From cd8396f763b36bcb7d88aa33bb500af872a0f3fd Mon Sep 17 00:00:00 2001 From: maurane Date: Wed, 15 Jul 2026 14:11:44 +0200 Subject: [PATCH] update: add all nginx config for each active services --- authelia/configurations.yml | 211 ++++++++++++++++++++----------- nginx/affine | 53 ++++++++ nginx/aliasvault | 34 +++++ nginx/authelia | 31 +++++ nginx/default | 91 +++++++++++++ nginx/gitea | 53 ++++++++ nginx/homarr | 36 ++++++ nginx/matrix | 81 ++++++++++++ nginx/mealie | 35 +++++ nginx/n8n | 36 ++++++ nginx/ntfy | 67 ++++++++++ nginx/openwebui | 108 ++++++++++++++++ nginx/paperless | 34 +++++ nginx/radicale | 35 +++++ nginx/seafile | 73 +++++++++++ nginx/vikunja | 38 ++++++ paperless-ngx/docker-compose.env | 49 +++++++ paperless-ngx/docker-compose.yml | 45 +++++++ 18 files changed, 1038 insertions(+), 72 deletions(-) create mode 100644 nginx/affine create mode 100644 nginx/aliasvault create mode 100644 nginx/authelia create mode 100644 nginx/default create mode 100644 nginx/gitea create mode 100644 nginx/homarr create mode 100644 nginx/matrix create mode 100644 nginx/mealie create mode 100644 nginx/n8n create mode 100644 nginx/ntfy create mode 100644 nginx/openwebui create mode 100644 nginx/paperless create mode 100644 nginx/radicale create mode 100644 nginx/seafile create mode 100644 nginx/vikunja create mode 100644 paperless-ngx/docker-compose.env create mode 100644 paperless-ngx/docker-compose.yml diff --git a/authelia/configurations.yml b/authelia/configurations.yml index 33591c5..3ddda11 100644 --- a/authelia/configurations.yml +++ b/authelia/configurations.yml @@ -1,95 +1,162 @@ +theme: grey + +log: + file_path: /config/authelia.log + keep_stdout: true + # Stockage (fichier SQLite local) – suffisant pour commencer storage: - local: - path: /config/db.sqlite3 + local: + path: /config/db.sqlite3 # Base de données des utilisateurs (fichier) authentication_backend: - file: - path: /config/users.yml + file: + path: /config/users.yml # Accès par défaut (à ajuster selon tes besoins) access_control: - default_policy: deny - rules: - - domain: "paperless.crenam.space" - policy: one_factor - - domain: "git.crenam.space" - policy: one_factor - - domain: "task.crenam.space" - policy: one_factor - - domain: "salon.home" - + default_policy: 'one_factor' + rules: + - domain: + - "paperless.crenam.space" + - "git.crenam.space" + - "task.crenam.space" + - "seafile.crenam.space" + policy: one_factor # Session et cookie session: - cookies: - - name: authelia_session - domain: crenam.space - authelia_url: "https://auth.crenam.space" - default_redirection_url: "https://dashboard.crenam.space" - expiration: '16h' + cookies: + - name: authelia_session + domain: crenam.space + authelia_url: "https://auth.crenam.space" + default_redirection_url: "https://dashboard.crenam.space" + expiration: "16h" + remember_me: "1 month" + # sercret + # Notifications (par mail – on laisse vide pour le moment, pas de SMTP) notifier: - filesystem: - filename: /config/notifications.yml + disable_startup_check: true + filesystem: + filename: /config/notifications.yml + +# ban regulation if attempt to penetrate the network without authorization +regulation: + modes: + - "user" + max_retries: 5 + ban_time: '10m' + find_time: '2m' + +# identity_validation: + +# definitions: +# user_attributes: +# username +# email +# nickname + +# if needed, it will be lldap +# ldap: http://localhost:111 +# -# clients # identity_providers: -## The other portions of the mandatory OpenID Connect 1.0 configuration go here. -## See: https://www.authelia.com/c/oidc - # oidc: - # jwks: - # - key: {{ secret "/secrets/private.pem" | mindent 10 "|" | msquote }} - # certificate_chain: {{ secret "/secrets/public.crt" | mindent 10 "|" | msquote }} +# oidc: +# # hmac secret is used for OAuth2 tokens +# hmac_secret: - # clients: +# # jwks issuer is needed to configure multiple jwk. Must be based on RS256 algorithm +# # or on 2048 bit RSA/PA key +# jwks: +# # recommended not to configure this +# - key_id: {{ secret "/secrets/private.pem" | mindent 10 "|" | msquote }} +# # key algorithm +# algorithm: "RS256" +# use: "sig" +# key: | +# -----BEGIN PRIVATE KEY----- +# -----END PRIVATE KEY----- +# # Optionnally matchin certificate in PEM DER form +# certificate_chain: {{ secret "/secrets/public.crt" | mindent 10 "|" | msquote }} + +# # the signing algorithm used for signing discovery and metdata responses +# # most client