aboutsummaryrefslogtreecommitdiff
path: root/data/vaultwarden
diff options
context:
space:
mode:
Diffstat (limited to 'data/vaultwarden')
-rw-r--r--data/vaultwarden/vaultwarden.conf.j239
1 files changed, 39 insertions, 0 deletions
diff --git a/data/vaultwarden/vaultwarden.conf.j2 b/data/vaultwarden/vaultwarden.conf.j2
new file mode 100644
index 0000000..76fd99c
--- /dev/null
+++ b/data/vaultwarden/vaultwarden.conf.j2
@@ -0,0 +1,39 @@
1server {
2 listen 443 ssl;
3 server_name {{ vaultwarden_server_name }};
4
5 ssl_certificate /etc/letsencrypt/live/chudnick.com/fullchain.pem;
6 ssl_certificate_key /etc/letsencrypt/live/chudnick.com/privkey.pem;
7 add_header Strict-Transport-Security "max-age=31536000" always;
8 ssl_stapling on;
9 ssl_stapling_verify on;
10
11 # Security / XSS Mitigation Headers
12 add_header X-Frame-Options "SAMEORIGIN";
13 add_header X-XSS-Protection "1; mode=block";
14 add_header X-Content-Type-Options "nosniff";
15
16 # authelia
17 include /etc/nginx/snippets/authelia-location.conf;
18
19 location /admin {
20 #authelia
21 include /etc/nginx/snippets/proxy.conf;
22 include /etc/nginx/snippets/authelia-authrequest.conf;
23
24 proxy_pass http://127.0.0.1:{{ vaultwarden_external_port }};
25 }
26
27 location / {
28 proxy_pass http://127.0.0.1:{{ vaultwarden_external_port }}/;
29 }
30
31
32}
33
34server {
35 listen 80;
36 listen [::]:80;
37 server_name {{ vaultwarden_server_name }};
38 return 301 https://$host$request_uri;
39}