# Host nginx example. The auth service MUST authenticate every request and return a stable # identity in X-Authenticated-User. ThothII itself remains on 127.0.0.1:8080. server { listen 443 ssl; server_name thoth.example.test; ssl_certificate /etc/nginx/tls/fullchain.pem; ssl_certificate_key /etc/nginx/tls/privkey.pem; location = /_authenticate { internal; proxy_pass http://authentication-gateway/verify; proxy_pass_request_body off; proxy_set_header Content-Length ""; proxy_set_header X-Original-URI $request_uri; } location / { auth_request /_authenticate; auth_request_set $authenticated_user $upstream_http_x_authenticated_user; proxy_set_header X-Authenticated-User $authenticated_user; proxy_set_header X-Forwarded-Proto https; proxy_set_header Host $host; proxy_pass http://127.0.0.1:8080; } }