153 lines
7.0 KiB
Plaintext
153 lines
7.0 KiB
Plaintext
# ══════════════════════════════════════════════════════════════════
|
||
# إنهاء TLS أمام سوكيتات Workerman
|
||
# ══════════════════════════════════════════════════════════════════
|
||
# يُنسَخ على **المضيف** لا داخل الحاويات:
|
||
# /etc/nginx/sites-enabled/tripz-sockets-tls.conf
|
||
#
|
||
# المشكلة التي يحلّها: حاويات السوكيت تفتح منافذها نصاً صريحاً
|
||
# (new SocketIO(2020) / (3030) / (4040) بلا سياق SSL)، بينما
|
||
# التطبيقات تطلب https://api.tripz-egypt.com:2020 و:3030 و:4040.
|
||
# مصافحة TLS ضد منفذ لا يتكلم TLS تتجمّد حتى المهلة، فيظهر في اللوج:
|
||
# Socket Connect Error: timeout
|
||
#
|
||
# الحل: الحاويات تُنشر على 127.0.0.1 فقط (12022 / 13033 / 14042)،
|
||
# و nginx هنا يستمع على 2020 / 3030 / 4040 بشهادة الدومين ويمرّر
|
||
# إليها مع ترقية WebSocket. النتيجة: روابط التطبيقات تبقى كما هي
|
||
# وبلا أي بناء جديد، والـ JWT في الـ query string يبقى داخل نفق TLS.
|
||
#
|
||
# ⚠️ هذه الملفات الثلاثة تعيش على نفس السيرفر مع نسخ أخرى بمنافذ
|
||
# خارجية مطابقة (2020/3030/4040) وبـ server_name مختلف — يفصل nginx
|
||
# بينها حسب SNI، فلا يتعارض. إذا ظهر تعارض listen فتأكد كأن كل ملف
|
||
# يُخصَّص server_name واحد فقط.
|
||
# ══════════════════════════════════════════════════════════════════
|
||
|
||
# لا نضع http2 إطلاقاً هنا: ترقية WebSocket تعتمد على ترقدية
|
||
# Upgrade في HTTP/1.1 ولا معنى لها في HTTP/2، وقد يرفضها nginx قديم.
|
||
map $http_upgrade $tripz_connection_upgrade {
|
||
default upgrade;
|
||
'' close;
|
||
}
|
||
|
||
# ── سوكيت السائقين — GPS ─────────────────────────────────────────
|
||
server {
|
||
listen 2020 ssl;
|
||
listen [::]:2020 ssl;
|
||
|
||
server_name api.tripz-egypt.com;
|
||
|
||
# عدّل المسارين إن كانت شهادتك في مكان آخر:
|
||
# grep -rh ssl_certificate /etc/nginx/sites-enabled/ | sort -u
|
||
ssl_certificate /etc/nginx/ssl-certificates/api.tripz-egypt.com.crt;
|
||
ssl_certificate_key /etc/nginx/ssl-certificates/api.tripz-egypt.com.key;
|
||
|
||
ssl_protocols TLSv1.2 TLSv1.3;
|
||
ssl_session_cache shared:TripzSock:10m;
|
||
ssl_session_timeout 1d;
|
||
|
||
# لا سجلّ وصول: نبضات GPS تصل كل ثوانٍ وتُغرق القرص
|
||
access_log off;
|
||
error_log /var/log/nginx/tripz-socket-driver-error.log warn;
|
||
|
||
location / {
|
||
proxy_pass http://127.0.0.1:12022;
|
||
|
||
proxy_http_version 1.1;
|
||
proxy_set_header Upgrade $http_upgrade;
|
||
proxy_set_header Connection $tripz_connection_upgrade;
|
||
|
||
proxy_set_header Host $host;
|
||
proxy_set_header X-Real-IP $remote_addr;
|
||
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
||
proxy_set_header X-Forwarded-Proto $scheme;
