Skip to content

Commit

Permalink
Add upgrade rule (#8733)
Browse files Browse the repository at this point in the history
* Add upgrade rule

* Update ssl.conf

* Update ssl.conf
  • Loading branch information
klewis0928 authored Oct 25, 2024
1 parent 59a5183 commit 6271a1a
Showing 1 changed file with 20 additions and 10 deletions.
30 changes: 20 additions & 10 deletions ansible/configs/osp-on-ocp/templates/httpd/ssl.conf
Original file line number Diff line number Diff line change
Expand Up @@ -69,26 +69,36 @@ Header edit Location "apps.ocp.example.com/auth/callback" "apps.{{ guid }}.{{ cl
<VirtualHost *:443>

ServerAlias *.apps.{{ guid }}.{{ cluster_dns_zone }}
ErrorLog logs/ssl_apps_error_log
TransferLog logs/ssl_app_access_log
LogLevel warn
ErrorLog logs/ssl_nova_error_log
TransferLog logs/ssl_nova_access_log
LogLevel debug
SSLEngine on
SSLHonorCipherOrder on
SSLCipherSuite PROFILE=SYSTEM
SSLProxyCipherSuite PROFILE=SYSTEM
SSLCertificateFile /root/certbot/config/live/api.{{ guid }}.{{ cluster_dns_zone }}/fullchain.pem
SSLCertificateKeyFile /root/certbot/config/live/api.{{ guid }}.{{ cluster_dns_zone }}/privkey.pem
#RequestHeader set Referer "https://zzzzz.apps.ocp.example.com"
#RequestHeader set Origin "https://zzzzz.apps.ocp.example.com"

ProxyRequests off
ProxyVia on
ProxyPreserveHost On
ProxyTimeout 300

ProxyPass / https://nova-novncproxy-cell1-public-openstack.apps.ocp.example.com/
ProxyPassReverse / https://nova-novncproxy-cell1-public-openstack.apps.ocp.example.com/

SSLProxyEngine on
SSLProxyVerify none
SSLProxyCheckPeerCN off
SSLProxyCheckPeerName off
ProxyPass "/" "https://zzzzz.apps.ocp.example.com/" max=20 ttl=120 retry=300
ProxyPassReverse "/" "https://zzzzz.apps.ocp.example.com/"
RewriteEngine On
RewriteCond %{HTTP:Connection} upgrade [NC]
RewriteCond %{HTTP:Upgrade} websocket [NC]
RewriteRule /(.*) wss://nova-novncproxy-cell1-public-openstack.apps.ocp.example.com/$1 [P,L]

AddOutputFilterByType SUBSTITUTE text/javascript
Substitute "s|apps.ocp.example.com|apps.6s9zw.dynamic.redhatworkshops.io|i"

AddOutputFilterByType SUBSTITUTE text/html
#Substitute "s|apps.ocp.example.com|apps.{{ guid }}.{{ cluster_dns_zone }}|i"
Header edit Location "oauth-openshift.apps.ocp.example.com" "oauth-openshift.apps.{{ guid }}.{{ cluster_dns_zone }}"
</VirtualHost>

<VirtualHost *:443>

0 comments on commit 6271a1a

Please sign in to comment.