reverse-proxy-confs/qbittorrent.subdomain.conf.sample

163 lines
5.6 KiB
Plaintext

## Version 2023/10/10
# make sure that your qbittorrent container is named qbittorrent
# make sure that your dns has a cname set for qbittorrent
# Api and related location bypasses are now commented out by default
# due to users easily misconfiguring qbittorrent to allow
# public access through the api endpoint by including SWAG in
# "Bypass authentication for clients in whitelisted IP subnets",
# which results in all connections through SWAG to be considered
# local and bypassing auth, which also applies to qbittorrent's
# api endpoint (webui api)
# enable at your own risk
server {
listen 443 ssl http2;
listen [::]:443 ssl http2;
server_name qbittorrent.*;
include /config/nginx/ssl.conf;
client_max_body_size 0;
# enable for ldap auth (requires ldap-location.conf in the location block)
#include /config/nginx/ldap-server.conf;
# enable for Authelia (requires authelia-location.conf in the location block)
#include /config/nginx/authelia-server.conf;
# enable for Authentik (requires authentik-location.conf in the location block)
#include /config/nginx/authentik-server.conf;
location / {
# enable the next two lines for http auth
#auth_basic "Restricted";
#auth_basic_user_file /config/nginx/.htpasswd;
# enable for ldap auth (requires ldap-server.conf in the server block)
#include /config/nginx/ldap-location.conf;
# enable for Authelia (requires authelia-server.conf in the server block)
#include /config/nginx/authelia-location.conf;
# enable for Authentik (requires authentik-server.conf in the server block)
#include /config/nginx/authentik-location.conf;
include /config/nginx/proxy.conf;
include /config/nginx/resolver.conf;
set $upstream_app qbittorrent;
set $upstream_port 8080;
set $upstream_proto http;
proxy_pass $upstream_proto://$upstream_app:$upstream_port;
proxy_set_header Referer '';
proxy_set_header Host $upstream_app:$upstream_port;
proxy_set_header X-Forwarded-Host $host;
}
# location ~ (/qbittorrent)?/api {
# include /config/nginx/proxy.conf;
# include /config/nginx/resolver.conf;
# set $upstream_app qbittorrent;
# set $upstream_port 8080;
# set $upstream_proto http;
# proxy_pass $upstream_proto://$upstream_app:$upstream_port;
# rewrite /qbittorrent(.*) $1 break;
# proxy_set_header Referer '';
# proxy_set_header Host $upstream_app:$upstream_port;
# proxy_set_header X-Forwarded-Host $host;
# }
# location ~ (/qbittorrent)?/command {
# include /config/nginx/proxy.conf;
# include /config/nginx/resolver.conf;
# set $upstream_app qbittorrent;
# set $upstream_port 8080;
# set $upstream_proto http;
# proxy_pass $upstream_proto://$upstream_app:$upstream_port;
# rewrite /qbittorrent(.*) $1 break;
# proxy_set_header Referer '';
# proxy_set_header Host $upstream_app:$upstream_port;
# proxy_set_header X-Forwarded-Host $host;
# }
# location ~ (/qbittorrent)?/css {
# include /config/nginx/proxy.conf;
# include /config/nginx/resolver.conf;
# set $upstream_app qbittorrent;
# set $upstream_port 8080;
# set $upstream_proto http;
# proxy_pass $upstream_proto://$upstream_app:$upstream_port;
# rewrite /qbittorrent(.*) $1 break;
# proxy_set_header Referer '';
# proxy_set_header Host $upstream_app:$upstream_port;
# proxy_set_header X-Forwarded-Host $host;
# }
# location ~ (/qbittorrent)?/query {
# include /config/nginx/proxy.conf;
# include /config/nginx/resolver.conf;
# set $upstream_app qbittorrent;
# set $upstream_port 8080;
# set $upstream_proto http;
# proxy_pass $upstream_proto://$upstream_app:$upstream_port;
# rewrite /qbittorrent(.*) $1 break;
# proxy_set_header Referer '';
# proxy_set_header Host $upstream_app:$upstream_port;
# proxy_set_header X-Forwarded-Host $host;
# }
# location ~ (/qbittorrent)?/login {
# include /config/nginx/proxy.conf;
# include /config/nginx/resolver.conf;
# set $upstream_app qbittorrent;
# set $upstream_port 8080;
# set $upstream_proto http;
# proxy_pass $upstream_proto://$upstream_app:$upstream_port;
# rewrite /qbittorrent(.*) $1 break;
# proxy_set_header Referer '';
# proxy_set_header Host $upstream_app:$upstream_port;
# proxy_set_header X-Forwarded-Host $host;
# }
# location ~ (/qbittorrent)?/sync {
# include /config/nginx/proxy.conf;
# include /config/nginx/resolver.conf;
# set $upstream_app qbittorrent;
# set $upstream_port 8080;
# set $upstream_proto http;
# proxy_pass $upstream_proto://$upstream_app:$upstream_port;
# rewrite /qbittorrent(.*) $1 break;
# proxy_set_header Referer '';
# proxy_set_header Host $upstream_app:$upstream_port;
# proxy_set_header X-Forwarded-Host $host;
# }
# location ~ (/qbittorrent)?/scripts {
# include /config/nginx/proxy.conf;
# include /config/nginx/resolver.conf;
# set $upstream_app qbittorrent;
# set $upstream_port 8080;
# set $upstream_proto http;
# proxy_pass $upstream_proto://$upstream_app:$upstream_port;
# rewrite /qbittorrent(.*) $1 break;
# proxy_set_header Referer '';
# proxy_set_header Host $upstream_app:$upstream_port;
# proxy_set_header X-Forwarded-Host $host;
# }
}