Initial commit: Apache config with starshipos-f18 and strshipos domains

Virtual hosts for starshipos-f18.com/.org (XWiki, Gitea, Nexus) with
Let's Encrypt SSL. Old strshipos.* domains redirect 301 to new domains.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
Robert James
2026-10-08 14:41:21 +00:00
co-authored by Claude Sonnet 4.6
commit 46c2ae201f
87 changed files with 973 additions and 0 deletions
+3
View File
@@ -0,0 +1,3 @@
# Ignore magic files and lock files
*.pid
*.lock
+225
View File
@@ -0,0 +1,225 @@
# This is the main Apache server configuration file. It contains the
# configuration directives that give the server its instructions.
# See http://httpd.apache.org/docs/2.4/ for detailed information about
# the directives and /usr/share/doc/apache2/README.Debian about Debian specific
# hints.
#
#
# Summary of how the Apache 2 configuration works in Debian:
# The Apache 2 web server configuration in Debian is quite different to
# upstream's suggested way to configure the web server. This is because Debian's
# default Apache2 installation attempts to make adding and removing modules,
# virtual hosts, and extra configuration directives as flexible as possible, in
# order to make automating the changes and administering the server as easy as
# possible.
# It is split into several files forming the configuration hierarchy outlined
# below, all located in the /etc/apache2/ directory:
#
# /etc/apache2/
# |-- apache2.conf
# | `-- ports.conf
# |-- mods-enabled
# | |-- *.load
# | `-- *.conf
# |-- conf-enabled
# | `-- *.conf
# `-- sites-enabled
# `-- *.conf
#
#
# * apache2.conf is the main configuration file (this file). It puts the pieces
# together by including all remaining configuration files when starting up the
# web server.
#
# * ports.conf is always included from the main configuration file. It is
# supposed to determine listening ports for incoming connections which can be
# customized anytime.
#
# * Configuration files in the mods-enabled/, conf-enabled/ and sites-enabled/
# directories contain particular configuration snippets which manage modules,
# global configuration fragments, or virtual host configurations,
# respectively.
#
# They are activated by symlinking available configuration files from their
# respective *-available/ counterparts. These should be managed by using our
# helpers a2enmod/a2dismod, a2ensite/a2dissite and a2enconf/a2disconf. See
# their respective man pages for detailed information.
#
# * The binary is called apache2. Due to the use of environment variables, in
# the default configuration, apache2 needs to be started/stopped with
# /etc/init.d/apache2 or apache2ctl. Calling /usr/bin/apache2 directly will not
# work with the default configuration.
# Global configuration
#
#
# ServerRoot: The top of the directory tree under which the server's
# configuration, error, and log files are kept.
#
# NOTE! If you intend to place this on an NFS (or otherwise network)
# mounted filesystem then please read the Mutex documentation (available
# at <URL:http://httpd.apache.org/docs/2.4/mod/core.html#mutex>);
# you will save yourself a lot of trouble.
#
# Do NOT add a slash at the end of the directory path.
#
#ServerRoot "/etc/apache2"
