# DO NOT EDIT - This file is being maintained by Chef
-<VirtualHost *:80>
- ServerName <%= @name %>
+<VirtualHost *:443>
+ ServerName <%= @name %>
<% @aliases.each do |alias_name| -%>
- ServerAlias <%= alias_name %>
+ ServerAlias <%= alias_name %>
<% end -%>
- ServerAdmin webmaster@openstreetmap.org
+ ServerAdmin webmaster@openstreetmap.org
+
+ SSLEngine on
+ SSLCertificateFile /etc/ssl/certs/<%= @name %>.pem
+ SSLCertificateKeyFile /etc/ssl/private/<%= @name %>.key
+
+ CustomLog /var/log/apache2/<%= @name %>-access.log combined
+ ErrorLog /var/log/apache2/<%= @name %>-error.log
+
+ DocumentRoot /srv/<%= @name %>/public
- DocumentRoot /srv/<%= @name %>/public
+ RailsEnv production
+ PassengerAppGroupName <%= @application_name %>
- CustomLog /var/log/apache2/<%= @name %>-access.log combined
- ErrorLog /var/log/apache2/<%= @name %>-error.log
+ SetEnv SECRET_KEY_BASE <%= @secret_key_base %>
- RailsEnv production
+ # Ensure robots do not index dev site
+ # https://developers.google.com/webmasters/control-crawl-index/docs/robots_meta_tag
+ Header set X-Robots-Tag "noindex, nofollow"
- SetEnv SECRET_KEY_BASE <%= @secret_key_base %>
+ # Force special MIME type for crossdomain.xml files
+ <Files crossdomain.xml>
+ ForceType text/x-cross-domain-policy
+ </Files>
</VirtualHost>
+
+<VirtualHost *:80>
+ ServerName <%= @name %>
+<% @aliases.each do |alias_name| -%>
+ ServerAlias <%= alias_name %>
+<% end -%>
+ ServerAdmin webmaster@openstreetmap.org
+
+ CustomLog /var/log/apache2/<%= @name %>-access.log combined
+ ErrorLog /var/log/apache2/<%= @name %>-error.log
+
+ RedirectPermanent /.well-known/acme-challenge/ http://acme.openstreetmap.org/.well-known/acme-challenge/
+ RedirectPermanent / https://<%= @name %>/
+
+ # Ensure robots do not index dev site
+ # https://developers.google.com/webmasters/control-crawl-index/docs/robots_meta_tag
+ Header set X-Robots-Tag "noindex, nofollow"
+</VirtualHost>
+
+<Directory /srv/<%= @name %>/public>
+ Require all granted
+</Directory>
+
+<Directory /srv/<%= @name %>/app/assets>
+ Require all granted
+</Directory>
+
+<Directory /srv/<%= @name %>/vendor/assets>
+ Require all granted
+</Directory>