LAN/local deployment support, OS compat, Cloudflare Tunnel
- Smart TLS: skip certbot for IPs/.local/.lan, self-signed with SAN, HSTS max-age=0 for self-signed certs, split LAN vs public messages - Dynamic PHP: versionless meta-packages, runtime detection via php_ver fact - Vaultwarden: fail-fast on armv7l (32-bit ARM not supported upstream) - Module prompts: accept IPs for matrix/cloud/vault/media, hard error on email with IP, all_in_one skips certbot email for LAN - Matrix: skip matrix. prefix strip for IPs, warn about immutable server_name - OS family guards: ansible_os_family == Debian on all apt tasks - SSH key path: expanduser().resolve() on user-provided key paths - Cloudflare Tunnel: post-deploy script (setup-tunnel.sh) using CF API token — no browser auth needed, creates tunnel + credentials + DNS + systemd Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
@@ -42,7 +42,7 @@
|
||||
dest: /etc/nginx/sites-available/nextcloud
|
||||
content: |
|
||||
upstream php-handler {
|
||||
server unix:/run/php/php8.2-fpm-nextcloud.sock;
|
||||
server unix:/run/php/php{{ php_ver }}-fpm-nextcloud.sock;
|
||||
}
|
||||
|
||||
server {
|
||||
@@ -63,7 +63,11 @@
|
||||
ssl_prefer_server_ciphers on;
|
||||
|
||||
server_tokens off;
|
||||
{% if _is_selfsigned | default(false) | bool %}
|
||||
add_header Strict-Transport-Security "max-age=0" always;
|
||||
{% else %}
|
||||
add_header Strict-Transport-Security "max-age=63072000; includeSubDomains" always;
|
||||
{% endif %}
|
||||
add_header X-Content-Type-Options nosniff always;
|
||||
add_header X-Frame-Options SAMEORIGIN always;
|
||||
add_header X-Robots-Tag "noindex, nofollow" always;
|
||||
|
||||
Reference in New Issue
Block a user