#
# The accept serialization lock file MUST BE STORED ON A LOCAL DISK.
#
#Mutex file:${APACHE_LOCK_DIR} default
#
# The directory where shm and other runtime files will be stored.
#
DefaultRuntimeDir ${APACHE_RUN_DIR}
#
# PidFile: The file in which the server should record its process
# identification number when it starts.
# This needs to be set in /etc/apache2/envvars
#
PidFile ${APACHE_PID_FILE}
#
# Timeout: The number of seconds before receives and sends time out.
#
Timeout 300
#
# KeepAlive: Whether or not to allow persistent connections (more than
# one request per connection). Set to "Off" to deactivate.
#
KeepAlive On
#
# MaxKeepAliveRequests: The maximum number of requests to allow
# during a persistent connection. Set to 0 to allow an unlimited amount.
# We recommend you leave this number high, for maximum performance.
#
MaxKeepAliveRequests 100
#
# KeepAliveTimeout: Number of seconds to wait for the next request from the
# same client on the same connection.
#
KeepAliveTimeout 5
# These need to be set in /etc/apache2/envvars
User ${APACHE_RUN_USER}
Group ${APACHE_RUN_GROUP}
#
# HostnameLookups: Log the names of clients or just their IP addresses
# e.g., www.apache.org (on) or 204.62.129.132 (off).
# The default is off because it'd be overall better for the net if people
# had to knowingly turn this feature on, since enabling it means that
# each client request will result in AT LEAST one lookup request to the
# nameserver.
#
HostnameLookups Off
# ErrorLog: The location of the error log file.
# If you do not specify an ErrorLog directive within a <VirtualHost>
# container, error messages relating to that virtual host will be
# logged here. If you *do* define an error logfile for a <VirtualHost>
# container, that host's errors will be logged there and not here.
#
ErrorLog ${APACHE_LOG_DIR}/error.log
#
# LogLevel: Control the severity of messages logged to the error_log.
# Available values: trace8, ..., trace1, debug, info, notice, warn,
# error, crit, alert, emerg.
# It is also possible to configure the log level for particular modules, e.g.
# "LogLevel info ssl:warn"
#
LogLevel warn
# Include module configuration:
IncludeOptional mods-enabled/*.load
IncludeOptional mods-enabled/*.conf
# Include list of ports to listen on
Include ports.conf
# Sets the default security model of the Apache2 HTTPD server. It does
# not allow access to the root filesystem outside of /usr/share and /var/www.
# The former is used by web applications packaged in Debian,
# the latter may be used for local directories served by the web server. If
# your system is serving content from a sub-directory in /srv you must allow
# access here, or in any related virtual host.
<Directory />
Options FollowSymLinks
AllowOverride None
Require all denied
</Directory>
<Directory /usr/share>
AllowOverride None
Require all granted
</Directory>
<Directory /var/www/>
Options Indexes FollowSymLinks
AllowOverride None
Require all granted
</Directory>
#<Directory /srv/>
# Options Indexes FollowSymLinks
# AllowOverride None
# Require all granted
#</Directory>
# AccessFileName: The name of the file to look for in each directory
# for additional configuration directives. See also the AllowOverride
# directive.
#
AccessFileName .htaccess
#
# The following lines prevent .htaccess and .htpasswd files from being
# viewed by Web clients.
#
<FilesMatch "^\.ht">
Require all denied
</FilesMatch>
#
# The following directives define some format nicknames for use with
# a CustomLog directive.
#
# These deviate from the Common Log Format definitions in that they use %O
# (the actual bytes sent including headers) instead of %b (the size of the
# requested file), because the latter makes it impossible to detect partial
# requests.
#
# Note that the use of %{X-Forwarded-For}i instead of %h is not recommended.
# Use mod_remoteip instead.
#
LogFormat "%v:%p %h %l %u %t \"%r\" %>s %O \"%{Referer}i\" \"%{User-Agent}i\"" vhost_combined
LogFormat "%h %l %u %t \"%r\" %>s %O \"%{Referer}i\" \"%{User-Agent}i\"" combined
LogFormat "%h %l %u %t \"%r\" %>s %O" common
LogFormat "%{Referer}i -> %U" referer
LogFormat "%{User-agent}i" agent
# Include of directories ignores editors' and dpkg's backup files,
# see README.Debian for details.
# Include generic snippets of statements
IncludeOptional conf-enabled/*.conf
# Include the virtual host configurations:
IncludeOptional sites-enabled/*.conf
+6
View File
@@ -0,0 +1,6 @@
# Read the documentation before enabling AddDefaultCharset.
# In general, it is only a good idea if you know that all your files
# have this encoding. It will override any encoding given in the files
# in meta http-equiv or xml encoding tags.
#AddDefaultCharset UTF-8
+79
View File
@@ -0,0 +1,79 @@
# Customizable error responses come in three flavors:
# 1) plain text
# 2) local redirects
# 3) external redirects
#
# Some examples:
#ErrorDocument 500 "The server made a boo boo."
#ErrorDocument 404 /missing.html
#ErrorDocument 404 "/cgi-bin/missing_handler.pl"
#ErrorDocument 402 http://www.example.com/subscription_info.html
#
#
# Putting this all together, we can internationalize error responses.
#
# We use Alias to redirect any /error/HTTP_<error>.html.var response to
# our collection of by-error message multi-language collections. We use
# includes to substitute the appropriate text.
#
# You can modify the messages' appearance without changing any of the
# default HTTP_<error>.html.var files by adding the line:
#
#Alias /error/include/ "/your/include/path/"
