ctucx.git: ansible-configs

My personal ansible roles and playbooks [deprecated in favor of nixos]

1 
2 
3 
4 
5 
6 
7 
8 
9 
10 
11 
12 
13 
14 
15 
16 
17 
18 
19 
20 
21 
22 
23 
24 
25 
26 
27 
28 
29 
30 
31 
32 
33 
34 
35 
36 
37 
38 
39 
40 
41 
42 
43 
44 
45 
46 
47 
48 
49 
50 
51 #
# !!! This file is managed by Ansible !!!
#

upstream oeffisearch {
	least_conn;
	server 127.0.0.1:8081;
	server 127.0.0.1:8082;
	server 127.0.0.1:8083;
	server 127.0.0.1:8084;
}

{% if  services.oeffisearch.nginx.sslOnly is not defined or services.oeffisearch.nginx.sslOnly is false %}
server {
	listen 80 ;
	listen [::]:80;
	
	server_name {{ services.oeffisearch.nginx.domain }};

	location / {
		try_files $uri $uri/ @api;
		root /usr/share/oeffisearch;
	}

	location @api {
		proxy_pass http://oeffisearch;
	}
}

{% endif %}
{% if services.oeffisearch.nginx.ssl.enable is true %}
server {
	listen 443 ssl;
	listen [::]:443 ssl;

	ssl_certificate "{{ services.oeffisearch.nginx.ssl.cert }}";
	ssl_certificate_key "{{ services.oeffisearch.nginx.ssl.privkey }}";
	include /etc/nginx/ssl.conf;
	
	server_name {{ services.oeffisearch.nginx.domain }};

	location / {
		try_files $uri $uri/ @api;
		root /usr/share/oeffisearch;
	}

	location @api {
		proxy_pass http://oeffisearch;
	}
}
{% endif %}