← back to Kamatera Nginx

sites-available/lacountyeats.com.conf

118 lines

# lacountyeats.com — static coming-soon
# Day-1: direct A → Kamatera (no Cloudflare proxy)
# CF IP blocks included so vhost is CF-ready when proxy is added later

# HTTP — redirect all traffic to HTTPS apex
server {
    listen 80;
    listen [::]:80;
    server_name lacountyeats.com www.lacountyeats.com;

    set_real_ip_from 173.245.48.0/20;
    set_real_ip_from 103.21.244.0/22;
    set_real_ip_from 103.22.200.0/22;
    set_real_ip_from 103.31.4.0/22;
    set_real_ip_from 141.101.64.0/18;
    set_real_ip_from 108.162.192.0/18;
    set_real_ip_from 190.93.240.0/20;
    set_real_ip_from 188.114.96.0/20;
    set_real_ip_from 197.234.240.0/22;
    set_real_ip_from 198.41.128.0/17;
    set_real_ip_from 162.158.0.0/15;
    set_real_ip_from 104.16.0.0/13;
    set_real_ip_from 104.24.0.0/14;
    set_real_ip_from 172.64.0.0/13;
    set_real_ip_from 131.0.72.0/22;
    real_ip_header CF-Connecting-IP;

    location /.well-known/acme-challenge/ {
        # proxied to lacountyeats Express on :9744
    }

    location / { proxy_pass http://127.0.0.1:9744; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto https;
        return 301 https://lacountyeats.com$request_uri;
    }
}

# HTTPS — www → apex 301
server {
    listen 443 ssl http2;
    listen [::]:443 ssl http2;
    server_name www.lacountyeats.com;

    ssl_certificate /etc/letsencrypt/live/lacountyeats.com/fullchain.pem;
    ssl_certificate_key /etc/letsencrypt/live/lacountyeats.com/privkey.pem;
    include /etc/letsencrypt/options-ssl-nginx.conf;
    ssl_dhparam /etc/letsencrypt/ssl-dhparams.pem;

    set_real_ip_from 173.245.48.0/20;
    set_real_ip_from 103.21.244.0/22;
    set_real_ip_from 103.22.200.0/22;
    set_real_ip_from 103.31.4.0/22;
    set_real_ip_from 141.101.64.0/18;
    set_real_ip_from 108.162.192.0/18;
    set_real_ip_from 190.93.240.0/20;
    set_real_ip_from 188.114.96.0/20;
    set_real_ip_from 197.234.240.0/22;
    set_real_ip_from 198.41.128.0/17;
    set_real_ip_from 162.158.0.0/15;
    set_real_ip_from 104.16.0.0/13;
    set_real_ip_from 104.24.0.0/14;
    set_real_ip_from 172.64.0.0/13;
    set_real_ip_from 131.0.72.0/22;
    real_ip_header CF-Connecting-IP;

    return 301 https://lacountyeats.com$request_uri;
}

# HTTPS — apex, serves static coming-soon
server {
    listen 443 ssl http2;
    listen [::]:443 ssl http2;
    server_name lacountyeats.com;

    ssl_certificate /etc/letsencrypt/live/lacountyeats.com/fullchain.pem;
    ssl_certificate_key /etc/letsencrypt/live/lacountyeats.com/privkey.pem;
    include /etc/letsencrypt/options-ssl-nginx.conf;
    ssl_dhparam /etc/letsencrypt/ssl-dhparams.pem;

    # Security headers + HSTS
    add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always;
    add_header X-Frame-Options "SAMEORIGIN" always;
    add_header X-Content-Type-Options "nosniff" always;
    add_header X-XSS-Protection "1; mode=block" always;
    add_header Referrer-Policy "strict-origin-when-cross-origin" always;

    set_real_ip_from 173.245.48.0/20;
    set_real_ip_from 103.21.244.0/22;
    set_real_ip_from 103.22.200.0/22;
    set_real_ip_from 103.31.4.0/22;
    set_real_ip_from 141.101.64.0/18;
    set_real_ip_from 108.162.192.0/18;
    set_real_ip_from 190.93.240.0/20;
    set_real_ip_from 188.114.96.0/20;
    set_real_ip_from 197.234.240.0/22;
    set_real_ip_from 198.41.128.0/17;
    set_real_ip_from 162.158.0.0/15;
    set_real_ip_from 104.16.0.0/13;
    set_real_ip_from 104.24.0.0/14;
    set_real_ip_from 172.64.0.0/13;
    set_real_ip_from 131.0.72.0/22;
    real_ip_header CF-Connecting-IP;

    if ($http_user_agent ~* "copyrightagent|copyrightbot") {
        return 403;
    }

    location /.well-known/acme-challenge/ {
        # proxied to lacountyeats Express on :9744
    }

    # proxied to lacountyeats Express on :9744
    

    location / { proxy_pass http://127.0.0.1:9744; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto https;
        
    }
}