#
# which allows you to create your own set of files by starting with the
# /usr/share/apache2/error/include/ files and copying them to /your/include/path/,
# even on a per-VirtualHost basis. If you include the Alias in the global server
# context, is has to come _before_ the 'Alias /error/ ...' line.
#
# The default include files will display your Apache version number and your
# ServerAdmin email address regardless of the setting of ServerSignature.
#
# WARNING: The configuration below will NOT work out of the box if you have a
# SetHandler directive in a <Location /> context somewhere. Adding
# the following three lines AFTER the <Location /> context should
# make it work in most cases:
# <Location /error/>
# SetHandler none
# </Location>
#
# The internationalized error documents require mod_alias, mod_include
# and mod_negotiation. To activate them, uncomment the following 37 lines.
#<IfModule mod_negotiation.c>
# <IfModule mod_include.c>
# <IfModule mod_alias.c>
#
# Alias /error/ "/usr/share/apache2/error/"
#
# <Directory "/usr/share/apache2/error">
# Options IncludesNoExec
# AddOutputFilter Includes html
# AddHandler type-map var
# Order allow,deny
# Allow from all
# LanguagePriority en cs de es fr it nl sv pt-br ro
# ForceLanguagePriority Prefer Fallback
# </Directory>
#
# ErrorDocument 400 /error/HTTP_BAD_REQUEST.html.var
# ErrorDocument 401 /error/HTTP_UNAUTHORIZED.html.var
# ErrorDocument 403 /error/HTTP_FORBIDDEN.html.var
# ErrorDocument 404 /error/HTTP_NOT_FOUND.html.var
# ErrorDocument 405 /error/HTTP_METHOD_NOT_ALLOWED.html.var
# ErrorDocument 408 /error/HTTP_REQUEST_TIME_OUT.html.var
# ErrorDocument 410 /error/HTTP_GONE.html.var
# ErrorDocument 411 /error/HTTP_LENGTH_REQUIRED.html.var
# ErrorDocument 412 /error/HTTP_PRECONDITION_FAILED.html.var
# ErrorDocument 413 /error/HTTP_REQUEST_ENTITY_TOO_LARGE.html.var
# ErrorDocument 414 /error/HTTP_REQUEST_URI_TOO_LARGE.html.var
# ErrorDocument 415 /error/HTTP_UNSUPPORTED_MEDIA_TYPE.html.var
# ErrorDocument 500 /error/HTTP_INTERNAL_SERVER_ERROR.html.var
# ErrorDocument 501 /error/HTTP_NOT_IMPLEMENTED.html.var
# ErrorDocument 502 /error/HTTP_BAD_GATEWAY.html.var
# ErrorDocument 503 /error/HTTP_SERVICE_UNAVAILABLE.html.var
# ErrorDocument 506 /error/HTTP_VARIANT_ALSO_VARIES.html.var
# </IfModule>
# </IfModule>
#</IfModule>
@@ -0,0 +1,2 @@
# Define an access log for VirtualHosts that don't define their own logfile
CustomLog ${APACHE_LOG_DIR}/other_vhosts_access.log vhost_combined
+58
View File
@@ -0,0 +1,58 @@
# Changing the following options will not really affect the security of the
# server, but might make attacks slightly more difficult in some cases.
#
# ServerTokens
# This directive configures what you return as the Server HTTP response
# Header. The default is 'Full' which sends information about the OS-Type
# and compiled in modules.
# Set to one of: Full | OS | Minimal | Minor | Major | Prod
# where Full conveys the most information, and Prod the least.
#ServerTokens Minimal
ServerTokens OS
#ServerTokens Full
#
# Optionally add a line containing the server version and virtual host
# name to server-generated pages (internal error documents, FTP directory
# listings, mod_status and mod_info output etc., but not CGI generated
# documents or custom error documents).
# Set to "EMail" to also include a mailto: link to the ServerAdmin.
# Set to one of: On | Off | EMail
#ServerSignature Off
ServerSignature On
#
# Allow TRACE method
#
# Set to "extended" to also reflect the request body (only for testing and
# diagnostic purposes).
#
# Set to one of: On | Off | extended
TraceEnable Off
#TraceEnable On
#
# Forbid access to version control directories
#
# If you use version control systems in your document root, you should
# probably deny access to their directories.
#
# Examples:
#
#RedirectMatch 404 /\.git
#RedirectMatch 404 /\.svn
#
# Setting this header will prevent MSIE from interpreting files as something
# else than declared by the content type in the HTTP headers.
# Requires mod_headers to be enabled.
#
#Header set X-Content-Type-Options: "nosniff"
#
# Setting this header will prevent other sites from embedding pages from this
# site as frames. This defends against clickjacking attacks.
# Requires mod_headers to be enabled.
#
#Header set Content-Security-Policy "frame-ancestors 'self';"
+18
View File
@@ -0,0 +1,18 @@
<IfModule mod_alias.c>
<IfModule mod_cgi.c>
Define ENABLE_USR_LIB_CGI_BIN
</IfModule>
<IfModule mod_cgid.c>
Define ENABLE_USR_LIB_CGI_BIN
</IfModule>
<IfDefine ENABLE_USR_LIB_CGI_BIN>
ScriptAlias /cgi-bin/ /usr/lib/cgi-bin/
<Directory "/usr/lib/cgi-bin">
AllowOverride None
Options +ExecCGI -MultiViews +SymLinksIfOwnerMatch
Require all granted
</Directory>
</IfDefine>
</IfModule>
+1
View File
@@ -0,0 +1 @@
../conf-available/charset.conf
+1
View File
@@ -0,0 +1 @@
../conf-available/localized-error-pages.conf
+1
View File
@@ -0,0 +1 @@
../conf-available/other-vhosts-access-log.conf
+1
View File
@@ -0,0 +1 @@
../conf-available/security.conf
+1
View File
@@ -0,0 +1 @@
../conf-available/serve-cgi-bin.conf
+47
View File
@@ -0,0 +1,47 @@
# envvars - default environment variables for apache2ctl
# this won't be correct after changing uid
unset HOME
# for supporting multiple apache2 instances
if [ "${APACHE_CONFDIR##/etc/apache2-}" != "${APACHE_CONFDIR}" ] ; then
SUFFIX="-${APACHE_CONFDIR##/etc/apache2-}"
