# HTTPS gateway, only if [lighthouse] gateway_listen is set. # Needs wildcard DNS and a wildcard certificate (DNS-01): # certbot certonly --dns- -d '*.mesh.faro.example' limit_req_zone $binary_remote_addr zone=lm_gateway:10m rate=30r/s; server { listen 80; listen [::]:80; server_name *.mesh.faro.example; return 308 https://$host$request_uri; } server { listen 443 ssl http2; listen [::]:443 ssl http2; server_name *.mesh.faro.example; ssl_certificate /etc/letsencrypt/live/mesh.faro.example/fullchain.pem; ssl_certificate_key /etc/letsencrypt/live/mesh.faro.example/privkey.pem; client_max_body_size 41m; location / { limit_req zone=lm_gateway burst=60 nodelay; proxy_set_header Host $host; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_pass http://127.0.0.1:8443; proxy_read_timeout 120s; proxy_send_timeout 120s; } }