install via docker
mkdir -p /data/kod_data
chmod -R 755 /data/kod_data
docker run -d -p 8080:80 --name kod -v /data/kod_data:/var/www/html kodcloud/kodexplorer:v4.46
nginx config
server {
listen 80;
server_name test.com;
rewrite ^(.*)$ https://$host$1 permanent;
#rewrite ^(.*)$ https://test.com$1 permanent;
}
server {
listen 443 ssl;
server_name test.com;
add_header Strict-Transport-Security "max-age=63072000; includeSubdomains; preload";
ssl_certificate ssl/test.com.pem;
ssl_certificate_key ssl/test.com.key;
ssl_session_cache shared:SSL:10m;
ssl_session_timeout 1440m;
ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
ssl_prefer_server_ciphers on;
# ssl_ciphers ALL:!kEDH!ADH:RC4+RSA:+HIGH:+MEDIUM:+LOW:+SSLv2:+EXP;
ssl_ciphers 'ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384';
#ssl_session_tickets on;
### openssl rand -out session_ticket.key 48
#ssl_session_ticket_key /web/ssl/session_ticket.key;
client_max_body_size 10000m;
location / {
proxy_set_header X-Forwarded-For $remote_addr;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_set_header Host ci.sre.ink;
proxy_pass http://127.0.0.1:8080;
proxy_redirect off;
proxy_http_version 1.1;
proxy_buffering off;
chunked_transfer_encoding off;
#proxy_set_header Host $host;
#proxy_set_header X-Real-Ip $remote_addr;
#proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
}
}