else
SUFFIX=
fi
# Since there is no sane way to get the parsed apache2 config in scripts, some
# settings are defined via environment variables and then used in apache2ctl,
# /etc/init.d/apache2, /etc/logrotate.d/apache2, etc.
export APACHE_RUN_USER=www-data
export APACHE_RUN_GROUP=www-data
# temporary state file location. This might be changed to /run in Wheezy+1
export APACHE_PID_FILE=/var/run/apache2$SUFFIX/apache2.pid
export APACHE_RUN_DIR=/var/run/apache2$SUFFIX
export APACHE_LOCK_DIR=/var/lock/apache2$SUFFIX
# Only /var/log/apache2 is handled by /etc/logrotate.d/apache2.
export APACHE_LOG_DIR=/var/log/apache2$SUFFIX
## The locale used by some modules like mod_dav
export LANG=C
## Uncomment the following line to use the system default locale instead:
#. /etc/default/locale
export LANG
## The command to get the status for 'apache2ctl status'.
## Some packages providing 'www-browser' need '--dump' instead of '-dump'.
#export APACHE_LYNX='www-browser -dump'
## If you need a higher file descriptor limit, uncomment and adjust the
## following line (default is 8192):
#APACHE_ULIMIT_MAX_FILES='ulimit -n 65536'
## If you would like to pass arguments to the web server, add them below
## to the APACHE_ARGUMENTS environment.
#export APACHE_ARGUMENTS=''
