nomad

created pr with 8.1 on 2026-06-25 · by 84351313
cmds
checkout latest patchset:
ssh pr.in0rdr.ch print 8 | git am -3
checkout any patchset in a patch request:
ssh pr.in0rdr.ch print 8.[rev] | git am -3
add changes to patch request:
git format-patch main --stdout | ssh pr.in0rdr.ch pr add 8
+8 -9 hcl/default/git/templates/stagit.conf.tmpl #
......@@ -1,7 +1,7 @@
11 ErrorLog /dev/stderr
22 TransferLog /dev/stdout
33
4-LogFormat "%{X-Forwarded-For}i %h %l %u %t \"%r\" %>s %b" common
4+LogFormat "%{X-Real-Ip}i %h %l %u %t \"%r\" %>s %b" common
55
66 # HTTPS listener that forwards to Anubis
77 <IfModule mod_proxy.c>
......@@ -10,17 +10,10 @@ LogFormat "%{X-Forwarded-For}i %h %l %u %t \"%r\" %>s %b" common
1010 SSLCertificateFile "/etc/letsencrypt/live/code.in0rdr.ch/fullchain.pem"
1111 SSLCertificateKeyFile "/etc/letsencrypt/live/code.in0rdr.ch/privkey.pem"
1212
13- # Haproxy sends real ip (send-proxy)
13+ # HAProxy sends real ip (send-proxy)
1414 # https://www.haproxy.com/documentation/haproxy-configuration-manual/latest/#send-proxy
1515 # https://httpd.apache.org/docs/2.4/mod/mod_remoteip.html#remoteipproxyprotocol
1616 RemoteIPProxyProtocol On
17- # Haproxy network
18- RemoteIPInternalProxy 10.0.0.0/24
19- RemoteIPInternalProxy 10.0.0.1
20- # Podman default bridge network
21- # https://docs.podman.io/en/stable/markdown/podman-network.1.html
22- RemoteIPInternalProxy 10.88.0.0/16
23- RemoteIPInternalProxy 10.88.0.1
2417
2518 # These headers need to be set or else Anubis will
2619 # throw an "admin misconfiguration" error.
......@@ -40,6 +33,12 @@ LogFormat "%{X-Forwarded-For}i %h %l %u %t \"%r\" %>s %b" common
4033 <VirtualHost *:80>
4134 DocumentRoot /var/www/localhost/htdocs
4235
36+ # HAProxy and Podman default bridge network
37+ # https://docs.podman.io/en/stable/markdown/podman-network.1.html
38+ RemoteIPHeader X-Real-Ip
39+ RemoteIPInternalProxy 10.0.0.0/8
40+ RemoteIPTrustedProxy 127.0.0.1/32
41+
4342 <Directory /var/www/localhost/htdocs>
4443 Order allow,deny
4544 Allow from all
Back to top