summaryrefslogtreecommitdiffstats
path: root/files/etc/nginx
diff options
context:
space:
mode:
Diffstat (limited to 'files/etc/nginx')
-rw-r--r--files/etc/nginx/sites-available/webmap5
-rw-r--r--files/etc/nginx/snippets/ssl.conf7
2 files changed, 4 insertions, 8 deletions
diff --git a/files/etc/nginx/sites-available/webmap b/files/etc/nginx/sites-available/webmap
index 121dada..e43af57 100644
--- a/files/etc/nginx/sites-available/webmap
+++ b/files/etc/nginx/sites-available/webmap
@@ -66,7 +66,7 @@ server {
location ^~ /assets/ {
expires 7d;
try_files $uri =404;
- location ~ "\.(css|js|svg)$" {
+ location ~ "\.(?:css|js|svg)$" {
brotli_static on;
}
}
@@ -82,6 +82,9 @@ server {
try_files $uri =404;
# service an empty payload to save bandwidth
error_page 404 /_.txt;
+ location ~ "\.json$" {
+ brotli_static on;
+ }
}
location = /q {
expires epoch;
diff --git a/files/etc/nginx/snippets/ssl.conf b/files/etc/nginx/snippets/ssl.conf
index 0bce30a..b86f5e3 100644
--- a/files/etc/nginx/snippets/ssl.conf
+++ b/files/etc/nginx/snippets/ssl.conf
@@ -7,10 +7,3 @@ ssl_dhparam /etc/ssl/dhparams.pem;
ssl_protocols TLSv1.2 TLSv1.3;
ssl_ciphers ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384:DHE-RSA-CHACHA20-POLY1305;
ssl_prefer_server_ciphers off;
-
-ssl_stapling on;
-ssl_stapling_verify on;
-
-ssl_trusted_certificate /usr/share/lacme/ca-certificates.crt;
-
-resolver 127.0.0.53;