## Enable the debug mode for maintainer scripts.
## This will produce a verbose output on package installations of web server modules and web application
## installations which interact with Apache
#export APACHE2_MAINTSCRIPT_DEBUG=1
+1
View File
@@ -0,0 +1 @@
../mods-available/access_compat.load
+1
View File
@@ -0,0 +1 @@
../mods-available/alias.conf
+1
View File
@@ -0,0 +1 @@
../mods-available/alias.load
+1
View File
@@ -0,0 +1 @@
../mods-available/auth_basic.load
+1
View File
@@ -0,0 +1 @@
../mods-available/authn_core.load
+1
View File
@@ -0,0 +1 @@
../mods-available/authn_file.load
+1
View File
@@ -0,0 +1 @@
../mods-available/authz_core.load
+1
View File
@@ -0,0 +1 @@
../mods-available/authz_host.load
+1
View File
@@ -0,0 +1 @@
../mods-available/authz_user.load
+1
View File
@@ -0,0 +1 @@
../mods-available/autoindex.conf
+1
View File
@@ -0,0 +1 @@
../mods-available/autoindex.load
+1
View File
@@ -0,0 +1 @@
../mods-available/deflate.conf
+1
View File
@@ -0,0 +1 @@
../mods-available/deflate.load
+1
View File
@@ -0,0 +1 @@
../mods-available/dir.conf
+1
View File
@@ -0,0 +1 @@
../mods-available/dir.load
+1
View File
@@ -0,0 +1 @@
../mods-available/env.load
+1
View File
@@ -0,0 +1 @@
../mods-available/filter.load
+1
View File
@@ -0,0 +1 @@
../mods-available/headers.load
+1
View File
@@ -0,0 +1 @@
../mods-available/mime.conf
+1
View File
@@ -0,0 +1 @@
../mods-available/mime.load
+1
View File
@@ -0,0 +1 @@
../mods-available/mpm_event.conf
+1
View File
@@ -0,0 +1 @@
../mods-available/mpm_event.load
+1
View File
@@ -0,0 +1 @@
../mods-available/negotiation.conf
+1
View File
@@ -0,0 +1 @@
../mods-available/negotiation.load
+1
View File
@@ -0,0 +1 @@
../mods-available/proxy.conf
+1
View File
@@ -0,0 +1 @@
../mods-available/proxy.load
+1
View File
@@ -0,0 +1 @@
../mods-available/proxy_http.load
+1
View File
@@ -0,0 +1 @@
../mods-available/proxy_wstunnel.load
+1
View File
@@ -0,0 +1 @@
../mods-available/reqtimeout.conf
+1
View File
@@ -0,0 +1 @@
../mods-available/reqtimeout.load
+1
View File
@@ -0,0 +1 @@
../mods-available/rewrite.load
+1
View File
@@ -0,0 +1 @@
../mods-available/setenvif.conf
+1
View File
@@ -0,0 +1 @@
../mods-available/setenvif.load
+1
View File
@@ -0,0 +1 @@
../mods-available/socache_shmcb.load
+1
View File
@@ -0,0 +1 @@
../mods-available/ssl.conf
+1
View File
@@ -0,0 +1 @@
../mods-available/ssl.load
+1
View File
@@ -0,0 +1 @@
../mods-available/status.conf
+1
View File
@@ -0,0 +1 @@
../mods-available/status.load
+13
View File
@@ -0,0 +1,13 @@
# If you just change the port or add more ports here, you will likely also
# have to change the VirtualHost statement in
# /etc/apache2/sites-enabled/000-default.conf
Listen 80
<IfModule ssl_module>
Listen 443
</IfModule>
<IfModule mod_gnutls.c>
Listen 443
</IfModule>
+29
View File
@@ -0,0 +1,29 @@
<VirtualHost *:80>
# The ServerName directive sets the request scheme, hostname and port that
# the server uses to identify itself. This is used when creating
# redirection URLs. In the context of virtual hosts, the ServerName
# specifies what hostname must appear in the request's Host: header to
# match this virtual host. For the default virtual host (this file) this
# value is not decisive as it is used as a last resort host regardless.
# However, you must set it for any further virtual host explicitly.
#ServerName www.example.com
ServerAdmin webmaster@localhost
DocumentRoot /var/www/html
# Available loglevels: trace8, ..., trace1, debug, info, notice, warn,
# error, crit, alert, emerg.
# It is also possible to configure the loglevel for particular
# modules, e.g.
#LogLevel info ssl:warn
ErrorLog ${APACHE_LOG_DIR}/error.log
CustomLog ${APACHE_LOG_DIR}/access.log combined
# For most configuration files from conf-available/, which are
# enabled or disabled at a global level, it is possible to
# include a line for only one particular virtual host. For example the
# following line enables the CGI configuration for this host only
# after it has been globally disabled with "a2disconf".
#Include conf-available/serve-cgi-bin.conf
</VirtualHost>
+101
View File
@@ -0,0 +1,101 @@
<VirtualHost *:443>
ServerAdmin webmaster@localhost
DocumentRoot /var/www/html
# Available loglevels: trace8, ..., trace1, debug, info, notice, warn,
# error, crit, alert, emerg.
# It is also possible to configure the loglevel for particular
# modules, e.g.
#LogLevel info ssl:warn
ErrorLog ${APACHE_LOG_DIR}/error.log
CustomLog ${APACHE_LOG_DIR}/access.log combined
# For most configuration files from conf-available/, which are
# enabled or disabled at a global level, it is possible to
# include a line for only one particular virtual host. For example the
# following line enables the CGI configuration for this host only
# after it has been globally disabled with "a2disconf".
#Include conf-available/serve-cgi-bin.conf
# SSL Engine Switch:
# Enable/Disable SSL for this virtual host.
SSLEngine on
