Update: 2026-08-01 19:24:16
This commit is contained in:
@@ -0,0 +1,99 @@
|
|||||||
|
# ══════════════════════════════════════════════════════════════════
|
||||||
|
# إنهاء TLS أمام سوكيتات Workerman — تطبيق intaleq
|
||||||
|
# ══════════════════════════════════════════════════════════════════
|
||||||
|
# يُنسَخ على **المضيف** لا داخل الحاويات:
|
||||||
|
# /etc/nginx/sites-enabled/intaleq-sockets-tls.conf
|
||||||
|
#
|
||||||
|
# نفس منطق siro-sockets-tls.conf تماماً، لكن هذا التطبيق (intaleq) يطلب
|
||||||
|
# https://api.intaleqapp.com:2020 و :3030 — دومين مختلف عن دومين سيرو
|
||||||
|
# (jordan-siro.intaleqapp.com). بما أن كلا التطبيقين على نفس السيرفر
|
||||||
|
# ويستخدمان نفس المنفذين الخارجيين 2020/3030، فالفصل بينهما يتم عبر
|
||||||
|
# SNI: كل server{} هنا يطابق دومينه فقط، ونجينكس يختار الحاوية الصحيحة
|
||||||
|
# من اسم الدومين في مصافحة TLS — بلا أي حاجة لتغيير المنفذين الخارجيين.
|
||||||
|
#
|
||||||
|
# الحاويتان تُنشران على 127.0.0.1 فقط (12032 / 13032 — انظر
|
||||||
|
# docker-compose.yml، DRIVER_SOCKET_PORT / PASSENGER_SOCKET_PORT)، وهذان
|
||||||
|
# المنفذان مختلفان فعلاً عن منفذي سيرو (12020 / 13030) فلا تصادم بينهما.
|
||||||
|
#
|
||||||
|
# تحقّق أولاً من مسار شهادة api.intaleqapp.com الصحيح:
|
||||||
|
# grep -rh ssl_certificate /etc/nginx/sites-enabled/ | grep -v key | sort -u
|
||||||
|
# ══════════════════════════════════════════════════════════════════
|
||||||
|
|
||||||
|
map $http_upgrade $intaleq_connection_upgrade {
|
||||||
|
default upgrade;
|
||||||
|
'' close;
|
||||||
|
}
|
||||||
|
|
||||||
|
# ── سوكيت السائقين — GPS ─────────────────────────────────────────
|
||||||
|
server {
|
||||||
|
listen 2020 ssl;
|
||||||
|
listen [::]:2020 ssl;
|
||||||
|
|
||||||
|
server_name api.intaleqapp.com;
|
||||||
|
|
||||||
|
ssl_certificate /etc/nginx/ssl-certificates/api.intaleqapp.com.crt;
|
||||||
|
ssl_certificate_key /etc/nginx/ssl-certificates/api.intaleqapp.com.key;
|
||||||
|
|
||||||
|
ssl_protocols TLSv1.2 TLSv1.3;
|
||||||
|
ssl_session_cache shared:IntaleqSock:10m;
|
||||||
|
ssl_session_timeout 1d;
|
||||||
|
|
||||||
|
access_log off;
|
||||||
|
error_log /var/log/nginx/intaleq-socket-driver-error.log warn;
|
||||||
|
|
||||||
|
location / {
|
||||||
|
proxy_pass http://127.0.0.1:12032;
|
||||||
|
|
||||||
|
proxy_http_version 1.1;
|
||||||
|
proxy_set_header Upgrade $http_upgrade;
|
||||||
|
proxy_set_header Connection $intaleq_connection_upgrade;
|
||||||
|
|
||||||
|
proxy_set_header Host $host;
|
||||||
|
proxy_set_header X-Real-IP $remote_addr;
|
||||||
|
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
||||||
|
proxy_set_header X-Forwarded-Proto $scheme;
|
||||||
|
|
||||||
|
proxy_connect_timeout 10s;
|
||||||
|
proxy_send_timeout 3600s;
|
||||||
|
proxy_read_timeout 3600s;
|
||||||
|
|
||||||
|
proxy_buffering off;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
# ── سوكيت الركاب — حالة الرحلة وموقع السائق ──────────────────────
|
||||||
|
server {
|
||||||
|
listen 3030 ssl;
|
||||||
|
listen [::]:3030 ssl;
|
||||||
|
|
||||||
|
server_name api.intaleqapp.com;
|
||||||
|
|
||||||
|
ssl_certificate /etc/nginx/ssl-certificates/api.intaleqapp.com.crt;
|
||||||
|
ssl_certificate_key /etc/nginx/ssl-certificates/api.intaleqapp.com.key;
|
||||||
|
|
||||||
|
ssl_protocols TLSv1.2 TLSv1.3;
|
||||||
|
ssl_session_cache shared:IntaleqSock:10m;
|
||||||
|
ssl_session_timeout 1d;
|
||||||
|
|
||||||
|
access_log off;
|
||||||
|
error_log /var/log/nginx/intaleq-socket-passenger-error.log warn;
|
||||||
|
|
||||||
|
location / {
|
||||||
|
proxy_pass http://127.0.0.1:13032;
|
||||||
|
|
||||||
|
proxy_http_version 1.1;
|
||||||
|
proxy_set_header Upgrade $http_upgrade;
|
||||||
|
proxy_set_header Connection $intaleq_connection_upgrade;
|
||||||
|
|
||||||
|
proxy_set_header Host $host;
|
||||||
|
proxy_set_header X-Real-IP $remote_addr;
|
||||||
|
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
||||||
|
proxy_set_header X-Forwarded-Proto $scheme;
|
||||||
|
|
||||||
|
proxy_connect_timeout 10s;
|
||||||
|
proxy_send_timeout 3600s;
|
||||||
|
proxy_read_timeout 3600s;
|
||||||
|
|
||||||
|
proxy_buffering off;
|
||||||
|
}
|
||||||
|
}
|
||||||
Reference in New Issue
Block a user