ignore this so set it to none +# discovery_signed_response_alg: 'none' + +# # the signing key used for signing discovery and metdata responses +# # most client ignore this so set it to '' +# discovery_signed_response_key_id: '' + +# # authorization policies +# authorization_policy: +# policy_name: +# default_policy: 'two_factor' +# rules: +# - policy: 'one_factor' +# subject: 'group:services' + +# clients: ######################################### # sso configuration for vikunja # ######################################### - # - client_id: 'vikunja' - # client_name: 'Vikunja' - # client_secret: '$pbkdf2-sha512$310000$hPnUYU6BCaRSZYulOiWXwA$5hsAJD494cyoQ/X9JlAbsMF//yGDg009lfDe2WhGQjl5JA> - # public: false - # authorization_policy: 'one_factor' - # require_pkce: false - # pkce_challenge_method: '' - # redirect_uris: - # - 'https://task.crenam.space/auth/openid/authelia' - # - 'https://task.crenam.space/login?redirectToProvider=authentik' - # scopes: - # - 'openid' - # - 'profile' - # - 'email' - # response_types: - # - 'code' - # grant_types: - # - 'authorization_code' - # access_token_signed_response_alg: 'none' - # userinfo_signed_response_alg: 'none' - # token_endpoint_auth_method: 'client_secret_post' +# - client_id: 'vikunja' +# client_name: 'Vikunja' +# # generated with +# client_secret: '$pbkdf2-sha512$310000$hPnUYU6BCaRSZYulOiWXwA$5hsAJD494cyoQ/X9JlAbsMF//yGDg009lfDe2WhGQ> +# public: false +# redirect_uris: +# - 'https://task.crenam.space/auth/openid/authelia' +# - 'https://task.crenam.space/login?redirectToProvider=authentik' +# +# # audience this client is allowed to request +# audience: [] +# # scopes this client is allowed to request +# scopes: +# - +# +# # list of response modes the client support +# response_modes: +# - 'form_post' +# - 'query' +# # the policy required for this client +# # can also be the key names fot eh authorization policies section +# authorization_policy: 'one_factor' +# require_pkce: false +# pkce_challenge_method: '' +# scopes: +# - 'openid' +# - 'profile' +# - 'email' +# response_types: +# - 'code' +# grant_types: +# - 'authorization_code' +# access_token_signed_response_alg: 'none' +# userinfo_signed_response_alg: 'none' +# token_endpoint_auth_method: 'client_secret_post' ######################################### # config sso for gitea # ######################################### - # - client_id: 'gitea' - # client_name: 'Gitea' - # client_secret: '$pbkdf2-sha512$310000$pJR7colZSiWF7SWIfUsoqg$IGGqIZGVqcpXpzVCBgptZ3zBMqpFk4oaIKvOZPa1fn/GIg> - # public: false - # authorization_policy: 'one_factor' - # require_pkce: false - # pkce_challenge_method: '' - # redirect_uris: - # - 'https://git.crenam.space/user/oauth2/authelia/callback' - # scopes: - # - 'openid' - # - 'email' - # - 'profile' - # response_types: - # - 'code' - # grant_types: - # - 'authorization_code' - # access_token_signed_response_alg: 'none' - # userinfo_signed_response_alg: 'none' - # token_endpoint_auth_method: 'client_secret_basic' - +# - client_id: 'gitea' +# client_name: 'Gitea' +# client_secret: '$pbkdf2-sha512$310000$pJR7colZSiWF7SWIfUsoqg$IGGqIZGVqcpXpzVCBgptZ3zBMqpFk4oaIKvOZPa1f> +# public: false +# authorization_policy: 'one_factor' +# require_pkce: false +# pkce_challenge_method: '' +# redirect_uris: +# - 'https://git.crenam.space/user/oauth2/authelia/callback' +# scopes: +# - 'openid' +# - 'email' +# - 'profile' +# response_types: +# - 'code' +# grant_types: +# - 'authorization_code' +# access_token_signed_response_alg: 'none' +# userinfo_signed_response_alg: 'none' +# token_endpoint_auth_method: 'client_secret_basic' diff --git a/nginx/affine b/nginx/affine new file mode 100644 index 0000000..c8bd798 --- /dev/null +++ b/nginx/affine @@ -0,0 +1,53 @@ +server { + if ($host = www.affine.crenam.space) { + return 301 https://$host$request_uri; + } # managed by Certbot + + + if ($host = affine.crenam.space) { + return 301 https://$host$request_uri; + } # managed by Certbot + + + listen 80; + server_name affine.crenam.space www.affine.crenam.space; + + location / { + return 301 https://$host$request_uri; + } + + + + +} + +server { + listen 443 ssl http2; + server_name affine.crenam.space www.affine.crenam.space; + ssl_certificate /etc/letsencrypt/live/affine.crenam.space/fullchain.pem; # managed by Certbot + ssl_certificate_key /etc/letsencrypt/live/affine.crenam.space/privkey.pem; # managed by Certbot + + # Maximum allowed upload