# A self-signed (snakeoil) certificate can be created by installing
# the ssl-cert package. See
# /usr/share/doc/apache2/README.Debian.gz for more info.
# If both key and certificate are stored in the same file, only the
# SSLCertificateFile directive is needed.
SSLCertificateFile /etc/ssl/certs/ssl-cert-snakeoil.pem
SSLCertificateKeyFile /etc/ssl/private/ssl-cert-snakeoil.key
# Server Certificate Chain:
# Point SSLCertificateChainFile at a file containing the
# concatenation of PEM encoded CA certificates which form the
# certificate chain for the server certificate. Alternatively
# the referenced file can be the same as SSLCertificateFile
# when the CA certificates are directly appended to the server
# certificate for convinience.
#SSLCertificateChainFile /etc/apache2/ssl.crt/server-ca.crt
# Certificate Authority (CA):
# Set the CA certificate verification path where to find CA
# certificates for client authentication or alternatively one
# huge file containing all of them (file must be PEM encoded)
# Note: Inside SSLCACertificatePath you need hash symlinks
# to point to the certificate files. Use the provided
# Makefile to update the hash symlinks after changes.
#SSLCACertificatePath /etc/ssl/certs/
#SSLCACertificateFile /etc/apache2/ssl.crt/ca-bundle.crt
# Certificate Revocation Lists (CRL):
# Set the CA revocation path where to find CA CRLs for client
# authentication or alternatively one huge file containing all
# of them (file must be PEM encoded)
# Note: Inside SSLCARevocationPath you need hash symlinks
# to point to the certificate files. Use the provided
# Makefile to update the hash symlinks after changes.
#SSLCARevocationPath /etc/apache2/ssl.crl/
#SSLCARevocationFile /etc/apache2/ssl.crl/ca-bundle.crl
# Client Authentication (Type):
# Client certificate verification type and depth. Types are
# none, optional, require and optional_no_ca. Depth is a
# number which specifies how deeply to verify the certificate
# issuer chain before deciding the certificate is not valid.
#SSLVerifyClient require
#SSLVerifyDepth 10
# SSL Engine Options:
# Set various options for the SSL engine.
# o FakeBasicAuth:
# Translate the client X.509 into a Basic Authorisation. This means that
# the standard Auth/DBMAuth methods can be used for access control. The
# user name is the `one line' version of the client's X.509 certificate.
# Note that no password is obtained from the user. Every entry in the user
# file needs this password: `xxj31ZMTZzkVA'.
# o ExportCertData:
# This exports two additional environment variables: SSL_CLIENT_CERT and
# SSL_SERVER_CERT. These contain the PEM-encoded certificates of the
# server (always existing) and the client (only existing when client
# authentication is used). This can be used to import the certificates
# into CGI scripts.
# o StdEnvVars:
# This exports the standard SSL/TLS related `SSL_*' environment variables.
# Per default this exportation is switched off for performance reasons,
# because the extraction step is an expensive operation and is usually
# useless for serving static content. So one usually enables the
# exportation for CGI and SSI requests only.
# o OptRenegotiate:
# This enables optimized SSL connection renegotiation handling when SSL
# directives are used in per-directory context.
#SSLOptions +FakeBasicAuth +ExportCertData +StrictRequire
<FilesMatch "\.(?:cgi|shtml|phtml|php)$">
SSLOptions +StdEnvVars
</FilesMatch>
<Directory /usr/lib/cgi-bin>
SSLOptions +StdEnvVars
</Directory>
</VirtualHost>
@@ -0,0 +1,25 @@
<IfModule mod_ssl.c>
<VirtualHost *:443>
ServerName gitea.starshipos-f18.com
ServerAlias gitea.starshipos-f18.org
ProxyPreserveHost On
ProxyRequests Off
RewriteEngine On
RewriteCond %{HTTP:Upgrade} websocket [NC]
RewriteRule /(.*) ws://127.0.0.1:3000/$1 [P,L]
RewriteRule ^/(.*) http://127.0.0.1:3000/$1 [P,L]
ProxyPassReverse / http://127.0.0.1:3000/
RequestHeader set X-Forwarded-Proto "http"
ErrorLog ${APACHE_LOG_DIR}/gitea-starshipos-f18-error.log
CustomLog ${APACHE_LOG_DIR}/gitea-starshipos-f18-access.log combined
Include /etc/letsencrypt/options-ssl-apache.conf
SSLCertificateFile /etc/letsencrypt/live/starshipos-f18.com/fullchain.pem
SSLCertificateKeyFile /etc/letsencrypt/live/starshipos-f18.com/privkey.pem
</VirtualHost>
</IfModule>
+23
View File
@@ -0,0 +1,23 @@
# Gitea — gitea.starshipos-f18.com
<VirtualHost *:80>
ServerName gitea.starshipos-f18.com
ServerAlias gitea.starshipos-f18.org
ProxyPreserveHost On
ProxyRequests Off
RewriteEngine On
RewriteCond %{HTTP:Upgrade} websocket [NC]
RewriteRule /(.*) ws://127.0.0.1:3000/$1 [P,L]
RewriteRule ^/(.*) http://127.0.0.1:3000/$1 [P,L]
ProxyPassReverse / http://127.0.0.1:3000/
RequestHeader set X-Forwarded-Proto "http"
ErrorLog ${APACHE_LOG_DIR}/gitea-starshipos-f18-error.log
CustomLog ${APACHE_LOG_DIR}/gitea-starshipos-f18-access.log combined
RewriteCond %{SERVER_NAME} =gitea.starshipos-f18.com [OR]
RewriteCond %{SERVER_NAME} =gitea.starshipos-f18.org
RewriteRule ^ https://%{SERVER_NAME}%{REQUEST_URI} [END,NE,R=permanent]
</VirtualHost>
@@ -0,0 +1,18 @@
<IfModule mod_ssl.c>
<VirtualHost *:443>
ServerName gitea.strshipos.com
ServerAlias gitea.strshipos.org
RewriteEngine On
RewriteCond %{SERVER_NAME} =gitea.strshipos.org
