From caf1eb7d7b3082a6b3a335e59cdd5813b82f3966 Mon Sep 17 00:00:00 2001 From: Guilhem Moulin Date: Sun, 17 May 2020 17:03:00 +0200 Subject: git, wiki, website: Improve gzip support. --- roles/git/files/etc/nginx/sites-available/git | 9 +++++++-- roles/wiki/files/etc/nginx/sites-available/website | 13 ++++++------- roles/wiki/files/etc/nginx/sites-available/wiki | 7 ++++++- 3 files changed, 19 insertions(+), 10 deletions(-) diff --git a/roles/git/files/etc/nginx/sites-available/git b/roles/git/files/etc/nginx/sites-available/git index 7ad765f..0aa4345 100644 --- a/roles/git/files/etc/nginx/sites-available/git +++ b/roles/git/files/etc/nginx/sites-available/git @@ -33,9 +33,13 @@ server { ssl_certificate_key ssl/git.fripost.org.key; include snippets/git.fripost.org.hpkp-hdr; + gzip on; + gzip_vary on; + gzip_min_length 256; + gzip_types application/javascript application/json application/xml image/svg+xml image/x-icon text/css text/plain; + location ^~ /static/ { alias /usr/share/cgit/; - expires 30d; } # disallow push over HTTP/HTTPS @@ -58,10 +62,11 @@ server { fastcgi_pass unix:/run/git-http-backend.socket; } + location = /robots.txt { root /usr/share/cgit; } + location = /favicon.ico { root /usr/share/cgit; } # send all other URLs to cgit location / { - gzip off; fastcgi_param SCRIPT_FILENAME /usr/lib/cgit/cgit.cgi; fastcgi_param PATH_INFO $uri; fastcgi_param CONTENT_TYPE $content_type; diff --git a/roles/wiki/files/etc/nginx/sites-available/website b/roles/wiki/files/etc/nginx/sites-available/website index c524800..cd6832a 100644 --- a/roles/wiki/files/etc/nginx/sites-available/website +++ b/roles/wiki/files/etc/nginx/sites-available/website @@ -35,28 +35,27 @@ server { ssl_certificate_key ssl/www.fripost.org.key; include snippets/fripost.org.hpkp-hdr; + gzip on; + gzip_vary on; + gzip_min_length 256; + gzip_types application/font-woff application/font-woff2 application/javascript application/json application/xml image/svg+xml image/x-icon text/css text/plain; + location / { try_files $uri $uri/ =404; index index.html; root /var/lib/ikiwiki/public_html/fripost-wiki/website; } + location = /ikiwiki.cgi { internal; } location /static/ { alias /var/lib/ikiwiki/public_html/fripost-wiki/static/; - expires 30d; } location /material/ { alias /var/www/fripost.org/material/; - expires 30d; } location /minutes/ { alias /var/www/fripost.org/minutes/; - expires 30d; } location /.well-known/autoconfig/ { alias /var/www/fripost.org/autoconfig/; } - - location = /ikiwiki.cgi { - return 403; - } } diff --git a/roles/wiki/files/etc/nginx/sites-available/wiki b/roles/wiki/files/etc/nginx/sites-available/wiki index 4b62d54..89e86d8 100644 --- a/roles/wiki/files/etc/nginx/sites-available/wiki +++ b/roles/wiki/files/etc/nginx/sites-available/wiki @@ -34,6 +34,11 @@ server { ssl_certificate_key ssl/www.fripost.org.key; include snippets/fripost.org.hpkp-hdr; + gzip on; + gzip_vary on; + gzip_min_length 256; + gzip_types application/font-woff application/font-woff2 application/javascript application/json application/xml image/svg+xml image/x-icon text/css text/plain; + location / { location ~ ^/website(/.*)?$ { return 302 $scheme://fripost.org$1; } try_files $uri $uri/ =404; @@ -47,6 +52,6 @@ server { fastcgi_index ikiwiki.cgi; include snippets/fastcgi.conf; fastcgi_pass unix:/run/ikiwiki.socket; - gzip off; + gzip off; # protect against BREACH } } -- cgit v1.2.3