aboutsummaryrefslogtreecommitdiff
path: root/installation
AgeCommit message (Collapse)Author
2019-02-19add nginx rewrite rule for mediaproxyiodine
2019-02-19Remove slicing.lain
2019-01-28Update the openrc service's retry with the correct formatvaartis
2019-01-17Add comments and change default path of the Mix binary.shibayashi
2019-01-14Merge branch 'fix-nginx-caching' into 'develop'kaniini
Fix nginx caching issues See merge request pleroma/pleroma!654
2019-01-10Fix nginx caching issuesMark Felder
Nginx is currently not caching data because proxy_buffering needs to be enabled for caching to work at all, and we are receiving a Cache-Control header from Pleroma that states "max-age=0, private, must-revalidate" Even disregarding the Cache-Control header that should actually be set to "public, max-age=1209600" as defined in the reverse_proxy code, we don't want to obey this header at all as it overrides our Nginx caching rules.
2019-01-10Consistent intentationMark Felder
2019-01-10Cache partial objects for 10 minutesMark Felder
This enables caching/streaming of chunked responses
2019-01-10Streaming is enabled by defaultMark Felder
Support more filetypes for caching static media
2018-12-28Merge branch 'systemd-drop-sysadmin-privilege' into 'develop'kaniini
Security/Drops the sysadmin privilege from the daemon See merge request pleroma/pleroma!604
2018-12-28Security/Drops the sysadmin privilege from the daemonshibayashi
2018-12-16Simplify the NetBSD rc script.scarlett
2018-12-16Add an rc.d script for NetBSD.scarlett
2018-12-15Update/add OpenBSD config filesnonlinear
2018-12-14Added init file for OpenBSDnonlinear
2018-12-12proxy buffering still needs to be offMark Felder
2018-12-12Update proxy config to improve behavior and allow compatibility with Safari ↵Mark Felder
on MacOS and iOS
2018-11-30reverse_proxy: more headershref
2018-11-13Merge branch 'add-MIX_ENV-to-systemd-example' into 'develop'lambda
Add MIX_ENV=prod to systemd example file See merge request pleroma/pleroma!445
2018-11-12Add MIX_ENV=prodshibayashi
2018-11-11example configs: kill STS/CT headersWilliam Pitcock
2018-11-11example configs: remove obsolete CSP configurationWilliam Pitcock
2018-11-11nginx example config: remove CORS headers, now managed by CORSPlug.William Pitcock
2018-11-06Merge branch 'patch-2' into 'develop'kaniini
Remove Access-Control-Allow-Origin in pleroma.nginx See merge request pleroma/pleroma!424
2018-11-05Remove Access-Control-Allow-OriginHakaba Hitoyo
2018-11-04Use example.tld so a single search and replace worksshibayashi
2018-11-03Update instructionsshibayashi
2018-11-03Use the same example domain in all config examplesshibayashi
2018-11-03Use the server name as variableshibayashi
2018-10-25Add a little bit more detail in the comments.shibayashi
2018-10-25Add some security related directives to the systemd service exampleshibayashi
2018-09-28Relax form-action content security policybarrucadu
'self' only allows forms submitted to the same origin, which breaks the "remote follow" form. To allow remote following, we want to allow forms to be submitted to any host.
2018-09-03installation/pleroma-apache.conf: OCSP stapling needs to be outside of the ↵shibayashi
virtualhost directive
2018-08-30Add frame-ancestors 'none' to all configsshibayashi
2018-08-29installation/pleroma.nginx: Add 'always' to the security headers, so that ↵shibayashi
they are included regardless of the status code
2018-08-29installation/pleroma-apache.conf: Add TLS configuration and security headersshibayashi
2018-08-29installation/pleroma.vcl: Add HTTP security headersshibayashi
2018-08-29installation/caddyfile-pleroma.example: Add Content-Security-Policyshibayashi
2018-08-28installation/pleroma.nginx: Add Content-Security-PolicyHaelwenn (lanodan) Monnier
Closes: https://git.pleroma.social/pleroma/pleroma/issues/266
2018-08-26Improve example Caddyfileshibayashi
2018-08-23Add an OpenRC servicevaartis
2018-06-16Add comment about TLS curves for older servers.Artik Banana
2018-06-13* fix nginx 1.15 warning:dex
nginx: [warn] the "ssl" directive is deprecated, use the "listen ... ssl" directive instead
2018-06-11* Removed TLSv1 and TLSv1.1Artik Banana
* Added OCSP Stapling * Added SSL Cache * Changed ciphers * Specified ECDH curves
2018-06-11Security upgrades:Artik Banana
* Removed TLSv1 and TLSv1.1 * Added OCSP Stapling * Added SSL Cache * Changed ciphers * Specified ECDH curves
2018-06-03caddy config examplewitti
2018-05-28Update pleroma.nginxDominik V. Salonen
proxy_ignore_client_abort will continue to fetch from upstream even if a client aborts the connection. This is highly recommended when cache is being used. If a client leaves/refreshes the page while a user's avatar or some other media is halfway loaded, the cached copy might in some cases be broken. Leaving future requests to the same URL broken until cache expires.
2018-05-23Repair some access-control headers required for third-party webclientsNiklas Poslovski
2018-05-22Add access-control-expose-headers to Nginx default configNiklas Poslovski
2018-05-13Merge branch 'patch-2' into 'develop'lambda
Nginx config - secure defaults See merge request pleroma/pleroma!146