反代维基图像站,部分修复mashirozx#26 TODO:Mashiro签发新的证书,包含wikimedia.org和upload.wikimedia.org。

This commit is contained in:
jingkaimori 2020-10-16 21:41:24 +08:00
parent c3d514e93c
commit c0ffd02073

View File

@ -274,10 +274,12 @@ server {
} }
} }
upstream wikipedia-server { upstream wikipedia-text-lb {
#server 198.35.26.96:443;
server 208.80.153.224:443; server 208.80.153.224:443;
server 208.80.154.224:443; server 208.80.154.224:443;
server 91.198.174.192:443; server 91.198.174.192:443;
server 103.102.166.224:443;
} }
server { server {
@ -290,7 +292,7 @@ server {
ssl_certificate_key ca/pixiv.net.key; ssl_certificate_key ca/pixiv.net.key;
location / { location / {
proxy_pass https://wikipedia-server/; proxy_pass https://wikipedia-text-lb/;
proxy_set_header Host $http_host; proxy_set_header Host $http_host;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Real_IP $remote_addr; proxy_set_header X-Real_IP $remote_addr;
@ -300,6 +302,47 @@ server {
} }
} }
server {
listen 443 ssl;
server_name wikimedia.org;
ssl_certificate ca/pixiv.net.crt;
ssl_certificate_key ca/pixiv.net.key;
location / {
proxy_pass https://wikipedia-text-lb/;
proxy_set_header Host $http_host;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Real_IP $remote_addr;
proxy_set_header User-Agent $http_user_agent;
proxy_set_header Accept-Encoding '';
proxy_buffering off;
}
}
upstream wikipedia-upload-lb {
server 208.80.153.240:443;
server 208.80.154.240:443;
server 91.198.174.208:443;
server 103.102.166.240:443;
}
server {
listen 443 ssl;
server_name upload.wikimedia.org;
ssl_certificate ca/pixiv.net.crt;
ssl_certificate_key ca/pixiv.net.key;
location / {
proxy_pass https://wikipedia-upload-lb/;
proxy_set_header Host $http_host;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Real_IP $remote_addr;
proxy_set_header User-Agent $http_user_agent;
proxy_set_header Accept-Encoding '';
proxy_buffering off;
}
}
server { server {
listen 443 ssl; listen 443 ssl;
server_name *.steamcommunity.com; server_name *.steamcommunity.com;