|
||
|
||
# اتصال السائق يعيش ساعات وهو أونلاين — بلا هذه المهل يقطعه nginx
|
||
# كل 60 ثانية فتدخل الحاوية في حلقة إعادة اتصال دائمة.
|
||
proxy_connect_timeout 10s;
|
||
proxy_send_timeout 3600s;
|
||
proxy_read_timeout 3600s;
|
||
|
||
# التخزين المؤقّت يُعطّل الدفع الفوري في WebSocket
|
||
proxy_buffering off;
|
||
}
|
||
}
|
||
|
||
# ── سوكيت الركاب — حالة الرحلة وموقع السائق ──────────────────────
|
||
server {
|
||
listen 3030 ssl;
|
||
listen [::]:3030 ssl;
|
||
|
||
server_name api.tripz-egypt.com;
|
||
|
||
ssl_certificate /etc/nginx/ssl-certificates/api.tripz-egypt.com.crt;
|
||
ssl_certificate_key /etc/nginx/ssl-certificates/api.tripz-egypt.com.key;
|
||
|
||
ssl_protocols TLSv1.2 TLSv1.3;
|
||
ssl_session_cache shared:TripzSock:10m;
|
||
ssl_session_timeout 1d;
|
||
|
||
access_log off;
|
||
error_log /var/log/nginx/tripz-socket-passenger-error.log warn;
|
||
|
||
location / {
|
||
# ⚠️ 13033 وليس 13032: 13032 محجوزة من نسخة intaleq على
|
||
# السيرفر نفسه وكان سوكيت الركاب في تربز متوفّقاً بها.
|
||
proxy_pass http://127.0.0.1:13033;
|
||
|
||
proxy_http_version 1.1;
|
||
proxy_set_header Upgrade $http_upgrade;
|
||
proxy_set_header Connection $tripz_connection_upgrade;
|
||
|
||
proxy_set_header Host $host;
|
||
proxy_set_header X-Real-IP $remote_addr;
|
||
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
||
proxy_set_header X-Forwarded-Proto $scheme;
|
||
|
||
proxy_connect_timeout 10s;
|
||
proxy_send_timeout 3600s;
|
||
proxy_read_timeout 3600s;
|
||
|
||
proxy_buffering off;
|
||
}
|
||
}
|
||
|
||
# ── سوكيت الطعام — طلبات التوصيل ─────────────────────────────────
|
||
# الحاوية على 14042 (بورت مخصص لتربز؛ 14040 لنسخة سيرو).
|
||
# الحاوية نفسها قد تكون سليمة بينما لا مستمع خارجياً على 4040 —
|
||
# النتيجة `Socket Connect Error: timeout` في تطبيق السائق.
|
||
server {
|
||
listen 4040 ssl;
|
||
listen [::]:4040 ssl;
|
||
|
||
server_name api.tripz-egypt.com;
|
||
|
||
ssl_certificate /etc/nginx/ssl-certificates/api.tripz-egypt.com.crt;
|
||
ssl_certificate_key /etc/nginx/ssl-certificates/api.tripz-egypt.com.key;
|
||
|
||
ssl_protocols TLSv1.2 TLSv1.3;
|
||
ssl_session_cache shared:TripzSock:10m;
|
||
ssl_session_timeout 1d;
|
||
|
||
access_log off;
|
||
error_log /var/log/nginx/tripz-socket-food-error.log warn;
|
||
|
||
location / {
|
||
# FOOD_SOCKET_PORT في docker/.env — الافتراضي 14042.
|
||
proxy_pass http://127.0.0.1:14042;
|
||
|
||
proxy_http_version 1.1;
|
||
proxy_set_header Upgrade $http_upgrade;
|
||
proxy_set_header Connection $tripz_connection_upgrade;
|
||
|
||
proxy_set_header Host $host;
|
||
proxy_set_header X-Real-IP $remote_addr;
|
||
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
||
proxy_set_header X-Forwarded-Proto $scheme;
|
||
|
||
# وضع التوصيل يبقى مفتوحاً طوال مناوبة الكابتن — نفس مهل 2020.
|
||
proxy_connect_timeout 10s;
|
||
proxy_send_timeout 3600s;
|
||
proxy_read_timeout 3600s;
|
||
|
||
proxy_buffering off;
|
||
}
|
||
} |