<feed xmlns='http://www.w3.org/2005/Atom'>
<title>luke/ansible-roles/nginx/files, branch main</title>
<subtitle>Ansible roles for nth.io infrastructure
</subtitle>
<id>https://src.nth.io/luke/ansible-roles/atom?h=main</id>
<link rel='self' href='https://src.nth.io/luke/ansible-roles/atom?h=main'/>
<link rel='alternate' type='text/html' href='https://src.nth.io/luke/ansible-roles/'/>
<updated>2026-08-10T14:37:37Z</updated>
<entry>
<title>nginx: add catch-all default_server returning 404 for unmatched hosts</title>
<updated>2026-08-10T14:37:37Z</updated>
<author>
<name>Luke Hoersten</name>
<email>luke@hoersten.org</email>
</author>
<published>2026-08-10T14:36:28Z</published>
<link rel='alternate' type='text/html' href='https://src.nth.io/luke/ansible-roles/commit/?id=3610744c6a2324cbffeb49bd2e8a2b7c58a2e9e6'/>
<id>urn:sha1:3610744c6a2324cbffeb49bd2e8a2b7c58a2e9e6</id>
<content type='text'>
Without an explicit default_server, nginx falls back to the first
alphabetically-loaded vhost for any request whose Host or SNI matches no
server_name. Add an explicit catch-all that returns a plain 404 over
HTTP and rejects the TLS handshake (ssl_reject_handshake, nginx &gt;=
1.19.4) so unmatched HTTPS requests are not served a mismatched cert.
</content>
</entry>
<entry>
<title>Fixed paper build URL and nginx logging off.</title>
<updated>2026-03-27T19:56:43Z</updated>
<author>
<name>Luke Hoersten</name>
<email>luke@hoersten.org</email>
</author>
<published>2026-03-27T19:56:43Z</published>
<link rel='alternate' type='text/html' href='https://src.nth.io/luke/ansible-roles/commit/?id=0e8a85cd7c3a4ee1de23ffd78cc49b727382acae'/>
<id>urn:sha1:0e8a85cd7c3a4ee1de23ffd78cc49b727382acae</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Update versions and fix nginx logging.</title>
<updated>2026-03-26T02:42:49Z</updated>
<author>
<name>Luke Hoersten</name>
<email>luke@hoersten.org</email>
</author>
<published>2026-03-26T02:42:49Z</published>
<link rel='alternate' type='text/html' href='https://src.nth.io/luke/ansible-roles/commit/?id=58d4444b06de49587417791bb06a4fe1aeda571d'/>
<id>urn:sha1:58d4444b06de49587417791bb06a4fe1aeda571d</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Added stream support to nginx configs.</title>
<updated>2020-06-16T04:25:16Z</updated>
<author>
<name>Luke Hoersten</name>
<email>luke@hoersten.org</email>
</author>
<published>2020-06-16T04:25:16Z</published>
<link rel='alternate' type='text/html' href='https://src.nth.io/luke/ansible-roles/commit/?id=a10a0a3f06f514e4e7968b1b8db37342211979a7'/>
<id>urn:sha1:a10a0a3f06f514e4e7968b1b8db37342211979a7</id>
<content type='text'>
</content>
</entry>
</feed>
