3 ms·
I use Nginx: - as a layer on top the app servers for not having to expose Node.js, and loadbalancing app servers, - brotli_static, - serving avif condi
by efortis 2y ago
I use Nginx:
- as a layer on top the app servers for not having to expose Node.js, and loadbalancing app servers,
- brotli_static,
- serving avif conditionally[1]
- anonymizing IPs in logs
- injecting the caching headers
- injecting the CSP header
- SSL Offloading
Autorenewing SSL certificates within the server is not appealing to me because externally running a script to renew them is not much more complex and it's more secure.
I mean, the autorenew bots need more priviledges, such as:
- HTTP challenges need to be via HTTP (not HTTPS) [2],
- HTTP challenges need write permissions on a servable directory,
- DNS or HTTP challenges would need a program on a live server,
- need ‘pass out’ firewall exceptions without IP scope. "We don’t publish a list of IP addresses we use to validate… Let’s Encrypt" [3]
1. https://blog.uxtly.com/conditional-avif-for-video-posters https://blog.uxtly.com/conditional-avif-for-video-posters
2. https://datatracker.ietf.org/doc/html/rfc8555#section-8.3 https://datatracker.ietf.org/doc/html/rfc8555#section-8.3
3. https://letsencrypt.org/docs/faq/#what-ip-addresses-does-let-s-encrypt-use-to-validate-my-web-server https://letsencrypt.org/docs/faq/#what-ip-addresses-does-let...
- martinbaun 2y agoInteresting, what do you for SSL instead?
- efortis 2y agoI use acme.sh with DNS challenges on an external machine. Then I push up (rsync) the certs and reload Nginx. Here’s a blog post https://blog.uxtly.com/isolated-tls-certificate-creation https://blog.uxtly.com/isolated-tls-certificate-creation
- martinbaun 2y agoThanks eFortis? I guess this mainly for security and separation of concerns?
- efortis 2y agoYes, the certificate renewal and the server are more hardened this way.
- martinbaun 2y agoCool! Do you do other things to hardend the servers like Knockerd?