X-Git-Url: https://git.openstreetmap.org./chef.git/blobdiff_plain/03b558df0da59d9669162fd3926a8f860f7c0ee0..22076001213b1d8d27763c787ffc125931c7c164:/cookbooks/nominatim/templates/default/nginx.erb diff --git a/cookbooks/nominatim/templates/default/nginx.erb b/cookbooks/nominatim/templates/default/nginx.erb index dc8b54a9a..6f355dd11 100644 --- a/cookbooks/nominatim/templates/default/nginx.erb +++ b/cookbooks/nominatim/templates/default/nginx.erb @@ -1,5 +1,5 @@ upstream nominatim_service { - server unix:/run/php/nominatim.openstreetmap.org.sock; + server unix:/run/php/php-nominatim.openstreetmap.org-fpm.sock; } map $uri $nominatim_script_name { @@ -57,7 +57,12 @@ geo $whitelisted { 46.235.224.148 1; 209.132.180.180 1; 209.132.180.168 1; - 8.43.85.23 1; # gnome + 8.43.85.3 1; # gnome + 8.43.85.4 1; # gnome + 8.43.85.5 1; # gnome + 2620:52:3:1:5054:ff:fe0a:75a4 1; # gnome + 2620:52:3:1:5054:ff:fe0a:75a2 1; # gnome + 2620:52:3:1:5054:ff:fe0a:75aa 1; # gnome } map $missing_email$missing_referer$http_user_agent $blocked_user_agent { @@ -128,9 +133,9 @@ server { server { # IPv4 - listen 443 ssl deferred backlog=16384 reuseport http2 default_server; + listen 443 ssl http2 default_server; # IPv6 - listen [::]:443 ssl deferred backlog=16384 reuseport http2 default_server; + listen [::]:443 ssl http2 default_server; server_name localhost; ssl_certificate /etc/ssl/certs/<%= node[:fqdn] %>.pem; @@ -170,7 +175,7 @@ server { } location /qa-data/ { - add_header Access-Control-Allow-Origin "*"; + add_header Access-Control-Allow-Origin "*" always; } location @php {