size. + client_max_body_size 100m; + + # Set required headers. + proxy_set_header Host $http_host; + proxy_set_header X-Real-IP $remote_addr; + proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; + proxy_set_header X-Forwarded-Proto $scheme; + + # WebSocket config for the sync system. + proxy_http_version 1.1; + proxy_set_header Upgrade $http_upgrade; + proxy_set_header Connection "upgrade"; + + # to add to configs for sso auth + # include /etc/nginx/snippets/authelia-verify.conf; + + location / { + # to add to configs for sso auth + # include /etc/nginx/snippets/authelia-authrequest.conf; + proxy_pass http://localhost:3010; + } +} + diff --git a/nginx/aliasvault b/nginx/aliasvault new file mode 100644 index 0000000..9588ee2 --- /dev/null +++ b/nginx/aliasvault @@ -0,0 +1,34 @@ +server { + if ($host = aliasvault.crenam.space) { + return 301 https://$host$request_uri; + } # managed by Certbot + + + listen 80; + server_name aliasvault.crenam.space; + return 301 https://$host$request_uri; + + +} + +server { + listen 443 ssl http2; + server_name aliasvault.crenam.space; + + client_max_body_size 100m; + + location / { + proxy_pass http://192.168.1.15:8008; + proxy_set_header Host $host; + proxy_set_header X-Real-IP $remote_addr; + proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; + proxy_set_header X-Forwarded-Proto https; + proxy_http_version 1.1; + proxy_set_header Upgrade $http_upgrade; + proxy_set_header Connection "upgrade"; + proxy_read_timeout 86400; + } + + ssl_certificate /etc/letsencrypt/live/aliasvault.crenam.space/fullchain.pem; # managed by Certbot + ssl_certificate_key /etc/letsencrypt/live/aliasvault.crenam.space/privkey.pem; # managed by Certbot +} diff --git a/nginx/authelia b/nginx/authelia new file mode 100644 index 0000000..4d1f206 --- /dev/null +++ b/nginx/authelia @@ -0,0 +1,31 @@ +server { + if ($host = auth.crenam.space) { + return 301 https://$host$request_uri; + } # managed by Certbot + + + listen 80; + server_name auth.crenam.space; + + return 301 https://$server_name$request_uri; + + +} + +server { + listen 443 ssl http2; + server_name auth.crenam.space; + + ssl_certificate /etc/letsencrypt/live/auth.crenam.space/fullchain.pem; # managed by Certbot + ssl_certificate_key /etc/letsencrypt/live/auth.crenam.space/privkey.pem; # managed by Certbot + + set $upstream http://192.168.27.69:9091; + + location / { + include /etc/nginx/snippets/proxy.conf; + proxy_pass $upstream; + proxy_cache_bypass $cookie_session; + proxy_no_cache $cookie_session; + } + +} diff --git a/nginx/default b/nginx/default new file mode 100644 index 0000000..c5af914 --- /dev/null +++ b/nginx/default @@ -0,0 +1,91 @@ +## +# You should look at the following URL's in order to grasp a solid understanding +# of Nginx configuration files in order to fully unleash the power of Nginx. +# https://www.nginx.com/resources/wiki/start/ +# https://www.nginx.com/resources/wiki/start/topics/tutorials/config_pitfalls/ +# https://wiki.debian.org/Nginx/DirectoryStructure +# +# In most cases, administrators will remove this file from sites-enabled/ and +# leave it as reference inside of sites-available where it will continue to be +# updated by the nginx packaging team. +# +# This file will automatically load configuration files provided by other +# applications, such as Drupal or Wordpress. These applications will be made +# available underneath a path with that package name, such as /drupal8. +# +# Please see /usr/share/doc/nginx-doc/examples/ for more detailed examples. +## + +# Default server configuration +# +server { + listen 80 default_server; + listen [::]:80 default_server; + + # SSL configuration + # + # listen 443 ssl default_server; + # listen [::]:443 ssl default_server; + # + # Note: You should disable gzip for SSL traffic. + # See: https://bugs.debian.org/773332 + # + # Read up on ssl_ciphers to ensure a secure configuration. + # See: https://bugs.debian.org/765782 + # + # Self signed certs generated by the ssl-cert package + # Don't use them in a production server! + # + # include snippets/snakeoil.conf; + + root /var/www/html; + + # Add index.php to the list if you are using PHP + index index.html index.htm index.nginx-debian.html; + + server_name _; + + location / { + # First attempt to serve request as file, then + # as directory, then fall back to displaying a 404. + try_files $uri $uri/ =404; + } + + # pass PHP scripts to FastCGI server + # + #location ~ \.php$ { + # include snippets/fastcgi-php.conf; + # + # # With php-fpm (or other unix sockets): + # fastcgi_pass unix:/run/php/php7.4-fpm.sock; + # # With php-cgi (or other tcp sockets): + # fastcgi_pass 127.0.0.1:9000; + #} + + # deny access to .htaccess files, if Apache's document root + # concurs with nginx's one + # + #location ~ /\.ht { + # deny all; + #} +} + + +# Virtual Host configuration for example.com +# +# You can move that to a different file under sites-available/ and symlink that +# to sites-enabled/ to enable it. +# +#server { +# listen 80; +# listen [::]:80; +# +# server_name example.com; +# +# root /var/www/example.com; +# index index.html; +# +# location / { +# try_files $uri $uri/ =404; +# } +#} diff --git a/nginx/gitea b/nginx/gitea new file mode 100644 index 0000000..5ff7779 --- /dev/null +++ b/nginx/gitea @@ -0,0 +1,53 @@ +server { + if ($host = www.git.crenam.space) { + return 301 https://$host$request_uri; + } # managed by Certbot + + + if ($host = git.crenam.space) { + return 301 https://$host$request_uri; + } # managed by Certbot + + + listen 80; + server_name git.crenam.space www.git.crenam.space; + + location / { + return 301 https://git.crenam.space$request_uri; + } + + + + +} + +server { + listen 443 ssl http2; + server_name git.crenam.space www.git.crenam.space; + + # ---------- Authelia ---------- +# include /etc/nginx/snippets/authelia-verify.conf; + + location / { + client_max_body_size 512M; + +# include /etc/nginx/snippets/authelia-authrequest.conf; + +# auth_request_set $auth_user $upstream_http_remote_user; +# proxy_set_header X-Webauth-user $auth_user; + + proxy_pass http://192.168.1.15:3000; + + proxy_http_version 1.1; + proxy_set_header Connection $http_connection; + proxy_set_header Upgrade $http_upgrade; + proxy_set_header Host $host; + proxy_set_header X-Real-IP $remote_addr; + proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; + proxy_set_header X-Forwarded-Proto $scheme; + } + + ssl_certificate /etc/letsencrypt/live/git.crenam.space/fullchain.pem; # managed by Certbot + ssl_certificate_key /etc/letsencrypt/live/git.crenam.space/privkey.pem; # managed by Certbot + +} diff --git a/nginx/homarr b/nginx/homarr new file mode 100644 index 0000000..de72b8f --- /dev/null +++ b/nginx/homarr @@ -0,0 +1,36 @@ +server { + if ($host = www.dashboard.crenam.space) { + return 301 https://$host$request_uri; + } # managed by Certbot + + + if ($host = dashboard.crenam.space) { + return 301 https://$host$request_uri; + } # managed by Certbot + + + listen 80; + server_name dashboard.crenam.space www.dashboard.crenam.space; + return 301 https://dashboard.crenam.space$request_uri; + + + + +} + +server { + listen 443 ssl http2; + server_name dashboard.crenam.space www.dashboard.crenam.space; + + location / { + proxy_pass http://192.168.1.15:7575; + proxy_set_header Host $host; + proxy_set_header X-Real-IP $remote_addr; + proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; + proxy_set_header X-Forwarded-Proto $scheme; + } + + ssl_certificate /etc/letsencrypt/live/dashboard.crenam.space/fullchain.pem; # managed by Certbot + ssl_certificate_key /etc/letsencrypt/live/dashboard.crenam.space/privkey.pem; # managed by Certbot + +} diff --git a/nginx/matrix b/nginx/matrix new file mode 100644 index 0000000..350fffd --- /dev/null +++ b/nginx/matrix @@ -0,0 +1,81 @@ +server { + listen 443 ssl http2; + + access_log /var/log/nginx/ess.log; + error_log /var/log/nginx/ess.errors; + ssl_certificate /etc/letsencrypt/live/ess/fullchain.pem; # managed by Certbot + ssl_certificate_key /etc/letsencrypt/live/ess/privkey.pem; # managed by Certbot + + #TLSv1.2 is required for iOS support for now + ssl_dhparam /etc/nginx/dhparam.pem; + ssl_session_cache shared:le_nginx_SSL:10m; + ssl_session_timeout 1440m; + ssl_session_tickets off; + ssl_buffer_size 4k; + # ssl_stapling on; + # ssl_stapling_verify on; + add_header Strict-Transport-Security 'max-age=31536000; includeSubDomains; preload' always; + ssl_ciphers ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384:DHE-RSA-CHACHA20-POLY1305; + + server_name admin.element.crenam.space chat.element.crenam.space matrix.element.crenam.space account.element.crenam.space mrtc.element.crenam.space element.crenam.space; + + location / { + proxy_pass http://127.0.0.1:8080; + proxy_set_header X-Forwarded-For $remote_addr; + proxy_set_header X-Forwarded-Proto $scheme; + proxy_set_header