From a3189d2cd14866eb868f23eb722946efabf30cea Mon Sep 17 00:00:00 2001 From: ronny abraham Date: Tue, 3 Oct 2023 17:29:19 +0300 Subject: [PATCH] got rid of some crap in unixsocket.jinja2, and fixed a but in ssl_socket that ceated a Error: duplicate listen options for [::]:443 sss --- share/templates/conf/nginx/files/ssl_socket.jinja2 | 7 +++++-- share/templates/conf/nginx/files/unixsocket.jinja2 | 6 ------ 2 files changed, 5 insertions(+), 8 deletions(-) diff --git a/share/templates/conf/nginx/files/ssl_socket.jinja2 b/share/templates/conf/nginx/files/ssl_socket.jinja2 index b1adbf1..0322bbb 100644 --- a/share/templates/conf/nginx/files/ssl_socket.jinja2 +++ b/share/templates/conf/nginx/files/ssl_socket.jinja2 @@ -1,6 +1,6 @@ upstream app_server_{{ extended_name }} { - # fail_timeout=0 means we always retry an upstream even if it failed + # fail_timeout=0 means we always retry an upstream even if it failed # to return a good HTTP response # for UNIX domain socket setups @@ -49,7 +49,10 @@ server { root html; } - listen [::]:443 ssl ipv6only=on; # managed by Certbot + # this breaks down with multiple domains using ssl + # so I'm commenting it out + # listen [::]:443 ssl ipv6only=on; # managed by Certbot + listen 443 ssl; # managed by Certbot ssl_certificate /etc/letsencrypt/live/{{server_name}}/fullchain.pem; # managed by Certbot ssl_certificate_key /etc/letsencrypt/live/{{server_name}}/privkey.pem; # managed by Certbot diff --git a/share/templates/conf/nginx/files/unixsocket.jinja2 b/share/templates/conf/nginx/files/unixsocket.jinja2 index 420769e..18ed70a 100644 --- a/share/templates/conf/nginx/files/unixsocket.jinja2 +++ b/share/templates/conf/nginx/files/unixsocket.jinja2 @@ -1,9 +1,3 @@ -# upstream django_bastardo { -# # server unix:///path/to/your/mysite/mysite.sock; # for a file socket -# #server unix:///tmp/uwsgi_replyall.sock; # for a file socket -# server 127.0.0.1:8002; # for a web port socket (we'll use this first) -# } - upstream app_server_{{ extended_name }} { # fail_timeout=0 means we always retry an upstream even if it failed # to return a good HTTP response