RewriteRule ^ https://gitea.starshipos-f18.org%{REQUEST_URI} [END,NE,R=permanent]
RewriteRule ^ https://gitea.starshipos-f18.com%{REQUEST_URI} [END,NE,R=permanent]
ErrorLog ${APACHE_LOG_DIR}/gitea-error.log
CustomLog ${APACHE_LOG_DIR}/gitea-access.log combined
Include /etc/letsencrypt/options-ssl-apache.conf
SSLCertificateFile /etc/letsencrypt/live/gitea.strshipos.com/fullchain.pem
SSLCertificateKeyFile /etc/letsencrypt/live/gitea.strshipos.com/privkey.pem
</VirtualHost>
</IfModule>
+24
View File
@@ -0,0 +1,24 @@
# Gitea — canonical: gitea.strshipos.com
<VirtualHost *:80>
ServerName gitea.strshipos.com
ServerAlias gitea.strshipos.org
ProxyPreserveHost On
ProxyRequests Off
RewriteEngine On
# Websocket support (Gitea uses SSE/WS for live updates)
RewriteCond %{HTTP:Upgrade} websocket [NC]
RewriteRule /(.*) ws://127.0.0.1:3000/$1 [P,L]
RewriteRule ^/(.*) http://127.0.0.1:3000/$1 [P,L]
ProxyPassReverse / http://127.0.0.1:3000/
RequestHeader set X-Forwarded-Proto "http"
ErrorLog ${APACHE_LOG_DIR}/gitea-error.log
CustomLog ${APACHE_LOG_DIR}/gitea-access.log combined
RewriteCond %{SERVER_NAME} =gitea.strshipos.com [OR]
RewriteCond %{SERVER_NAME} =gitea.strshipos.org
RewriteRule ^ https://%{SERVER_NAME}%{REQUEST_URI} [END,NE,R=permanent]
</VirtualHost>
@@ -0,0 +1,22 @@
<IfModule mod_ssl.c>
<VirtualHost *:443>
ServerName nexus.starshipos-f18.com
ServerAlias nexus.starshipos-f18.org
ProxyPreserveHost On
ProxyRequests Off
ProxyPass / http://127.0.0.1:8081/
ProxyPassReverse / http://127.0.0.1:8081/
RequestHeader set X-Forwarded-Proto "http"
ProxyTimeout 300
ErrorLog ${APACHE_LOG_DIR}/nexus-starshipos-f18-error.log
CustomLog ${APACHE_LOG_DIR}/nexus-starshipos-f18-access.log combined
Include /etc/letsencrypt/options-ssl-apache.conf
SSLCertificateFile /etc/letsencrypt/live/starshipos-f18.com/fullchain.pem
SSLCertificateKeyFile /etc/letsencrypt/live/starshipos-f18.com/privkey.pem
</VirtualHost>
</IfModule>
+21
View File
@@ -0,0 +1,21 @@
# Nexus — nexus.starshipos-f18.com
<VirtualHost *:80>
ServerName nexus.starshipos-f18.com
ServerAlias nexus.starshipos-f18.org
ProxyPreserveHost On
ProxyRequests Off
ProxyPass / http://127.0.0.1:8081/
ProxyPassReverse / http://127.0.0.1:8081/
RequestHeader set X-Forwarded-Proto "http"
ProxyTimeout 300
ErrorLog ${APACHE_LOG_DIR}/nexus-starshipos-f18-error.log
CustomLog ${APACHE_LOG_DIR}/nexus-starshipos-f18-access.log combined
RewriteEngine on
RewriteCond %{SERVER_NAME} =nexus.starshipos-f18.com [OR]
RewriteCond %{SERVER_NAME} =nexus.starshipos-f18.org
RewriteRule ^ https://%{SERVER_NAME}%{REQUEST_URI} [END,NE,R=permanent]
</VirtualHost>
@@ -0,0 +1,18 @@
<IfModule mod_ssl.c>
<VirtualHost *:443>
ServerName nexus.strshipos.com
ServerAlias nexus.strshipos.org
RewriteEngine On
RewriteCond %{SERVER_NAME} =nexus.strshipos.org
RewriteRule ^ https://nexus.starshipos-f18.org%{REQUEST_URI} [END,NE,R=permanent]
RewriteRule ^ https://nexus.starshipos-f18.com%{REQUEST_URI} [END,NE,R=permanent]
ErrorLog ${APACHE_LOG_DIR}/nexus-error.log
CustomLog ${APACHE_LOG_DIR}/nexus-access.log combined
Include /etc/letsencrypt/options-ssl-apache.conf
SSLCertificateFile /etc/letsencrypt/live/nexus.strshipos.com/fullchain.pem
SSLCertificateKeyFile /etc/letsencrypt/live/nexus.strshipos.com/privkey.pem
</VirtualHost>
</IfModule>
+23
View File
@@ -0,0 +1,23 @@
# Nexus — canonical: nexus.strshipos.com
<VirtualHost *:80>
ServerName nexus.strshipos.com
ServerAlias nexus.strshipos.org
ProxyPreserveHost On
ProxyRequests Off
ProxyPass / http://127.0.0.1:8081/
ProxyPassReverse / http://127.0.0.1:8081/
RequestHeader set X-Forwarded-Proto "http"
# Nexus needs large client body for artifact uploads
ProxyTimeout 300
ErrorLog ${APACHE_LOG_DIR}/nexus-error.log
CustomLog ${APACHE_LOG_DIR}/nexus-access.log combined
RewriteEngine on
RewriteCond %{SERVER_NAME} =nexus.strshipos.org [OR]
RewriteCond %{SERVER_NAME} =nexus.strshipos.com
RewriteRule ^ https://%{SERVER_NAME}%{REQUEST_URI} [END,NE,R=permanent]
</VirtualHost>
@@ -0,0 +1,22 @@
<IfModule mod_ssl.c>
<VirtualHost *:443>
ServerName starshipos-f18.com
ServerAlias www.starshipos-f18.com
ProxyPreserveHost On
ProxyRequests Off
ProxyPass / http://127.0.0.1:8091/
ProxyPassReverse / http://127.0.0.1:8091/
RequestHeader set X-Forwarded-Proto "http"
ProxyTimeout 300
ErrorLog ${APACHE_LOG_DIR}/starshipos-f18-com-error.log
CustomLog ${APACHE_LOG_DIR}/starshipos-f18-com-access.log combined
Include /etc/letsencrypt/options-ssl-apache.conf
SSLCertificateFile /etc/letsencrypt/live/starshipos-f18.com/fullchain.pem
SSLCertificateKeyFile /etc/letsencrypt/live/starshipos-f18.com/privkey.pem
</VirtualHost>
</IfModule>
+21
View File
@@ -0,0 +1,21 @@
# XWiki — starshipos-f18.com
<VirtualHost *:80>
ServerName starshipos-f18.com
ServerAlias www.starshipos-f18.com
ProxyPreserveHost On
ProxyRequests Off
ProxyPass / http://127.0.0.1:8091/
ProxyPassReverse / http://127.0.0.1:8091/
RequestHeader set X-Forwarded-Proto "http"
ProxyTimeout 300
ErrorLog ${APACHE_LOG_DIR}/starshipos-f18-com-error.log
CustomLog ${APACHE_LOG_DIR}/starshipos-f18-com-access.log combined
