gabriel / musehub public
nginx-ssl.conf
36 lines 1.2 KB
7f1d07e8 feat: domains, MCP expansion, MIDI player, and production hardening (#8) Gabriel Cardona <cgcardona@gmail.com> 4d ago
1 # /etc/nginx/sites-available/musehub
2 # This is the final config AFTER Certbot has added SSL.
3 # Certbot auto-generates a version like this; included here for reference/recovery.
4
5 server {
6 listen 80;
7 listen [::]:80;
8 server_name musehub.ai www.musehub.ai;
9 return 301 https://$host$request_uri;
10 }
11
12 server {
13 listen 443 ssl;
14 listen [::]:443 ssl;
15 server_name musehub.ai www.musehub.ai;
16
17 ssl_certificate /etc/letsencrypt/live/musehub.ai/fullchain.pem;
18 ssl_certificate_key /etc/letsencrypt/live/musehub.ai/privkey.pem;
19 include /etc/letsencrypt/options-ssl-nginx.conf;
20 ssl_dhparam /etc/letsencrypt/ssl-dhparams.pem;
21
22 client_max_body_size 50m;
23
24 # Proxy all traffic to the MuseHub uvicorn container
25 location / {
26 proxy_pass http://127.0.0.1:10003;
27 proxy_http_version 1.1;
28 proxy_set_header Upgrade $http_upgrade;
29 proxy_set_header Connection "upgrade";
30 proxy_set_header Host $host;
31 proxy_set_header X-Real-IP $remote_addr;
32 proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
33 proxy_set_header X-Forwarded-Proto $scheme;
34 proxy_read_timeout 60s;
35 }
36 }