Commit b65d3d30 authored by Brian Long's avatar Brian Long
Browse files

Merge branch 'acs-proxy.proxy' into acs-base.acs-proxy

parents 6332985e 010149e6
Loading
Loading
Loading
Loading
+4 −0
Original line number Diff line number Diff line
@@ -20,3 +20,7 @@ services:

    activemq:
        image: alfresco/alfresco-activemq:latest

    proxy:
        build: ./nginx-ingress
        image: local/nginx-ingress:base
+8 −0
Original line number Diff line number Diff line
FROM nginx:stable-alpine

COPY nginx.conf /etc/nginx/nginx.conf

COPY entrypoint.sh /
RUN chmod +x /entrypoint.sh

ENTRYPOINT [ "/entrypoint.sh" ]
+11 −0
Original line number Diff line number Diff line
#!/bin/sh

if [[ $ACS_PLATFORM_URL ]]; then
  sed -i s%http:\/\/platform:8080%"$REPO_URL"%g /etc/nginx/nginx.conf
fi

if [[ $ACCESS_LOG ]]; then
  sed -i s%\#ENV_ACCESS_LOG%"access_log $ACCESS_LOG;"%g /etc/nginx/nginx.conf
fi

nginx -g "daemon off;"
+51 −0
Original line number Diff line number Diff line
worker_processes  1;

events {
    worker_connections  1024;
}

http {
    server {
        listen *:8080;

        client_max_body_size 0;

        set  $allowOriginSite *;
        proxy_pass_request_headers on;
        proxy_pass_header Set-Cookie;

        # External settings, do not remove
        #ENV_ACCESS_LOG

        proxy_next_upstream error timeout invalid_header http_500 http_502 http_503 http_504;
        proxy_redirect off;
        proxy_buffering off;
        proxy_set_header Host            $host:$server_port;
        proxy_set_header X-Real-IP       $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_pass_header Set-Cookie;
        
        # Protect access to SOLR APIs
        location ~ ^(/.*/service/api/solr/.*)$ {return 403;}
        location ~ ^(/.*/s/api/solr/.*)$ {return 403;}
        location ~ ^(/.*/wcservice/api/solr/.*)$ {return 403;}
        location ~ ^(/.*/wcs/api/solr/.*)$ {return 403;}

        location ~ ^(/.*/proxy/alfresco/api/solr/.*)$ {return 403 ;}
        location ~ ^(/.*/-default-/proxy/alfresco/api/.*)$ {return 403;}
        
        # Protect access to Prometheus endpoint
        location ~ ^(/.*/s/prometheus)$ {return 403;}
        
        location / {
            proxy_pass http://platform:8080;
        }

        location /alfresco/ {
            proxy_pass http://platform:8080;

            # If using external proxy / load balancer (for initial redirect if no trailing slash)
            absolute_redirect off;
        }
    }
}