server { | |
listen 443 ssl; | |
listen [::]:443 ssl; | |
server_name id.${SA_PUBLIC_DOMAIN_NAME}; | |
location /auth/ { # Gerrit adds this prefix for Keycloak... | |
rewrite ^/auth(.*)$ $1 last; | |
} | |
location = / { # For convenience, redirect to account console. | |
rewrite ^.*$ /realms/sourcearcade/account last; | |
} | |
location ~ ^/(?:realms|resources|js)/ { | |
proxy_pass http://keycloak:8080; | |
proxy_set_header X-Forwarded-For $remote_addr; | |
proxy_set_header Host $host; | |
} | |
location / { | |
return 403; | |
} | |
} |