added globals

This commit is contained in:
Mende
2020-11-27 16:51:04 +01:00
parent 1024d21556
commit 106e797edb
3 changed files with 76 additions and 0 deletions
+20
View File
@@ -20,6 +20,26 @@
notify:
- "Restart nginx"
- name: "Generate global restrictions"
template:
src: ./restrictions.j2
dest: /etc/nginx/global/restrictions.conf
owner: root
group: root
mode: 0644
notify:
- "Restart nginx"
- name: "Generate global php config"
template:
src: ./php.j2
dest: /etc/nginx/global/php.conf
owner: root
group: root
mode: 0644
notify:
- "Restart nginx"
- name: "Generate default config"
template:
src: ./default.j2
+17
View File
@@ -0,0 +1,17 @@
##
# global php settings
##
#server {
# using php-fpm socket module
location ~ \.php$ {
include snippets/fastcgi-php.conf;
#
# With php-fpm (or other unix sockets):
fastcgi_pass unix:/run/php/php7.4-fpm.sock;
# With php-cgi (or other tcp sockets):
# fastcgi_pass 127.0.0.1:9000;
}
#}
+39
View File
@@ -0,0 +1,39 @@
# Global restrictions configuration file.
# Designed to be included in any server {} block.
location = /favicon.ico {
log_not_found off;
access_log off;
}
# robots.txt fallback to index.php
location = /robots.txt {
# Some WordPress plugin gererate robots.txt file
allow all;
try_files $uri $uri/ /index.php?$args @robots;
access_log off;
log_not_found off;
}
# additional fallback if robots.txt doesn't exist
location @robots {
return 200 "User-agent: *\nDisallow: /wp-admin/\nAllow: /wp-admin/admin-ajax.php\n";
}
# Deny all attempts to access hidden files such as .htaccess, .htpasswd, .DS_Store (Mac) excepted .well-known directory.
# Keep logging the requests to parse later (or to pass to firewall utilities such as fail2ban)
location ~ /\.(?!well-known\/) {
deny all;
}
# Deny access to any files with a .php extension in the uploads directory for the single site
location /wp-content/uploads {
location ~ \.php$ {
deny all;
}
}
# Deny access to any files with a .php extension in the uploads directory
# Works in sub-directory installs and also in multisite network
# Keep logging the requests to parse later (or to pass to firewall utilities such as fail2ban)
location ~* /(?:uploads|files)/.*\.php$ {
deny all;
}