Skip to content

Commit 5d9a518

Browse files
Update nixpacks.toml
1 parent 51b0c3e commit 5d9a518

File tree

1 file changed

+3
-25
lines changed

1 file changed

+3
-25
lines changed

nixpacks.toml

Lines changed: 3 additions & 25 deletions
Original file line numberDiff line numberDiff line change
@@ -1,14 +1,12 @@
11
[phases.setup]
2-
nixPkgs = ["...", "python311Packages.supervisor", "openssl"]
2+
nixPkgs = ["...", "python311Packages.supervisor"]
33

44
[phases.build]
55
cmds = [
66
"mkdir -p /etc/supervisor/conf.d/",
77
"cp /assets/worker-*.conf /etc/supervisor/conf.d/",
88
"cp /assets/supervisord.conf /etc/supervisord.conf",
99
"chmod +x /assets/start.sh",
10-
"mkdir -p /etc/ssl/certs /etc/ssl/private",
11-
"openssl req -x509 -nodes -days 365 -newkey rsa:2048 -keyout /etc/ssl/private/nginx-selfsigned.key -out /etc/ssl/certs/nginx-selfsigned.crt -subj '/CN=localhost'",
1210
"..."
1311
]
1412

@@ -124,48 +122,28 @@ http {
124122
error_log /var/log/nginx-error.log;
125123
sendfile on;
126124
tcp_nopush on;
127-
server_names_hash_bucket_size 128;
125+
server_names_hash_bucket_size 128; # this seems to be required for some vhosts
128126
129-
# HTTP server - redirects to HTTPS
130127
server {
131128
listen ${PORT};
132129
listen [::]:${PORT};
133130
server_name localhost;
134131
135-
return 301 https://$host$request_uri;
136-
}
137-
138-
# HTTPS server
139-
server {
140-
listen 443 ssl;
141-
listen [::]:443 ssl;
142-
server_name localhost;
143-
144-
# SSL Certificate Configuration
145-
ssl_certificate /etc/ssl/certs/nginx-selfsigned.crt;
146-
ssl_certificate_key /etc/ssl/private/nginx-selfsigned.key;
147-
ssl_protocols TLSv1.2 TLSv1.3;
148-
ssl_prefer_server_ciphers on;
149-
ssl_ciphers "EECDH+AESGCM:EDH+AESGCM:AES256+EECDH:AES256+EDH";
150-
ssl_session_cache shared:SSL:10m;
151-
ssl_session_timeout 1h;
152-
ssl_session_tickets off;
153-
154132
$if(NIXPACKS_PHP_ROOT_DIR) (
155133
root ${NIXPACKS_PHP_ROOT_DIR};
156134
) else (
157135
root /app;
158136
)
159137
160138
add_header X-Content-Type-Options "nosniff";
161-
add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always;
162139
163140
client_max_body_size 35M;
164141
165142
index index.php;
166143
167144
charset utf-8;
168145
146+
169147
$if(NIXPACKS_PHP_FALLBACK_PATH) (
170148
location / {
171149
try_files $uri $uri/ ${NIXPACKS_PHP_FALLBACK_PATH}?$query_string;

0 commit comments

Comments
 (0)