A #linux application runs inside an LX-branded zone, where the #Illumos kernel (descended from #Solaris) natively implements the Linux kernel ABI. A #VPN connection, terminated in a separate Solaris-style zone, routes the application's traffic to a VPN endpoint on an #OpenBSD system running #Nginx, which serves #HTTPS content on a custom domain.
Life is great!
A #linux application runs inside an LX-branded zone, where the #Illumos kernel (descended from #Solaris) natively implements the Linux kernel ABI. A #VPN connection, terminated in a separate Solaris-style zone, routes the application's traffic to a VPN endpoint on an #OpenBSD system running #Nginx, which serves #HTTPS content on a custom domain.
Life is great!
I've got the skeleton of a companion container for nginx-proxy/nginx-proxy that will use RFC2136 to add/remove CNAME entries for proxied containers as they are created/removed.
I'll push it to GitHub from my Forgejo instance once it's a little bit more polished
This is in a similar vein to my one that adds mdns/avahi CNAME to the host machine.
https://github.com/hardillb/nginx-proxy-avahi-helper
I've got the skeleton of a companion container for nginx-proxy/nginx-proxy that will use RFC2136 to add/remove CNAME entries for proxied containers as they are created/removed.
I'll push it to GitHub from my Forgejo instance once it's a little bit more polished
This is in a similar vein to my one that adds mdns/avahi CNAME to the host machine.
https://github.com/hardillb/nginx-proxy-avahi-helper
What #OpenSource and #SelfHost can do. Had an idea, discussed it here. Seemed to rhyme with people. Booked two domains. Created a landing page with #Jekyll and CI/CD from a #git repo on my #Forgejo instance. Created logo with #Inkscape. Added #letsencrypt certificate. Put it on my VPS (Virtual Private Server) running Red Hat Enterprise Linux, (#RHEL) where it is now served with #Nginx. Git repo mirrored to #Codeberg so all can join. In under 8h.
Does anyone know of a public set of ModSecurity exceptions for the fediverse/ActivityPub I can take a look at? I'm setting it up for GoToSocial and Mastodon now and manually doing this is pain.
Update, @cloudymax and I started a plugin here:
https://github.com/small-hack/argocd-apps/blob/2b7995c6fae5ecbb3944c6c6f4b139d98b76e67f/ingress-nginx/modsecurity_plugins_configmap.yaml#L177
Still happy to collaborate on it, but also wanted to note there was a mention a year ago about making an ActivityPub plugin over at the OWASP CRS repo, so maybe we could donate to that if its ever created:
https://github.com/coreruleset/coreruleset/issues/3497#issuecomment-1902181156
#WAF #modsecurity #nginx #apache #firewall #webApplicationFirewall #mastodon #gotosocial #activitypub
Does anyone know of a public set of ModSecurity exceptions for the fediverse/ActivityPub I can take a look at? I'm setting it up for GoToSocial and Mastodon now and manually doing this is pain.
Update, @cloudymax and I started a plugin here:
https://github.com/small-hack/argocd-apps/blob/2b7995c6fae5ecbb3944c6c6f4b139d98b76e67f/ingress-nginx/modsecurity_plugins_configmap.yaml#L177
Still happy to collaborate on it, but also wanted to note there was a mention a year ago about making an ActivityPub plugin over at the OWASP CRS repo, so maybe we could donate to that if its ever created:
https://github.com/coreruleset/coreruleset/issues/3497#issuecomment-1902181156
#WAF #modsecurity #nginx #apache #firewall #webApplicationFirewall #mastodon #gotosocial #activitypub
What #OpenSource and #SelfHost can do. Had an idea, discussed it here. Seemed to rhyme with people. Booked two domains. Created a landing page with #Jekyll and CI/CD from a #git repo on my #Forgejo instance. Created logo with #Inkscape. Added #letsencrypt certificate. Put it on my VPS (Virtual Private Server) running Red Hat Enterprise Linux, (#RHEL) where it is now served with #Nginx. Git repo mirrored to #Codeberg so all can join. In under 8h.
https://github.com/nginx/nginx/pull/840
If you want to see ECH in nginx sooner rather than later, please jump in and review, give feedback, thumbs up, etc.
https://github.com/nginx/nginx/pull/840
If you want to see ECH in nginx sooner rather than later, please jump in and review, give feedback, thumbs up, etc.
I know #iocaine doesn't have a fully fledged howto for using #nginx as the reverse proxy, but I have a lot in my nginx config currently, so I want to try and get it working there
After figuring out that the different configuration pages don't agree on what socket path for the client connections to iocaine, I now have the 421 error being returned to the browser, but I don't understand what I need to fix to get to a working set up
I have no log outputs when accessing blog.cerberos.id.au
#askFedi
He afegit dues gràfiques més al panell de Grafana que mostra totes les peticions que gestiona nginx d'aquest servidor mastodont.cat.
"avg request time" mostra el temps total promig en atendre una petició, per exemple, actualitzar la línia de temps. "avg upstream time" mostra el temps promig que necessita el "back-end" per a gestionar-la.
https://blog.nginx.org/blog/native-support-for-acme-protocol
#Web#Webserver
https://blog.nginx.org/blog/native-support-for-acme-protocol
#Web#Webserver
Competition is a funny thing. #nginx finally introduces native support fort the #ACME protocol.
Competition is a funny thing. #nginx finally introduces native support fort the #ACME protocol.