# Android Cast FE — staging cluster (cast01–03). No artc0 upstream. # Target install on Gentoo FE (monstro): /etc/nginx/ac-fe.conf # Enable in /etc/nginx/nginx.conf (http {}): # include /etc/nginx/ac-fe-upstream.conf; # include /etc/nginx/apps.conf; # include /etc/nginx/ac-fe.conf; # # Reload: nginx -t && rc-service nginx reload # upstream ac_be_backend — see ac-fe-upstream.conf (shared with apps.f0xx.org) # --- Lab public names (DNS → monstro FE → cluster BE) --- # cluster.env: acl0.f0xx.org, c1–c3.acl0.f0xx.org server { listen 80; server_name acl0.f0xx.org c1.acl0.f0xx.org c2.acl0.f0xx.org c3.acl0.f0xx.org; return 301 https://$host$request_uri; } server { listen 443 ssl http2; server_name acl0.f0xx.org c1.acl0.f0xx.org c2.acl0.f0xx.org c3.acl0.f0xx.org; access_log /var/log/nginx/acl0.f0xx.org.access_log main; error_log /var/log/nginx/acl0.f0xx.org.error_log info; # Issue cert first: certbot certonly --nginx -d acl0.f0xx.org -d c1.acl0.f0xx.org ... ssl_certificate /etc/letsencrypt/live/acl0.f0xx.org/fullchain.pem; ssl_certificate_key /etc/letsencrypt/live/acl0.f0xx.org/privkey.pem; location ^~ /v0/ota/ { proxy_pass http://ac_be_backend; proxy_http_version 1.1; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; } location = /app/androidcast_project/build { return 301 $scheme://$host/app/androidcast_project/build/; } location ^~ /app/androidcast_project/build/ { proxy_pass http://ac_be_backend; proxy_http_version 1.1; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; proxy_set_header X-Forwarded-Host $host; proxy_set_header Upgrade $http_upgrade; proxy_set_header Connection $connection_upgrade; proxy_read_timeout 1800s; proxy_send_timeout 1800s; client_max_body_size 512m; } include /etc/nginx/ac-fe.fragment; location = /app/androidcast_project/graphs { return 301 $scheme://$host/app/androidcast_project/graphs/; } location ^~ /app/androidcast_project/graphs/ { proxy_pass http://ac_be_backend; proxy_http_version 1.1; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; } location = /app/androidcast_project { return 301 $scheme://$host/app/androidcast_project/; } location ^~ /app/androidcast_project/ { proxy_pass http://ac_be_backend; proxy_http_version 1.1; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; } location = /app/androidcast_project/git { return 301 $scheme://$host/app/androidcast_project/git/; } location ^~ /app/androidcast_project/git/ { proxy_pass http://ac_be_backend; proxy_http_version 1.1; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; proxy_set_header X-Forwarded-Host $host; proxy_set_header Upgrade $http_upgrade; proxy_set_header Connection $connection_upgrade; proxy_read_timeout 1800s; proxy_send_timeout 1800s; client_max_body_size 512m; } location / { proxy_pass http://ac_be_backend; proxy_http_version 1.1; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; } location ~ /\.ht { deny all; } }