fix(nginx): split saas and git domains
This commit is contained in:
@@ -1,17 +1,23 @@
|
||||
# Production Nginx routing for XiaoXia SaaS.
|
||||
#
|
||||
# Domains are intentionally separated:
|
||||
# - xiaoxiajianji.com / www.xiaoxiajianji.com: SaaS web UI
|
||||
# - api.xiaoxiajianji.com: SaaS API, docs, generated files
|
||||
# - git.xiaoxiajianji.com: Gitea code repository
|
||||
|
||||
server {
|
||||
listen 443 ssl http2;
|
||||
server_name api.xiaoxiajianji.com;
|
||||
|
||||
ssl_certificate /etc/letsencrypt/live/api.xiaoxiajianji.com/fullchain.pem;
|
||||
ssl_certificate_key /etc/letsencrypt/live/api.xiaoxiajianji.com/privkey.pem;
|
||||
server_name xiaoxiajianji.com www.xiaoxiajianji.com;
|
||||
|
||||
ssl_certificate /etc/letsencrypt/live/xiaoxiajianji.com/fullchain.pem;
|
||||
ssl_certificate_key /etc/letsencrypt/live/xiaoxiajianji.com/privkey.pem;
|
||||
include /etc/letsencrypt/options-ssl-nginx.conf;
|
||||
ssl_dhparam /etc/letsencrypt/ssl-dhparams.pem;
|
||||
|
||||
|
||||
client_max_body_size 100m;
|
||||
|
||||
# Gitea 代码仓库(保留)
|
||||
location /git/ {
|
||||
proxy_pass http://127.0.0.1:3000/;
|
||||
|
||||
location / {
|
||||
proxy_pass http://127.0.0.1:3002/;
|
||||
proxy_http_version 1.1;
|
||||
proxy_set_header Host $host;
|
||||
proxy_set_header X-Real-IP $remote_addr;
|
||||
@@ -19,10 +25,20 @@ server {
|
||||
proxy_set_header X-Forwarded-Proto $scheme;
|
||||
proxy_set_header Upgrade $http_upgrade;
|
||||
proxy_set_header Connection upgrade;
|
||||
proxy_read_timeout 300s;
|
||||
}
|
||||
|
||||
# SaaS API
|
||||
}
|
||||
|
||||
server {
|
||||
listen 443 ssl http2;
|
||||
server_name api.xiaoxiajianji.com;
|
||||
|
||||
ssl_certificate /etc/letsencrypt/live/api.xiaoxiajianji.com/fullchain.pem;
|
||||
ssl_certificate_key /etc/letsencrypt/live/api.xiaoxiajianji.com/privkey.pem;
|
||||
include /etc/letsencrypt/options-ssl-nginx.conf;
|
||||
ssl_dhparam /etc/letsencrypt/ssl-dhparams.pem;
|
||||
|
||||
client_max_body_size 100m;
|
||||
|
||||
location /api/ {
|
||||
proxy_pass http://127.0.0.1:8001;
|
||||
proxy_http_version 1.1;
|
||||
@@ -32,7 +48,6 @@ server {
|
||||
proxy_set_header X-Forwarded-Proto $scheme;
|
||||
}
|
||||
|
||||
# API health and documentation
|
||||
location = /health {
|
||||
proxy_pass http://127.0.0.1:8001/health;
|
||||
proxy_http_version 1.1;
|
||||
@@ -60,7 +75,6 @@ server {
|
||||
proxy_set_header X-Forwarded-Proto $scheme;
|
||||
}
|
||||
|
||||
# Generated video files
|
||||
location /generated-files/ {
|
||||
alias /var/lib/xiaoxia-saas-production/generated/;
|
||||
types {
|
||||
@@ -69,10 +83,25 @@ server {
|
||||
default_type application/octet-stream;
|
||||
add_header Cache-Control "public, max-age=3600";
|
||||
}
|
||||
|
||||
# SaaS Web(默认路径)
|
||||
|
||||
location / {
|
||||
proxy_pass http://127.0.0.1:3002/;
|
||||
return 404;
|
||||
}
|
||||
}
|
||||
|
||||
server {
|
||||
listen 443 ssl http2;
|
||||
server_name git.xiaoxiajianji.com;
|
||||
|
||||
ssl_certificate /etc/letsencrypt/live/git.xiaoxiajianji.com/fullchain.pem;
|
||||
ssl_certificate_key /etc/letsencrypt/live/git.xiaoxiajianji.com/privkey.pem;
|
||||
include /etc/letsencrypt/options-ssl-nginx.conf;
|
||||
ssl_dhparam /etc/letsencrypt/ssl-dhparams.pem;
|
||||
|
||||
client_max_body_size 100m;
|
||||
|
||||
location / {
|
||||
proxy_pass http://127.0.0.1:3000/;
|
||||
proxy_http_version 1.1;
|
||||
proxy_set_header Host $host;
|
||||
proxy_set_header X-Real-IP $remote_addr;
|
||||
@@ -80,11 +109,24 @@ server {
|
||||
proxy_set_header X-Forwarded-Proto $scheme;
|
||||
proxy_set_header Upgrade $http_upgrade;
|
||||
proxy_set_header Connection upgrade;
|
||||
proxy_read_timeout 300s;
|
||||
}
|
||||
}
|
||||
|
||||
server {
|
||||
listen 80;
|
||||
server_name xiaoxiajianji.com www.xiaoxiajianji.com;
|
||||
return 301 https://xiaoxiajianji.com$request_uri;
|
||||
}
|
||||
|
||||
server {
|
||||
listen 80;
|
||||
server_name api.xiaoxiajianji.com;
|
||||
return 301 https://api.xiaoxiajianji.com$request_uri;
|
||||
}
|
||||
|
||||
server {
|
||||
listen 80;
|
||||
server_name git.xiaoxiajianji.com;
|
||||
return 301 https://git.xiaoxiajianji.com$request_uri;
|
||||
}
|
||||
|
||||
@@ -36,7 +36,7 @@ echo ""
|
||||
echo "✅ 部署完成!"
|
||||
echo ""
|
||||
echo "📍 服务访问地址:"
|
||||
echo " Web: https://api.xiaoxiajianji.com"
|
||||
echo " Web: https://xiaoxiajianji.com"
|
||||
echo " API: https://api.xiaoxiajianji.com/docs"
|
||||
echo ""
|
||||
echo "📊 容器状态:"
|
||||
|
||||
@@ -53,9 +53,9 @@ echo ""
|
||||
echo "🎉 初始化完成!"
|
||||
echo ""
|
||||
echo "📍 服务访问地址:"
|
||||
echo " Web: https://api.xiaoxiajianji.com"
|
||||
echo " API: https://api.xiaoxiajianji.com/api/v1/docs"
|
||||
echo " Git: https://api.xiaoxiajianji.com/git"
|
||||
echo " Web: https://xiaoxiajianji.com"
|
||||
echo " API: https://api.xiaoxiajianji.com/docs"
|
||||
echo " Git: https://git.xiaoxiajianji.com"
|
||||
echo ""
|
||||
echo "📊 容器状态:"
|
||||
docker compose ps
|
||||
|
||||
Reference in New Issue
Block a user