Remove /var/lib/certidude prefix for paths
This commit is contained in:
parent
974b3e5bb2
commit
67e1cf6849
@ -1,5 +1,5 @@
|
|||||||
FROM alpine as build
|
FROM alpine
|
||||||
MAINTAINER lauri <lauri@pinecrypt.com>
|
MAINTAINER Pinecrypt Labs <info@pinecrypt.com>
|
||||||
RUN apk add --update npm nginx rsync bash
|
RUN apk add --update npm nginx rsync bash
|
||||||
RUN npm install --silent --no-optional -g nunjucks@2.5.2 nunjucks-date@1.2.0 node-forge bootstrap@4.0.0-alpha.6 jquery timeago tether font-awesome qrcode-svg xterm
|
RUN npm install --silent --no-optional -g nunjucks@2.5.2 nunjucks-date@1.2.0 node-forge bootstrap@4.0.0-alpha.6 jquery timeago tether font-awesome qrcode-svg xterm
|
||||||
COPY nginx.conf /etc/nginx/nginx.conf
|
COPY nginx.conf /etc/nginx/nginx.conf
|
||||||
|
@ -1,5 +1,5 @@
|
|||||||
#!/bin/sh
|
#!/bin/sh
|
||||||
while [ ! -f /var/lib/certidude/server-secrets/self_cert.pem ]; do
|
while [ ! -f /server-secrets/self_cert.pem ]; do
|
||||||
sleep 1
|
sleep 1
|
||||||
done
|
done
|
||||||
exec nginx -g "daemon off; error_log /dev/stdout info;"
|
exec nginx -g "daemon off; error_log /dev/stdout info;"
|
||||||
|
@ -62,8 +62,8 @@ http {
|
|||||||
send_timeout 600;
|
send_timeout 600;
|
||||||
|
|
||||||
# To use CA-s own certificate for frontend and mutually authenticated connections
|
# To use CA-s own certificate for frontend and mutually authenticated connections
|
||||||
ssl_certificate /var/lib/certidude/server-secrets/self_cert.pem;
|
ssl_certificate /server-secrets/self_cert.pem;
|
||||||
ssl_certificate_key /var/lib/certidude/server-secrets/self_key.pem;
|
ssl_certificate_key /server-secrets/self_key.pem;
|
||||||
|
|
||||||
server {
|
server {
|
||||||
# Section for serving insecure HTTP, note that this is suitable for
|
# Section for serving insecure HTTP, note that this is suitable for
|
||||||
@ -145,7 +145,7 @@ http {
|
|||||||
# Allow client authentication with certificate,
|
# Allow client authentication with certificate,
|
||||||
# backend must still check if certificate was used for TLS handshake
|
# backend must still check if certificate was used for TLS handshake
|
||||||
ssl_verify_client optional;
|
ssl_verify_client optional;
|
||||||
ssl_client_certificate /var/lib/certidude/server-secrets/ca_cert.pem;
|
ssl_client_certificate /server-secrets/ca_cert.pem;
|
||||||
|
|
||||||
# Proxy pass to backend
|
# Proxy pass to backend
|
||||||
location /api/ {
|
location /api/ {
|
||||||
|
Loading…
Reference in New Issue
Block a user