_LOG ]]; then sed -i s%\#ENV_ACCESS_LOG%"access_log $ACCESS_LOG;"%g /etc/nginx/nginx.conf fi nginx -g "daemon off;"
nginx-ingress/nginx.conf 0 → 100644 +51 −0 Original line number Diff line number Diff line worker_processes 1; events { worker_connections 1024; } http { server { listen *:8080; client_max_body_size 0; set $allowOriginSite *; proxy_pass_request_headers on; proxy_pass_header Set-Cookie; # External settings, do not remove #ENV_ACCESS_LOG proxy_next_upstream error timeout invalid_header http_500 http_502 http_503 http_504; proxy_redirect off; proxy_buffering off; proxy_set_header Host $host:$server_port; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_pass_header Set-Cookie; # Protect access to SOLR APIs location ~ ^(/.*/service/api/solr/.*)$ {return 403;} location ~ ^(/.*/s/api/solr/.*)$ {return 403;} location ~ ^(/.*/wcservice/api/solr/.*)$ {return 403;} location ~ ^(/.*/wcs/api/solr/.*)$ {return 403;} location ~ ^(/.*/proxy/alfresco/api/solr/.*)$ {return 403 ;} location ~ ^(/.*/-default-/proxy/alfresco/api/.*)$ {return 403;} # Protect access to Prometheus endpoint location ~ ^(/.*/s/prometheus)$ {return 403;} location / { proxy_pass http://platform:8080; } location /alfresco/ { proxy_pass http://platform:8080; # If using external proxy / load balancer (for initial redirect if no trailing slash) absolute_redirect off; } } }