diff --git a/config/root/etc/nginx/cipher_server.conf b/config/root/etc/nginx/cipher_server.conf new file mode 100644 index 00000000..bdd806bd --- /dev/null +++ b/config/root/etc/nginx/cipher_server.conf @@ -0,0 +1,81 @@ +lua_shared_dict cipher_server 1m; +upstream cipher_server { + server 127.0.0.1:8011 max_fails=0; + + balancer_by_lua_block { + local balancer = require "ngx.balancer" + local upstream = ngx.shared.cipher_server + local exit_error = ngx.HTTP_INTERNAL_SERVER_ERROR + + local ok, err, empty_port, host, port + local default_host, default_port, tries = '127.0.0.1', '8011', 1 + + local user_host = os.getenv('TUBESYNC_CIPHER_IPADDR') + local link_host = os.getenv('CIPHERSERVER_PORT_8001_TCP_ADDR') + local use_https = os.getenv('TUBESYNC_CIPHER_HTTPS') + if user_host and use_https then + use_https = true + empty_port = '443' + else + use_https = false + empty_port = '80' + end + + ok, err = balancer.get_last_failure() + if ok then + host, port, tries = default_host, default_port, 0 + elseif link_host then + host = link_host + local link_port = os.getenv('CIPHERSERVER_PORT_8001_TCP_PORT') + if link_port then + port = link_port + else + port = empty_port + end + elseif user_host then + host = user_host + local user_port = os.getenv('TUBESYNC_CIPHER_PORT') + if user_port then + port = user_port + else + port = empty_port + end + ok, err = balancer.set_upstream_tls(use_https) + if not ok then + ngx.log(ngx.ERR, "failed to set upstream TLS: ", err) + end + end + if not host then + host, port, tries = default_host, default_port, 0 + end + + ok, err = balancer.set_more_tries(tries) + if not ok then + ngx.log(ngx.err, ("failed to set tries to %d: "):format(tries), err) + end + + ok, err = balancer.set_current_peer(host, port) + if ok then + upstream:set('https', use_https) + upstream:set('addr', host) + upstream:set('port', port) + else + ngx.log(ngx.err, "failed to set the current peer: ", err) + return ngx.exit(exit_error) + end + } +} + +server { + + # Ports + listen 8001; + listen [::]:8001; + + # Server domain name + server_name _; + + location / { + proxy_pass http://cipher_server; + } +}