27 lines
927 B
Plaintext
27 lines
927 B
Plaintext
# Host nginx example. The auth service MUST authenticate every request and return a stable
|
|
# identity in X-Authenticated-User. ThothII itself remains on 127.0.0.1:8080.
|
|
server {
|
|
listen 443 ssl;
|
|
server_name thoth.example.test;
|
|
|
|
ssl_certificate /etc/nginx/tls/fullchain.pem;
|
|
ssl_certificate_key /etc/nginx/tls/privkey.pem;
|
|
|
|
location = /_authenticate {
|
|
internal;
|
|
proxy_pass http://authentication-gateway/verify;
|
|
proxy_pass_request_body off;
|
|
proxy_set_header Content-Length "";
|
|
proxy_set_header X-Original-URI $request_uri;
|
|
}
|
|
|
|
location / {
|
|
auth_request /_authenticate;
|
|
auth_request_set $authenticated_user $upstream_http_x_authenticated_user;
|
|
proxy_set_header X-Authenticated-User $authenticated_user;
|
|
proxy_set_header X-Forwarded-Proto https;
|
|
proxy_set_header Host $host;
|
|
proxy_pass http://127.0.0.1:8080;
|
|
}
|
|
}
|