Host $host; + + client_max_body_size 50M; + + proxy_http_version 1.1; + proxy_set_header Upgrade $http_upgrade; + proxy_set_header Connection "upgrade"; + + proxy_read_timeout 86400s; + proxy_send_timeout 86400s; + proxy_buffering off; + } + + + + + + +} + +server { + if ($host = element.crenam.space) { + return 301 https://$host$request_uri; + } # managed by Certbot + + + if ($host = admin.element.crenam.space) { + return 301 https://$host$request_uri; + } # managed by Certbot + + + if ($host = chat.element.crenam.space) { + return 301 https://$host$request_uri; + } # managed by Certbot + + + if ($host = mrtc.element.crenam.space) { + return 301 https://$host$request_uri; + } # managed by Certbot + + + if ($host = account.element.crenam.space) { + return 301 https://$host$request_uri; + } # managed by Certbot + + + if ($host = matrix.element.crenam.space) { + return 301 https://$host$request_uri; + } # managed by Certbot + + + listen 80; + server_name admin.element.crenam.space chat.element.crenam.space matrix.element.crenam.space account.element.crenam.space mrtc.element.crenam.space element.crenam.space; + return 301 https://$host$request_uri; + +} diff --git a/nginx/mealie b/nginx/mealie new file mode 100644 index 0000000..869ccba --- /dev/null +++ b/nginx/mealie @@ -0,0 +1,35 @@ +server { + listen 80; + server_name mealie.crenam.space; + + if ($host = mealie.crenam.space) { + return 301 https://$host$request_uri; + } # managed by Certbot +} + +server { + listen 443 ssl http2; + server_name mealie.crenam.space; + + # En-têtes de sécurité + add_header X-Frame-Options "SAMEORIGIN" always; + add_header X-Content-Type-Options "nosniff" always; + add_header X-XSS-Protection "1; mode=block" always; + + location / { + proxy_pass http://192.168.1.30:9925; + proxy_set_header Host $host; + proxy_set_header X-Real-IP $remote_addr; + proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; + proxy_set_header X-Forwarded-Proto $scheme; + + # Désactiver le buffering pour WebSocket si besoin (Mealie ne semble pas en avoir besoin) + proxy_buffering off; + proxy_http_version 1.1; + proxy_set_header Upgrade $http_upgrade; + proxy_set_header Connection "upgrade"; + } + + ssl_certificate /etc/letsencrypt/live/mealie.crenam.space/fullchain.pem; # managed by Certbot + ssl_certificate_key /etc/letsencrypt/live/mealie.crenam.space/privkey.pem; # managed by Certbot +} diff --git a/nginx/n8n b/nginx/n8n new file mode 100644 index 0000000..dd9f161 --- /dev/null +++ b/nginx/n8n @@ -0,0 +1,36 @@ +server { + if ($host = n8n.crenam.space) { + return 301 https://$host$request_uri; + } # managed by Certbot + + + listen 80; + server_name n8n.crenam.space; + return 301 https://$server_name$request_uri; + + +} + +server { + listen 443 ssl http2; + server_name n8n.crenam.space; + + location / { + proxy_pass http://192.168.1.30:5678; # IP de Gaufre sur le réseau local + + client_max_body_size 20M; + + proxy_set_header Host $host; + proxy_set_header Upgrade $http_upgrade; + proxy_set_header Connection "upgrade"; + proxy_set_header X-Real-IP $remote_addr; + proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; + proxy_set_header X-Forwarded-Proto $scheme; + proxy_set_header X-Forwarded-Host $host; + proxy_set_header X-Forwarded-Port $server_port; + } + + + ssl_certificate /etc/letsencrypt/live/n8n.crenam.space/fullchain.pem; # managed by Certbot + ssl_certificate_key /etc/letsencrypt/live/n8n.crenam.space/privkey.pem; # managed by Certbot +} diff --git a/nginx/ntfy b/nginx/ntfy new file mode 100644 index 0000000..92ddc08 --- /dev/null +++ b/nginx/ntfy @@ -0,0 +1,67 @@ +# /etc/nginx/sites-*/ntfy +# +# This config requires the use of the -L flag in curl to redirect to HTTPS, and it keeps nginx output buffering +# enabled. While recommended, I have had issues with that in the past. + +server { + if ($host = ntfy.crenam.space) { + return 301 https://$host$request_uri; + } # managed by Certbot + + + listen 80; + server_name ntfy.crenam.space; + + location / { + return 302 https://$http_host$request_uri$is_args$query_string; + + proxy_pass http://192.168.1.15:810; + proxy_http_version 1.1; + + proxy_set_header Host $http_host; + proxy_set_header Upgrade $http_upgrade; + proxy_set_header Connection "upgrade"; + proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; + + proxy_connect_timeout 3m; + proxy_send_timeout 3m; + proxy_read_timeout 3m; + + client_max_body_size 0; # Stream