blob: 3e6fde9d0dad8689d53788883f22fc8c1be05a71 [file] [log] [blame]
sebdetd85e24c2019-09-04 18:35:26 +02001server {
2
sebdet93b4fd42020-03-25 09:19:34 -07003 listen 2443 default ssl;
sebdetd85e24c2019-09-04 18:35:26 +02004 ssl_protocols TLSv1.2;
ChrisC2325efd2020-09-11 18:39:23 +02005 {{ if .Values.global.aafEnabled }}
6 ssl_certificate {{.Values.certInitializer.credsPath}}/{{.Values.certInitializer.clamp_pem}};
7 ssl_certificate_key {{.Values.certInitializer.credsPath}}/{{.Values.certInitializer.clamp_key}};
8 {{ else }}
sebdetd85e24c2019-09-04 18:35:26 +02009 ssl_certificate /etc/ssl/clamp.pem;
10 ssl_certificate_key /etc/ssl/clamp.key;
ChrisC2325efd2020-09-11 18:39:23 +020011 {{ end }}
12
sebdet60589992019-10-17 11:13:55 +020013 ssl_verify_client optional_no_ca;
sebdetd85e24c2019-09-04 18:35:26 +020014 location /restservices/clds/ {
15 proxy_pass https://clamp-backend:443;
sebdet60589992019-10-17 11:13:55 +020016 proxy_set_header X-SSL-Cert $ssl_client_escaped_cert;
sebdetd85e24c2019-09-04 18:35:26 +020017 }
18
19 location / {
20 root /usr/share/nginx/html;
21 index index.html index.htm;
22 try_files $uri $uri/ /index.html;
23 }
24
25 error_page 500 502 503 504 /50x.html;
26
27 location = /50x.html {
28 root /usr/share/nginx/html;
29 }
30
31}