diff --git a/host_vars/web01.l3d.space/vars.yml b/host_vars/web01.l3d.space/vars.yml index 136017c..b5228d1 100644 --- a/host_vars/web01.l3d.space/vars.yml +++ b/host_vars/web01.l3d.space/vars.yml @@ -29,7 +29,6 @@ users: - l3d@derpy.l3d.yt - l3d@backup-rsa.l3d.yt - l3d@business.wingcon.com - preview: - l3d@pinkie.l3d.yt - l3d@mobile.l3d.yt @@ -37,6 +36,13 @@ users: - l3d@derpy.l3d.yt - l3d@backup-rsa.l3d.yt - l3d@business.wingcon.com + see: + - l3d@pinkie.l3d.yt + - l3d@mobile.l3d.yt + - l3d@backup.l3d.yt + - l3d@derpy.l3d.yt + - l3d@backup-rsa.l3d.yt + - l3d@business.wingcon.com sshd__allowed_users: - "root" @@ -47,6 +53,7 @@ sshd__allowed_users: - "gitea" - "files" - "preview" + - 'see' sshd__allowed_groups: - "root" @@ -57,6 +64,7 @@ sshd__allowed_groups: - "gitea" - "files" - "preview" + - 'see' accounts: - 'l3d' @@ -64,6 +72,7 @@ accounts: - 'webwaffelpodcast' - "files" - "preview" + - 'see' acme_domain_unwant_list: [] @@ -129,6 +138,8 @@ nginx_sites: - name: 'waffelpate.de' - name: 'www.waffelpate.de' - name: 'xn--see-br-0xa.se' + webroot: + user: 'see' - name: 'www.xn--see-br-0xa.se' acme_notification_email: "{{ _acme_notification_email }}" diff --git a/templates/files/nginx/sites/xn--see-br-0xa.se_tls.conf b/templates/files/nginx/sites/xn--see-br-0xa.se_tls.conf index 5b67349..657a3b2 100644 --- a/templates/files/nginx/sites/xn--see-br-0xa.se_tls.conf +++ b/templates/files/nginx/sites/xn--see-br-0xa.se_tls.conf @@ -1,16 +1,19 @@ server { - listen 443 ssl http2; - listen [::]:443 ssl http2; + listen 443 ssl http2; + listen [::]:443 ssl http2; - server_name xn--see-br-0xa.se see-bör.se; + server_name xn--see-br-0xa.se see-bör.se; - include snippets/tls_parameters_{{ site.name }}.snippet.conf; - include snippets/tls_certificate_{{ site.name }}.snippet.conf; - include snippets/logging_{{ site.name }}.snippet.conf; + include snippets/tls_parameters_{{ site.name }}.snippet.conf; + include snippets/tls_certificate_{{ site.name }}.snippet.conf; + include snippets/logging_{{ site.name }}.snippet.conf; - location / { - add_header X-Served-By "CYBER Teapod 2.0"; - add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" - return 418; - } + root /srv/www/xn--see-br-0xa.se; + + location / { + add_header X-Served-By "CYBER Teapod 2.0"; + add_header Strict-Transport-Security "max-age=31536000; includeSubDomains"; + charset utf-8; + try_files $uri $uri/ =404; + } }