# /etc/nginx/sites-available/model.southwest-roleplay.dev # # Plain HTTP to start with. Run # sudo certbot --nginx -d model.southwest-roleplay.dev # and certbot adds the listen 443 / ssl_certificate lines and the redirect, # the same way it manages the other sites on this box. # # Only /samp/skin/ and the assets that page needs are exposed; everything # else returns 404. Model files are not served here at all - MODELS_BASE_URL # points the browser straight at static.southwest-roleplay.com. server { listen 80; listen [::]:80; server_name model.southwest-roleplay.dev; # Nothing caches in front of this origin, so compress here. three.module.js # is 1.3 MB uncompressed. gzip_proxied is required: every response comes # from the Node upstream, and nginx skips proxied responses without it. gzip on; gzip_proxied any; gzip_types application/javascript; gzip_min_length 1024; location /samp/skin/ { proxy_pass http://127.0.0.1:3000; proxy_set_header Host $host; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; } location /api/skin/ { proxy_pass http://127.0.0.1:3000; proxy_set_header Host $host; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; } location /js/ { proxy_pass http://127.0.0.1:3000; } location /vendor/ { proxy_pass http://127.0.0.1:3000; add_header Cache-Control "public, max-age=31536000, immutable"; } # The catch-all below does not block certbot: the nginx plugin inserts a # more specific location for /.well-known/acme-challenge/ while it runs. # Only if you switch to the webroot plugin would you need this permanently: # # location ^~ /.well-known/acme-challenge/ { # root /var/www/html; # } location / { return 404; } }