diff options
Diffstat (limited to 'custom/servers/lighttpd.conf')
| -rw-r--r-- | custom/servers/lighttpd.conf | 60 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
1 file changed, 38 insertions, 22 deletions
diff --git a/custom/servers/lighttpd.conf b/custom/servers/lighttpd.conf index 3111ed0..6ae87e0 100644 --- a/custom/servers/lighttpd.conf +++ b/custom/servers/lighttpd.conf @@ -1,5 +1,11 @@ # lighttpd configuration for cgit. # +# This is a complete lighttpd.conf rather than a snippet for conf-enabled, so +# nothing here is included from elsewhere and no distro base config is +# assumed. Check it and run it with +# lighttpd -tt -f /path/to/lighttpd.conf # check the syntax and modules +# lighttpd -D -f /path/to/lighttpd.conf # run it in the foreground +# # lighttpd runs the cgit.cgi binary directly through mod_cgi, so no FastCGI # bridge is needed. This is cgit's classic reference deployment, mod_cgi with # mod_alias and mod_setenv. @@ -16,29 +22,40 @@ # straight off disk and must never be routed through cgit. -# --- Modules ---------------------------------------------------------------- -# Append the three modules cgit needs so the distro's base config is kept. -# mod_alias maps URL paths onto files, mod_setenv injects CGIT_CONFIG, and -# mod_cgi runs cgit.cgi. -server.modules += ( "mod_alias", "mod_setenv", "mod_cgi" ) +# A plain assignment rather than "+=", since this config stands on its own and +# there is no distro base list to append to. mod_alias maps URL paths onto +# files, mod_setenv injects CGIT_CONFIG and the response headers, and mod_cgi +# runs cgit.cgi. Adding mod_accesslog here is what the access log below needs. +server.modules = ( + "mod_alias", + "mod_setenv", + "mod_cgi", + "mod_accesslog", +) -# --- Server basics ---------------------------------------------------------- server.port = 80 server.username = "http" # Debian and Ubuntu use www-data server.groupname = "http" server.document-root = "/usr/share/cgit" # a valid docroot must exist, the # alias rules below do the routing +server.pid-file = "/run/lighttpd.pid" server.errorlog = "/var/log/lighttpd/error.log" -# Access logging needs mod_accesslog. Load it and uncomment to enable. -#server.modules += ( "mod_accesslog" ) -#accesslog.filename = "/var/log/lighttpd/access.log" +accesslog.filename = "/var/log/lighttpd/access.log" + +# Drop the version number from the Server header and from error pages. +server.tag = "lighttpd" + +# The only request body cgit ever reads is the auth-filter login form, and it +# stops after 4096 bytes. Nothing else here accepts an upload. The value is in +# kilobytes and the default of 0 means unlimited. +server.max-request-size = 64 -# --- MIME types for the static assets --------------------------------------- # mod_alias serves the assets off disk, so lighttpd must know their content # types. Without this the stylesheet is sent as application/octet-stream and -# the browser ignores it. +# the browser ignores it. Only these five files are served off disk, so this +# short table is the whole of it and no external mime file is needed. mimetype.assign = ( ".css" => "text/css", ".js" => "text/javascript", @@ -48,20 +65,19 @@ mimetype.assign = ( ) -# --- Virtual host, git.example.org ------------------------------------------ -# A top-level conditional, so it matches on both the port 80 socket and the -# optional TLS socket at the end of this file. +# The vhost, as a top-level conditional so it matches on both the port 80 +# socket and the optional TLS socket at the end of this file. $HTTP["host"] == "git.example.org" { # Which config cgit reads. It falls back to the compiled-in /etc/cgitrc, # the same path used here, but setting it makes the location explicit. setenv.add-environment = ( "CGIT_CONFIG" => "/etc/cgitrc" ) - # --- Security headers --------------------------------------------------- - # Set here, not in cgit, so they also cover the static assets lighttpd - # serves. script-src stays self because cgit loads only its own cgit.js, - # and style-src allows inline for the diffstat bars. If you enable the - # gravatar or libravatar avatar filter, add its host to img-src. + # Security headers are set here, not in cgit, so they also cover the + # static assets lighttpd serves. script-src stays self because cgit loads + # only its own cgit.js, and style-src allows inline for the diffstat bars. + # If you enable the gravatar or libravatar avatar filter, add its host to + # img-src. setenv.add-response-header = ( "Content-Security-Policy" => "default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; object-src 'none'; base-uri 'none'; frame-ancestors 'self'", "X-Content-Type-Options" => "nosniff", @@ -109,9 +125,9 @@ $HTTP["host"] == "git.example.org" { } -# --- Optional HTTPS on 443 -------------------------------------------------- -# Uncomment this whole block to enable TLS. The host block above is socket -# independent, so it serves cgit over this socket too once the crypto is set. +# Uncomment this whole block to enable TLS on 443. The host block above is +# socket independent, so it serves cgit over this socket too once the crypto +# is set. #server.modules += ( "mod_openssl" ) # #$SERVER["socket"] == ":443" { |