RewriteEngine on
RewriteCond %{SERVER_NAME} =www.starshipos-f18.com [OR]
RewriteCond %{SERVER_NAME} =starshipos-f18.com
RewriteRule ^ https://%{SERVER_NAME}%{REQUEST_URI} [END,NE,R=permanent]
</VirtualHost>
@@ -0,0 +1,22 @@
<IfModule mod_ssl.c>
<VirtualHost *:443>
ServerName starshipos-f18.org
ServerAlias www.starshipos-f18.org
ProxyPreserveHost On
ProxyRequests Off
ProxyPass / http://127.0.0.1:8090/
ProxyPassReverse / http://127.0.0.1:8090/
RequestHeader set X-Forwarded-Proto "http"
ProxyTimeout 300
ErrorLog ${APACHE_LOG_DIR}/starshipos-f18-org-error.log
CustomLog ${APACHE_LOG_DIR}/starshipos-f18-org-access.log combined
Include /etc/letsencrypt/options-ssl-apache.conf
SSLCertificateFile /etc/letsencrypt/live/starshipos-f18.com/fullchain.pem
SSLCertificateKeyFile /etc/letsencrypt/live/starshipos-f18.com/privkey.pem
</VirtualHost>
</IfModule>
+21
View File
@@ -0,0 +1,21 @@
# XWiki — starshipos-f18.org
<VirtualHost *:80>
ServerName starshipos-f18.org
ServerAlias www.starshipos-f18.org
ProxyPreserveHost On
ProxyRequests Off
ProxyPass / http://127.0.0.1:8090/
ProxyPassReverse / http://127.0.0.1:8090/
RequestHeader set X-Forwarded-Proto "http"
ProxyTimeout 300
ErrorLog ${APACHE_LOG_DIR}/starshipos-f18-org-error.log
CustomLog ${APACHE_LOG_DIR}/starshipos-f18-org-access.log combined
RewriteEngine on
RewriteCond %{SERVER_NAME} =www.starshipos-f18.org [OR]
RewriteCond %{SERVER_NAME} =starshipos-f18.org
RewriteRule ^ https://%{SERVER_NAME}%{REQUEST_URI} [END,NE,R=permanent]
</VirtualHost>
+15
View File
@@ -0,0 +1,15 @@
<IfModule mod_ssl.c>
<VirtualHost *:443>
ServerName strshipos.com
ServerAlias www.strshipos.com
Redirect permanent / https://starshipos-f18.com/
ErrorLog ${APACHE_LOG_DIR}/strshipos-com-error.log
CustomLog ${APACHE_LOG_DIR}/strshipos-com-access.log combined
Include /etc/letsencrypt/options-ssl-apache.conf
SSLCertificateFile /etc/letsencrypt/live/strshipos.com/fullchain.pem
SSLCertificateKeyFile /etc/letsencrypt/live/strshipos.com/privkey.pem
</VirtualHost>
</IfModule>
+21
View File
@@ -0,0 +1,21 @@
# XWiki .com instance
<VirtualHost *:80>
ServerName strshipos.com
ServerAlias www.strshipos.com
ProxyPreserveHost On
ProxyRequests Off
ProxyPass / http://127.0.0.1:8091/
ProxyPassReverse / http://127.0.0.1:8091/
RequestHeader set X-Forwarded-Proto "http"
ProxyTimeout 300
ErrorLog ${APACHE_LOG_DIR}/strshipos-com-error.log
CustomLog ${APACHE_LOG_DIR}/strshipos-com-access.log combined
RewriteEngine on
RewriteCond %{SERVER_NAME} =strshipos.com [OR]
RewriteCond %{SERVER_NAME} =www.strshipos.com
RewriteRule ^ https://%{SERVER_NAME}%{REQUEST_URI} [END,NE,R=permanent]
</VirtualHost>
+15
View File
@@ -0,0 +1,15 @@
<IfModule mod_ssl.c>
<VirtualHost *:443>
ServerName strshipos.org
ServerAlias www.strshipos.org
Redirect permanent / https://starshipos-f18.org/
ErrorLog ${APACHE_LOG_DIR}/strshipos-org-error.log
CustomLog ${APACHE_LOG_DIR}/strshipos-org-access.log combined
Include /etc/letsencrypt/options-ssl-apache.conf
SSLCertificateFile /etc/letsencrypt/live/strshipos.org/fullchain.pem
SSLCertificateKeyFile /etc/letsencrypt/live/strshipos.org/privkey.pem
</VirtualHost>
</IfModule>
+21
View File
@@ -0,0 +1,21 @@
# XWiki .org instance
<VirtualHost *:80>
ServerName strshipos.org
ServerAlias www.strshipos.org
ProxyPreserveHost On
ProxyRequests Off
ProxyPass / http://127.0.0.1:8090/
ProxyPassReverse / http://127.0.0.1:8090/
RequestHeader set X-Forwarded-Proto "http"
ProxyTimeout 300
ErrorLog ${APACHE_LOG_DIR}/strshipos-org-error.log
CustomLog ${APACHE_LOG_DIR}/strshipos-org-access.log combined
RewriteEngine on
RewriteCond %{SERVER_NAME} =www.strshipos.org [OR]
RewriteCond %{SERVER_NAME} =strshipos.org
RewriteRule ^ https://%{SERVER_NAME}%{REQUEST_URI} [END,NE,R=permanent]
</VirtualHost>
+1
View File
@@ -0,0 +1 @@
../sites-available/000-default.conf
+1
View File
@@ -0,0 +1 @@
/etc/apache2/sites-available/gitea.starshipos-f18-le-ssl.conf
+1
View File
@@ -0,0 +1 @@
../sites-available/gitea.starshipos-f18.conf
+1
View File
@@ -0,0 +1 @@
/etc/apache2/sites-available/gitea.strshipos-le-ssl.conf
+1
View File
@@ -0,0 +1 @@
../sites-available/gitea.strshipos.conf
+1
View File
@@ -0,0 +1 @@
/etc/apache2/sites-available/nexus.starshipos-f18-le-ssl.conf
+1
View File
@@ -0,0 +1 @@
../sites-available/nexus.starshipos-f18.conf
+1
View File
@@ -0,0 +1 @@
/etc/apache2/sites-available/nexus.strshipos-le-ssl.conf
+1
View File
@@ -0,0 +1 @@
../sites-available/nexus.strshipos.conf
+1
View File
@@ -0,0 +1 @@
/etc/apache2/sites-available/starshipos-f18-com-le-ssl.conf
+1
View File
@@ -0,0 +1 @@
../sites-available/starshipos-f18-com.conf
+1
View File
@@ -0,0 +1 @@
/etc/apache2/sites-available/starshipos-f18-org-le-ssl.conf
+1
View File
@@ -0,0 +1 @@
../sites-available/starshipos-f18-org.conf
+1
View File
@@ -0,0 +1 @@
/etc/apache2/sites-available/strshipos-com-le-ssl.conf
+1
View File
@@ -0,0 +1 @@
../sites-available/strshipos-com.conf
+1
View File
@@ -0,0 +1 @@
/etc/apache2/sites-available/strshipos-org-le-ssl.conf
+1
View File
@@ -0,0 +1 @@
../sites-available/strshipos-org.conf