From: Michael Krause Date: Fri, 28 Jul 2017 10:12:26 +0000 (+0200) Subject: update proxy_pass for confluence ajp X-Git-Tag: v0.1.0~2666^2~57 X-Git-Url: https://git.uhu-banane.de/?a=commitdiff_plain;h=47434fb30474b123f9f03510caaaf5dab1b1ffcb;p=pixelpark%2Fhiera.git update proxy_pass for confluence ajp --- diff --git a/customer/pixelpark/extranet01.pixelpark.net.yaml b/customer/pixelpark/extranet01.pixelpark.net.yaml index ff31bbc6..14b407ea 100644 --- a/customer/pixelpark/extranet01.pixelpark.net.yaml +++ b/customer/pixelpark/extranet01.pixelpark.net.yaml @@ -8,6 +8,7 @@ accounts::users: infra::role: base infra::additional_classes: - infra::profile::apache + - apache::mod::proxy_ajp # fact override infra::profile::icinga2::client::ipv4: '217.66.53.109' @@ -24,14 +25,25 @@ infra::profile::apache::pp_vhosts: ssl_cert: '/etc/pki/tls/certs/wildcard.pixelpark.com-cert.pem' ssl_key: '/etc/pki/tls/private/wildcard.pixelpark.com-key.pem' ssl_chain: '/etc/pki/tls/certs/wildcard.pixelpark.com-cert.pem' -# proxy_dest: 'ajp://extranet01.pixelpark.net:8001/confluence/' -# no_proxy_uris: -# - /server-status -# - /server-info + docroot_owner: apache + docroot_group: apache + docroot_mode: '2775' + directories: + - directory_root: + provider: directory + path: '/var/www/jira' + options: + - FollowSymLinks + - MultiViews + allow_override: + - All + directoryindex: index.html proxy_pass: - { path: /server-status, url: '!' } - { path: /server-info, url: '!' } - - { path: /confluence/, url: 'http://localhost:8090/confluence/' } + - { path: /confluence, url: 'ajp://extranet01.pixelpark.net:8001/confluence' } + headers_ssl: + - always set Strict-Transport-Security "max-age=31556926" setenvif: - 'Remote_Addr ^(217\.66\.49\.|217\.66\.50\.|217\.66\.51\.|217\.66\.56\.|213\.61\.241\.|81\.173\.202\.|194\.8\.221\.2|10\.200\.|62\.214\.114\.) ppnetze=true' rewrites: @@ -40,7 +52,7 @@ infra::profile::apache::pp_vhosts: - ^(/?)$ /confluence/ [R=301,L] - comment: 'switch to https' rewrite_cond: - - '%%{ich-trickse}{HTTPS} !=on' + - '%%{ich-trickse}{HTTPS} !=on [NC]' rewrite_rule: - ^(.*)$ https://%%{ich-trickse}{HTTP_HOST}$1 [R=301,L] - comment: 'browse people'