summary refs log tree commit diff
path: root/etc/relayd.conf
diff options
context:
space:
mode:
Diffstat (limited to 'etc/relayd.conf')
-rw-r--r--etc/relayd.conf8
1 files changed, 6 insertions, 2 deletions
diff --git a/etc/relayd.conf b/etc/relayd.conf
index a40fe4f..46342c1 100644
--- a/etc/relayd.conf
+++ b/etc/relayd.conf
@@ -1,6 +1,7 @@
 ip4="193.26.157.243"
 table <www> { 127.0.0.1 }
 table <wwwtext> { REPLACEME }
+table <wwwgit> { REPLACEME }
 
 log connection
 
@@ -11,13 +12,15 @@ http protocol https {
     match request header set "Connection" value "close"
     tcp { sack, backlog 128 }
     tls { keypair iwakura.page }
-    tls { keypair text.iwakura.page } 
+    tls { keypair text.iwakura.page }
+    tls { keypair git.iwakura.page }
     match request header "Host" value "iwakura.page" forward to <www>
     match request header "Host" value "www.iwakura.page" forward to <www>
     match request header "Host" value "text.iwakura.page" forward to <wwwtext>
+     match request header "Host" value "git.iwakura.page" forward to <wwwgit>
     match response header append "Strict-Transport-Security" value "max-age=31536000; includeSubDomains; preload"
     match response header append "Cache-Control" value "public, max-age=86400"
-    match response header append "Content-Security-Policy" value "default-src 'self'; script-src 'self'; object-src 'none';"
+    match response header append "Content-Security-Policy" value "default-src 'self'; script-src 'self' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; object-src 'none';"
     match response header append "X-Content-Type-Options" value "nosniff"
     match response header append "X-Frame-Options" value "SAMEORIGIN"
     match response header append "Referrer-Policy" value "no-referrer"
@@ -30,4 +33,5 @@ relay wwwtls {
     protocol https
     forward to <www> port 8080 check tcp
     forward to <wwwtext> port 8834 check tcp
+    forward to <wwwgit> port 8855 check tcp
 }