Nginx improvements. Closes #1499 - #1500
Draft
regulartim wants to merge 11 commits into
Draft
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
This introduces several improvements to the nginx configuration:
ssl.conffile which is not part of the repository. This means that on fresh installations or upgrades to the next version that includes this change, a single manual intervention is required. Instance admins need to copy and populate the prepared template file. Future changes to the https configuration file won't require any manual intervention.ssl.conf).^~/adminhas been removed./static/path.Documentation for the Wiki
HTTPS
In production GreedyBear should be used with TLS enabled. To create self-signed certificates for testing or internal use, run this command with the appropriate information in
-subj:sudo openssl req -x509 -nodes -days 3650 -newkey rsa:2048 \ -keyout /etc/ssl/private/greedybear.key \ -out /usr/local/share/ca-certificates/greedybear.crt \ -subj "/C=DE/ST=Hessen/L=Frankfurt/O=YourOrg/CN=greedybear.yourorg.de"Prepare your environment. Run the initialization with the
--httpsflag:# Production environment with HTTPS and external T-Pot Elasticsearch ./gbctl init --https --elastic-endpoint http://tpot-host:64298Now copy the TLS configuration template and change the paths, if necessary, such that they point to your SSL certificates. Your certificate and key must reside under
/usr/local/share/ca-certificates/and/etc/ssl/private/respectively, as these are the only host directories mounted into the nginx container.# Copy template and edit configuration cp configuration/nginx/ssl.conf.template configuration/nginx/ssl.conf nano configuration/nginx/ssl.confNote: The
-nodesflag in theopensslcommand creates an unencrypted key, which nginx can read without further configuration. If you instead use an encrypted key, uncomment ssl_password_file in ssl.conf and point it at a file containing the passphrase. Nginx cannot prompt for one at startup and will fail to boot without it. That file must also live under /etc/ssl/private/.Related issues
Type of change
Checklist
Please complete this checklist carefully. It helps guide your contribution and lets maintainers verify that all requirements are met.
Formalities
<feature name>. Closes #999develop.develop.Docs and tests
Ruff) gave 0 errors. If you have correctly installed pre-commit, it does these checks and adjustments on your behalf.GUI changes
Ignore this section if you did not make any changes to the GUI.
Review process