标签:
配置nginx对salt-api的https转发,以下是nginx配置文件
upstream saltapi.local {
server 192.186.156.55:8090 weight=10 max_fails=2 fail_timeout=30s;
}
server
{
listen 443 default ssl;
server_name 192.186.156.55;
access_log /export/servers/nginx/logs/saltapi.local/saltapi.local_access.log main;
error_log /export/servers/nginx/logs/saltapi.local/saltapi.local_error.log warn;
#chunkin on;
error_page 411 = @my_error;
location @my_error {
#chunkin_resume;
}
ssl_session_cache shared:SSL:1m;
ssl_session_timeout 10m;
ssl_certificate /export/data/salt-crt/salt-ssl.crt;
ssl_certificate_key /export/data/salt-crt/salt-ssl.key;
ssl_verify_client off;
ssl_protocols SSLv3 TLSv1 TLSv1.1 TLSv1.2;
ssl_ciphers RC4:HIGH:!aNULL:!MD5;
ssl_prefer_server_ciphers on;
location / {
proxy_next_upstream http_500 http_502 http_503 http_504 error timeout invalid_header;
proxy_set_header Host $host;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_pass https://saltapi.local;
expires 0;
}
#location /logs/ {
# autoindex off;
# deny all;
# }
}
标签:
原文地址:http://www.cnblogs.com/lihuiyw/p/4793976.html