# Temporary HTTP-only entry point used exclusively while Let's Encrypt issues # the first certificate for filyx.fr. The legacy domain keeps its existing # HTTPS configuration and remains available throughout the migration. server { server_name filyx.hom3r-off.fr; root /srv/filyx/apps/web/public; index index.php; client_max_body_size 32m; include /etc/nginx/snippets/filyx-oauth-callback.conf; include /etc/nginx/snippets/filyx-media.conf; include /etc/nginx/snippets/filyx-music-bridge.conf; location / { try_files $uri $uri/ /index.php?$query_string; } location ~ \.php$ { try_files $uri =404; include fastcgi_params; fastcgi_param SCRIPT_FILENAME $realpath_root$fastcgi_script_name; fastcgi_param DOCUMENT_ROOT $realpath_root; fastcgi_param HTTP_X_FORWARDED_PROTO $http_x_forwarded_proto; fastcgi_pass unix:/run/php/php8.2-fpm.sock; fastcgi_read_timeout 60s; } location ~ /\. { deny all; } location ~* \.(?:env|sql|log|bak)$ { deny all; } listen [::]:443 ssl ipv6only=on; listen 443 ssl; ssl_certificate /etc/letsencrypt/live/filyx.hom3r-off.fr/fullchain.pem; ssl_certificate_key /etc/letsencrypt/live/filyx.hom3r-off.fr/privkey.pem; include /etc/letsencrypt/options-ssl-nginx.conf; ssl_dhparam /etc/letsencrypt/ssl-dhparams.pem; } server { listen 80; listen [::]:80; server_name filyx.hom3r-off.fr; return 301 https://$host$request_uri; } # The challenge exception must come before the dot-file block so Certbot can # place a token under .well-known/acme-challenge without exposing anything else. server { listen 80; listen [::]:80; server_name filyx.fr www.filyx.fr; root /srv/filyx/apps/web/public; index index.php; client_max_body_size 32m; location ^~ /.well-known/acme-challenge/ { default_type text/plain; try_files $uri =404; } location / { try_files $uri $uri/ /index.php?$query_string; } location ~ \.php$ { try_files $uri =404; include fastcgi_params; fastcgi_param SCRIPT_FILENAME $realpath_root$fastcgi_script_name; fastcgi_param DOCUMENT_ROOT $realpath_root; fastcgi_pass unix:/run/php/php8.2-fpm.sock; fastcgi_read_timeout 60s; } location ~ /\. { deny all; } location ~* \.(?:env|sql|log|bak)$ { deny all; } }