Gavin 6 роки тому
батько
коміт
e99d5d881a

+ 0 - 21
k8swebapi-nginx/conf.d/default.conf

@@ -1,21 +0,0 @@
-server {
-    listen       443 ssl default;
-
-    ssl on;
-    ssl_certificate            ssl/jixiang.cn.pem;
-    ssl_certificate_key        ssl/jixiang.cn.key;
-    ssl_session_cache          shared:SSL:1m;
-    ssl_session_timeout        5m;
-    ssl_protocols              TLSv1 TLSv1.1 TLSv1.2;
-    ssl_ciphers                AESGCM:ALL:!DH:!EXPORT:!RC4:+HIGH:!MEDIUM:!LOW:!aNULL:!eNULL;
-    ssl_prefer_server_ciphers  on;
-
-    # 禁止IP访问及未绑定的域名跳转
-    return       403;
-}
-
-server {
-    listen       80 default;
-    # 禁止IP访问及未绑定的域名跳转
-    return       403;
-}

+ 4 - 5
k8swebapi-nginx/conf.d/k8swebapi-nginx.conf

@@ -3,12 +3,11 @@ upstream sharetransmit-svc {
 }
 
 server {
-    listen 80;
-    listen 443 ssl http2;
+    listen 8006;
 
     #ssl on;
-    ssl_certificate ssl/jixiang.cn.pem;
-    ssl_certificate_key ssl/jixiang.cn.key;
+    ssl_certificate ssl/xinyueyouxi.com.pem;
+    ssl_certificate_key ssl/xinyueyouxi.com.key;
     ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
     ssl_ciphers HIGH:!RC4:!MD5:!aNULL:!eNULL:!NULL:!DH:!EDH:!EXP:+MEDIUM;
     ssl_prefer_server_ciphers on;
@@ -20,7 +19,7 @@ server {
 
     charset utf-8;
 
-    server_name jinit1.jixiang.cn jinit2.jixiang.cn jinit3.jixiang.cn jinittest.jixiang.cn;
+    server_name _;
 
     location / {
         proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;

+ 0 - 12
k8swebapi-nginx/tcp.d/sharetransmit.jixiang.cn.conf

@@ -1,12 +0,0 @@
-stream {
-    upstream sharetransmit-svc {
-       hash $remote_addr consistent;
-       server sharetransmit-svc:8006;
-    }
-    server {
-       listen 8006;
-       proxy_connect_timeout 10s;
-       proxy_timeout 300s;
-       proxy_pass sharetransmit-svc;
-    }
-}