request body to backend + } + + +} + +server { + listen 443 ssl http2; + server_name ntfy.crenam.space; + + # See https://ssl-config.mozilla.org/#server=nginx&version=1.18.0&config=intermediate&openssl=1.1.1k&hsts=false&ocsp=false&guideline=5.6 + ssl_session_timeout 1d; + ssl_session_cache shared:MozSSL:10m; # about 40000 sessions + ssl_session_tickets off; + ssl_protocols TLSv1.2 TLSv1.3; + ssl_ciphers ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384; + ssl_prefer_server_ciphers off; + + + location / { + proxy_pass http://192.168.1.15:810; + proxy_http_version 1.1; + + proxy_set_header Host $http_host; + proxy_set_header Upgrade $http_upgrade; + proxy_set_header Connection "upgrade"; + proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; + + proxy_connect_timeout 3m; + proxy_send_timeout 3m; + proxy_read_timeout 3m; + + client_max_body_size 0; # Stream request body to backend + } + + ssl_certificate /etc/letsencrypt/live/ntfy.crenam.space/fullchain.pem; # managed by Certbot + ssl_certificate_key /etc/letsencrypt/live/ntfy.crenam.space/privkey.pem; # managed by Certbot +} diff --git a/nginx/openwebui b/nginx/openwebui new file mode 100644 index 0000000..308151f --- /dev/null +++ b/nginx/openwebui @@ -0,0 +1,108 @@ +upstream openwebui { + # server 10.43.14.141:80; + server 51.210.13.240:3000; + keepalive 128; + keepalive_timeout 1800s; + keepalive_requests 10000; + +} + +server { + if ($host = llm.crenam.space) { + return 301 https://$host$request_uri; + } # managed by Certbot + + + listen 80; + listen [::]:80; + server_name llm.crenam.space; # ou un autre sous-domaine + return 301 https://$host$request_uri; + + +} + +server { + listen 443 ssl http2; + server_name llm.crenam.space; + + ssl_protocols TLSv1.2 TLSv1.3; + ssl_ciphers 'TLS_AES_128_GCM_SHA256:TLS_AES_256_GCM_SHA384:ECDHE-RSA-AES128-GCM-SHA256'; + ssl_prefer_server_ciphers off; + + gzip on; + gzip_types text/plain text/css application/javascript image/svg+xml; + + location /api/ { + proxy_pass http://openwebui; + proxy_http_version 1.1; + + proxy_set_header Upgrade $http_upgrade; + proxy_set_header Connection "upgrade"; + proxy_set_header Host $host; + proxy_set_header X-Real-IP $remote_addr; + proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; + proxy_set_header X-Forwarded-Proto $scheme; + + + + # CRITICAL: Disable all buffering for streaming + gzip off; + proxy_buffering off; + proxy_request_buffering off; + proxy_cache off; + tcp_nodelay on; + add_header X-Accel-Buffering "no" always; + add_header Cache-Control "no-store" always; + + + # Extended timeouts for LLM completions + proxy_connect_timeout 1800; + proxy_send_timeout 1800; + proxy_read_timeout 1800; + } + + + + # WebSocket connections need even longer timeouts + + location ~ ^/(ws/|socket\.io/) { + proxy_pass http://openwebui; + proxy_http_version 1.1; + proxy_set_header Upgrade $http_upgrade; + proxy_set_header Connection "upgrade"; + gzip off; + proxy_buffering off; + proxy_cache off; + + # 24-hour timeout for persistent connections + proxy_connect_timeout 86400; + proxy_send_timeout 86400; + proxy_read_timeout 86400; + } + + + # Static assets - CAN buffer and cache + location /static/ { + proxy_pass http://openwebui; + proxy_buffering on; + proxy_cache_valid 200 7d; + add_header Cache-Control "public, max-age=604800, immutable"; + } + + + + # Default location + + location / { + proxy_pass http://openwebui; + proxy_http_version 1.1; + proxy_set_header Host $host; + proxy_set_header X-Real-IP $remote_addr; + proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; + proxy_set_header X-Forwarded-Proto $scheme; + + } + + ssl_certificate /etc/letsencrypt/live/llm.crenam.space/fullchain.pem; # managed by Certbot + ssl_certificate_key /etc/letsencrypt/live/llm.crenam.space/privkey.pem; # managed by Certbot +} diff --git a/nginx/paperless b/nginx/paperless new file mode 100644 index 0000000..6a51f45 --- /dev/null +++ b/nginx/paperless @@ -0,0 +1,34 @@ +server { + if ($host = paperless.crenam.space) { + return 301 https://$host$request_uri; + } # managed by Certbot + + + listen 80; + server_name paperless.crenam.space; + location / { + return 301 https://$host$request_uri; + } + + +} + +server { + listen 443 ssl http2; + server_name paperless.crenam.space; + + proxy_redirect off; + proxy_buffering off; + + # Authelia Remote User + include /etc/nginx/snippets/authelia-location.conf; + + location / { + include /etc/nginx/snippets/proxy.conf; + include /etc/nginx/snippets/authelia-authrequest.conf; + proxy_pass http://192.168.1.15:8101; + } + + ssl_certificate /etc/letsencrypt/live/paperless.crenam.space/fullchain.pem; # managed by Certbot + ssl_certificate_key /etc/letsencrypt/live/paperless.crenam.space/privkey.pem; # managed by Certbot +} diff --git a/nginx/radicale b/nginx/radicale new file mode 100644 index 0000000..0145683 --- /dev/null +++ b/nginx/radicale @@ -0,0 +1,35 @@ +server { + if ($host = www.radicale.crenam.space) { + return 301 https://$host$request_uri; + } # managed by Certbot + + + if ($host = radicale.crenam.space) { + return 301 https://$host$request_uri; + } # managed by Certbot + + + listen 80; + server_name radicale.crenam.space www.radicale.crenam.space; + return 301 https://$server_name$request_uri; +} + +server { + listen 443 ssl http2; + server_name radicale.crenam.space; + client_max_body_size 512M; + + location / { + proxy_pass http://192.168.1.20:5232; + proxy_set_header X-Script-Name /radicale; + proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; + proxy_set_header X-Forwarded-Host $host; + proxy_set_header X-Forwarded-Port $server_port; + proxy_set_header X-Forwarded-Proto $scheme; + proxy_set_header Host $http_host; + proxy_pass_header Authorization; + } + + ssl_certificate /etc/letsencrypt/live/radicale.crenam.space/fullchain.pem; # managed by Certbot + ssl_certificate_key /etc/letsencrypt/live/radicale.crenam.space/privkey.pem; # managed by Certbot +} diff --git a/nginx/seafile b/nginx/seafile new file mode 100644 index 0000000..5aa0c03 --- /dev/null +++ b/nginx/seafile @@ -0,0 +1,73 @@ +log_format seafileformat '$http_x_forwarded_for $remote_addr [$time_local] "$request" $status $body_bytes_sent "$http_referer" "$http_user_agent" $upstream_response_time'; + +server { + if ($host = seafile.crenam.space) { + return 301 https://$host$request_uri; + } # managed by Certbot + + + listen 80; + server_name seafile.crenam.space; + location / { + return 301 https://$server_name$request_uri; + } + + +} + +server { + listen 443 ssl http2; + server_name seafile.crenam.space; + + include /etc/nginx/snippets/authelia-location.conf; + + location / { + include /etc/nginx/snippets/proxy.conf; + include /etc/nginx/snippets/authelia-authrequest.conf; + + proxy_pass http://192.168.1.30:80; + proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; + proxy_set_header Connection ""; + + client_max_body_size 0; + } + + location /sdoc-server/ { + include /etc/nginx/snippets/proxy.conf; + + proxy_pass http://192.168.1.30:8888/; + client_max_body_size 100m; + } + + location /socket.io { + include /etc/nginx/snippets/websocket.conf; + + proxy_pass http://192.168.1.30:8888; + proxy_redirect off; + + proxy_buffer_size 64k; + proxy_buffers 8 32k; + proxy_busy_buffers_size 64k; + proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; + proxy_set_header Host $http_host; + proxy_set_header X-NginX-Proxy true; + } + + location /notification/ping { + proxy_pass http://192.168.1.30:8083/ping; + access_log /var/log/nginx/notification.access.log seafileformat; + error_log /var/log/nginx/notification.error.log; + } + + location /notification { + include /etc/nginx/snippets/proxy.conf; + include /etc/nginx/snippets/websocket.conf; + + proxy_pass http://192.168.1.30:8083; + access_log /var/log/nginx/notification.access.log seafileformat; + error_log /var/log/nginx/notification.error.log; + } + + ssl_certificate /etc/letsencrypt/live/seafile.crenam.space/fullchain.pem; # managed by Certbot + ssl_certificate_key /etc/letsencrypt/live/seafile.crenam.space/privkey.pem; # managed by Certbot +} diff --git a/nginx/vikunja b/nginx/vikunja new file mode 100644 index 0000000..e4687e0 --- /dev/null +++ b/nginx/vikunja @@ -0,0 +1,38 @@ +server { + if ($host = task.crenam.space) { + return 301 https://$host$request_uri; + } # managed by Certbot + + + listen 80; + server_name task.crenam.space; + return 301 https://$server_name$request_uri; + + +} + +server { + listen 443 ssl http2; + server_name task.crenam.space; + + # Protection générale avec Authelia +# include /etc/nginx/snippets/authelia-verify.conf; + + location / { +# include /etc/nginx/snippets/authelia-authrequest.conf; + + proxy_pass http://192.168.1.30:3456; # IP de Gaufre sur le réseau local + + client_max_body_size 20M; + + proxy_set_header Host $host; + proxy_set_header X-Real-IP $remote_addr; + proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; + proxy_set_header X-Forwarded-Proto $scheme; + proxy_set_header X-Forwarded-Host $host; + proxy_set_header X-Forwarded-Port $server_port; + } + + ssl_certificate /etc/letsencrypt/live/task.crenam.space/fullchain.pem; # managed by Certbot + ssl_certificate_key /etc/letsencrypt/live/task.crenam.space/privkey.pem; # managed by Certbot +} diff --git a/paperless-ngx/docker-compose.env b/paperless-ngx/docker-compose.env new file mode 100644 index 0000000..cfeb5c7 --- /dev/null +++ b/paperless-ngx/docker-compose.env @@ -0,0 +1,49 @@ +############################################################################## +# Paperless-ngx settings # +############################################################################### + +# See http://docs.paperless-ngx.com/configuration/ for all available options. + +# The UID and GID of the user used to run paperless in the container. Set this +# to your UID and GID on the host so that you have write access to the +# consumption directory. +USERMAP_UID=999 +USERMAP_GID=984 + +# See the documentation linked above for all options. A few commonly adjusted settings +# are provided below. + +# This is required if you will be exposing Paperless-ngx on a public domain +# (if doing so please consider security measures such as reverse proxy) +PAPERLESS_URL=https://paperless.crenam.space + +# Adjust this key if you plan to make paperless available publicly. It should +# be a very long sequence of random characters. You don't need to remember it. +PAPERLESS_SECRET_KEY=1c5e636bb450d4903c335af08cde34262e9cd6fdcb71d983b7f9240f4344b8dd + +# Use this variable to set a timezone for the Paperless Docker containers. Defaults to UTC. +PAPERLESS_TIME_ZONE=Europe/Paris + +# The default language to use for OCR. Set this to the language most of your +# documents are written in. +PAPERLESS_OCR_LANGUAGE=fra + +# Additional languages to install for text recognition, separated by a whitespace. +# Note that this is different from PAPERLESS_OCR_LANGUAGE (default=eng), which defines +# the language used for OCR. +# The container installs English, German, Italian, Spanish and French by default. +# See https://packages.debian.org/search?keywords=tesseract-ocr-&searchon=names +# for available languages. +PAPERLESS_OCR_LANGUAGES=eng + +# Database configurations +PAPERLESS_DBHOST=192.168.27.69 +PAPERLESS_DBPORT=5432 +PAPERLESS_DBNAME=paperless +PAPERLESS_DBUSER=paperless +PAPERLESS_DBPASS=9lPYFd04mNFF0XQYzq + +# Authelia SSO configurations +PAPERLESS_ENABLE_HTTP_REMOTE_USER=true +PAPERLESS_HTTP_REMOTE_USER_HEADER_NAME=HTTP_REMOTE_USER +PAPERLESS_LOGOUT_REDIRECT_URL=https://auth.crenam.space/logout \ No newline at end of file diff --git a/paperless-ngx/docker-compose.yml b/paperless-ngx/docker-compose.yml new file mode 100644 index 0000000..d237081 --- /dev/null +++ b/paperless-ngx/docker-compose.yml @@ -0,0 +1,45 @@ +# +# - Paperless is (re)started on system boot, if it was running before shutdown. +# - Docker volumes for storing data are managed by Docker. +# - Folders for importing and exporting files are created in the same directory +# as this file and mounted to the correct folders inside the container. +# - Paperless listens on port 8000. +# +# In addition to that, this Docker Compose file adds the following optional +# configurations: +# +# - Instead of SQLite (default), PostgreSQL is used as the database server. +# +# To install and update paperless with this file, do the following: +# +# - Copy this file as 'docker-compose.yml' and the files 'docker-compose.env' +# and '.env' into a folder. +# - Run 'docker compose pull'. +# - Run 'docker compose up -d'. +# +# For more extensive installation and update instructions, refer to the +# documentation. +services: + broker: + image: docker.io/library/redis:8 + restart: unless-stopped + volumes: + - ./redisdata:/data + webserver: + image: ghcr.io/paperless-ngx/paperless-ngx:latest + restart: unless-stopped + depends_on: + - broker + ports: + - "8101:8000" + volumes: + - ./data:/usr/src/paperless/data + - ./media:/usr/src/paperless/media + - ./export:/usr/src/paperless/export + - /mnt/freebox/data/inbox:/usr/src/paperless/consume + env_file: docker-compose.env + environment: + PAPERLESS_REDIS: redis://broker:6379 + # AUTHELIA ENV VARIABLES + PAPERLESS_ENABLE_HTTP_REMOTE_USER: true + PAPERLESS_HTTP_REMOTE_USER_HEADER_NAME: HTTP_REMOTE_USER