Replace nginx rebuild with nginx_conf

This commit is contained in:
Manuel Gutierrez
2020-02-05 18:02:25 +01:00
parent 3a2568879a
commit 2e08f91f62
6 changed files with 53 additions and 96 deletions
+20
View File
@@ -0,0 +1,20 @@
server {
listen 80;
listen [::]:80;
return 301 https://$host:443$request_uri;
}
server {
listen 443 default_server ssl http2;
listen [::]:443 ssl http2;
ssl_certificate /etc/nginx/conf.d/ssl/kibana-access.pem;
ssl_certificate_key /etc/nginx/conf.d/ssl/kibana-access.key;
location / {
auth_basic "Restricted Access";
auth_basic_user_file /etc/nginx/conf.d/kibana.htpasswd;
proxy_pass http://kibana:5601/;
# proxy_buffer_size 128k;
# proxy_buffers 4 256k;
# proxy_busy_buffers_size 256k;
}
}
+1
View File
@@ -0,0 +1 @@
foo:$apr1$WwUDPA87$v9Bj8DS5KF9u1wBTtHH.A/
+23
View File
@@ -0,0 +1,23 @@
### Enable SSL Traffic
Our Nginx config has SSL enabled by default, but it does require you to provide your certificate first, copy here your certificate files as `kibana-access.pem` and `kibana-access.key`.
The final tree should be like this:
```
nginx_conf/
├── kibana.htpasswd
├── kibana-web.conf
└── ssl
├── kibana-access.key
└── kibana-access.pem
```
#### Using a Self Signed Certificate
In case you want to use a self-signed certificate we provided a script to generate one. You may create your own with more relevant information.
Execute `bash generate-self-signed-cert.sh` on this same directory and the right files will be generated. You must have installed `openssl` locally.
@@ -0,0 +1,9 @@
#!/bin/bash
if [ -s kibana-access.key ]
then
echo "Aborting. Certificate already exists"
exit
else
openssl req -x509 -batch -nodes -days 365 -newkey rsa:2048 -keyout kibana-access.key -out kibana-access.pem
fi