]> git.openstreetmap.org Git - chef.git/blobdiff - cookbooks/web/templates/default/apache.frontend.erb
Broaden sender block
[chef.git] / cookbooks / web / templates / default / apache.frontend.erb
index 0989ea791c71cb147d51e59e9497288ba7f26c4d..ad5158d5e0d44961c0df837f29cbe89ee5830413 100644 (file)
   #
   RequestHeader set X-Request-Id %{UNIQUE_ID}e
 
+  #
+  # Remove Proxy request header to mitigate https://httpoxy.org/
+  #
+  RequestHeader unset Proxy early
+
   #
   # Block troublesome GPX data scrapping
   #
   RewriteCond %{HTTP_USER_AGENT} tilesAtHome
   RewriteRule . - [F,L]
 
+  #
+  # Block changeset scraper
+  #
+  RewriteCond %{HTTP_USER_AGENT} "OSMApp Tuner"
+  RewriteRule . - [F,L]  
+
   #
   # Block requests for the old 404 map tile
   #
   # Allow all proxy requests
   #
   <Proxy *>
-    Allow from all
+    Require all granted
   </Proxy>
 
   #
   ProxyPass /api/0.6/tracepoints balancer://backend/api/0.6/tracepoints
   ProxyPass /api/0.6/amf/read balancer://backend/api/0.6/amf/read
   ProxyPass /api/0.6/swf/trackpoints balancer://backend/api/0.6/swf/trackpoints
-  ProxyPassMatch ^(/api/0\.6/changeset/[0-9]+/(upload|download))$ balancer://backend$1
+  ProxyPassMatch ^(/api/0\.6/changeset/[0-9]+/upload)$ balancer://bytemark$1
+  ProxyPassMatch ^(/api/0\.6/changeset/[0-9]+/download)$ balancer://backend$1
   ProxyPassMatch ^(/api/0\.6/(node|way|relation)/[0-9]+)$ balancer://backend$1
   ProxyPassMatch ^(/api/0\.6/(node|way|relation)/[0-9]+/(full|history|search|ways))$ balancer://backend$1
   ProxyPass /api/0.6/nodes balancer://backend/api/0.6/nodes
   RedirectPermanent /images/cc_button.png http://www.openstreetmap.org/assets/cc_button.png
 
   #
-  # Define a load balancer for the backends
+  # Define a load balancer for the local backends
   #
   <Proxy balancer://backend>
     ProxySet lbmethod=bybusyness
+<% node[:web][:backends].each do |backend| -%>
+<% if port == 443 -%>
+    BalancerMember https://<%= backend %> disablereuse=on
+<% else -%>
+    BalancerMember http://<%= backend %>
+<% end -%>
+<% end -%>
+  </Proxy>
+
+  #
+  # Define a load balancer for the Bytemark backends
+  #
+  <Proxy balancer://bytemark>
+    ProxySet lbmethod=bybusyness
+<% ["rails4.bm", "rails5.bm"].each do |backend| -%>
 <% if port == 443 -%>
-    BalancerMember https://rails1 disablereuse=on
-    BalancerMember https://rails2 disablereuse=on
-    BalancerMember https://rails3 disablereuse=on
+    BalancerMember https://<%= backend %> disablereuse=on
 <% else -%>
-    BalancerMember http://rails1
-    BalancerMember http://rails2
-    BalancerMember http://rails3
+    BalancerMember http://<%= backend %>
+<% end -%>
 <% end -%>
   </Proxy>
 <% if port == 80 -%>