+5
-101
@@ -45,109 +45,13 @@ http {
|
||||
# --- Token auth ---
|
||||
include /etc/nginx/conf.d/auth.conf;
|
||||
|
||||
# --- HTTP server ---
|
||||
server {
|
||||
listen 8080;
|
||||
server_name _;
|
||||
|
||||
# --- Health check (no auth) ---
|
||||
location = /health {
|
||||
access_log off;
|
||||
default_type application/json;
|
||||
return 200 '{"status":"ok","version":"1.0"}';
|
||||
}
|
||||
|
||||
# --- ElevenLabs ---
|
||||
location /elevenlabs/ {
|
||||
# Auth checks
|
||||
if ($allowed_ip = 0) {
|
||||
return 403 '{"error":"ip_not_allowed"}';
|
||||
}
|
||||
if ($auth_ok = 0) {
|
||||
return 403 '{"error":"invalid_token"}';
|
||||
}
|
||||
|
||||
# Variable forces runtime DNS resolution (not cached at startup)
|
||||
set $elevenlabs_upstream https://api.elevenlabs.io;
|
||||
|
||||
# Strip /elevenlabs/ prefix and proxy
|
||||
rewrite ^/elevenlabs/(.*) /$1 break;
|
||||
|
||||
proxy_pass $elevenlabs_upstream;
|
||||
proxy_ssl_server_name on;
|
||||
proxy_ssl_name api.elevenlabs.io;
|
||||
proxy_ssl_protocols TLSv1.2 TLSv1.3;
|
||||
|
||||
# Host header must match upstream for Cloudflare
|
||||
proxy_set_header Host api.elevenlabs.io;
|
||||
proxy_set_header Connection "";
|
||||
|
||||
# Scrub all headers that leak the original client IP
|
||||
# Cloudflare reads these to determine "real" client geo
|
||||
proxy_set_header X-Forwarded-For "";
|
||||
proxy_set_header X-Real-IP "";
|
||||
proxy_set_header True-Client-IP "";
|
||||
proxy_set_header CF-Connecting-IP "";
|
||||
proxy_set_header X-Client-IP "";
|
||||
proxy_set_header Forwarded "";
|
||||
proxy_set_header Via "";
|
||||
|
||||
# Remove proxy token before forwarding to upstream
|
||||
proxy_set_header X-Proxy-Token "";
|
||||
|
||||
# HTTP/1.1 for keepalive
|
||||
proxy_http_version 1.1;
|
||||
|
||||
# Streaming / performance
|
||||
proxy_buffering off;
|
||||
proxy_request_buffering off;
|
||||
proxy_read_timeout 120s;
|
||||
proxy_send_timeout 120s;
|
||||
}
|
||||
|
||||
# --- OpenAI ---
|
||||
location /openai/ {
|
||||
if ($allowed_ip = 0) {
|
||||
return 403 '{"error":"ip_not_allowed"}';
|
||||
}
|
||||
if ($auth_ok = 0) {
|
||||
return 403 '{"error":"invalid_token"}';
|
||||
}
|
||||
|
||||
set $openai_upstream https://api.openai.com;
|
||||
|
||||
rewrite ^/openai/(.*) /$1 break;
|
||||
|
||||
proxy_pass $openai_upstream;
|
||||
proxy_ssl_server_name on;
|
||||
proxy_ssl_name api.openai.com;
|
||||
proxy_ssl_protocols TLSv1.2 TLSv1.3;
|
||||
|
||||
proxy_set_header Host api.openai.com;
|
||||
proxy_set_header Connection "";
|
||||
|
||||
# Scrub all headers that leak the original client IP
|
||||
proxy_set_header X-Forwarded-For "";
|
||||
proxy_set_header X-Real-IP "";
|
||||
proxy_set_header True-Client-IP "";
|
||||
proxy_set_header CF-Connecting-IP "";
|
||||
proxy_set_header X-Client-IP "";
|
||||
proxy_set_header Forwarded "";
|
||||
proxy_set_header Via "";
|
||||
|
||||
proxy_set_header X-Proxy-Token "";
|
||||
|
||||
proxy_http_version 1.1;
|
||||
|
||||
proxy_buffering off;
|
||||
proxy_request_buffering off;
|
||||
proxy_read_timeout 120s;
|
||||
proxy_send_timeout 120s;
|
||||
}
|
||||
|
||||
# --- Catch-all ---
|
||||
location / {
|
||||
default_type application/json;
|
||||
return 404 '{"error":"unknown_upstream","hint":"use /elevenlabs/ or /openai/"}';
|
||||
}
|
||||
include /etc/nginx/conf.d/locations.conf;
|
||||
}
|
||||
|
||||
# --- HTTPS server (generated at container start if certs exist) ---
|
||||
include /etc/nginx/conf.d/https_server.conf;
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user