<feed xmlns='http://www.w3.org/2005/Atom'>
<title>luke/ansible-roles/nginx, branch main</title>
<subtitle>Ansible roles for nth.io infrastructure
</subtitle>
<id>https://src.nth.io/luke/ansible-roles/atom?h=main</id>
<link rel='self' href='https://src.nth.io/luke/ansible-roles/atom?h=main'/>
<link rel='alternate' type='text/html' href='https://src.nth.io/luke/ansible-roles/'/>
<updated>2026-08-10T14:37:37Z</updated>
<entry>
<title>nginx: add catch-all default_server returning 404 for unmatched hosts</title>
<updated>2026-08-10T14:37:37Z</updated>
<author>
<name>Luke Hoersten</name>
<email>luke@hoersten.org</email>
</author>
<published>2026-08-10T14:36:28Z</published>
<link rel='alternate' type='text/html' href='https://src.nth.io/luke/ansible-roles/commit/?id=3610744c6a2324cbffeb49bd2e8a2b7c58a2e9e6'/>
<id>urn:sha1:3610744c6a2324cbffeb49bd2e8a2b7c58a2e9e6</id>
<content type='text'>
Without an explicit default_server, nginx falls back to the first
alphabetically-loaded vhost for any request whose Host or SNI matches no
server_name. Add an explicit catch-all that returns a plain 404 over
HTTP and rejects the TLS handshake (ssl_reject_handshake, nginx &gt;=
1.19.4) so unmatched HTTPS requests are not served a mismatched cert.
</content>
</entry>
<entry>
<title>Use checksum-based rsync for nginx root file sync</title>
<updated>2026-04-19T00:06:12Z</updated>
<author>
<name>Luke Hoersten</name>
<email>luke@hoersten.org</email>
</author>
<published>2026-04-19T00:06:12Z</published>
<link rel='alternate' type='text/html' href='https://src.nth.io/luke/ansible-roles/commit/?id=eb73ba26e2ef66e38097b784fb3c4621a2991a40'/>
<id>urn:sha1:eb73ba26e2ef66e38097b784fb3c4621a2991a40</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Fixed paper build URL and nginx logging off.</title>
<updated>2026-03-27T19:56:43Z</updated>
<author>
<name>Luke Hoersten</name>
<email>luke@hoersten.org</email>
</author>
<published>2026-03-27T19:56:43Z</published>
<link rel='alternate' type='text/html' href='https://src.nth.io/luke/ansible-roles/commit/?id=0e8a85cd7c3a4ee1de23ffd78cc49b727382acae'/>
<id>urn:sha1:0e8a85cd7c3a4ee1de23ffd78cc49b727382acae</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Update versions and fix nginx logging.</title>
<updated>2026-03-26T02:42:49Z</updated>
<author>
<name>Luke Hoersten</name>
<email>luke@hoersten.org</email>
</author>
<published>2026-03-26T02:42:49Z</published>
<link rel='alternate' type='text/html' href='https://src.nth.io/luke/ansible-roles/commit/?id=58d4444b06de49587417791bb06a4fe1aeda571d'/>
<id>urn:sha1:58d4444b06de49587417791bb06a4fe1aeda571d</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Lots of updates and fixes for Ubuntu 24.04 Noble.</title>
<updated>2024-10-07T20:25:37Z</updated>
<author>
<name>Luke Hoersten</name>
<email>luke@hoersten.org</email>
</author>
<published>2024-10-07T20:25:37Z</published>
<link rel='alternate' type='text/html' href='https://src.nth.io/luke/ansible-roles/commit/?id=27739609362360b2bf533f5a59106ce52c8d4b9f'/>
<id>urn:sha1:27739609362360b2bf533f5a59106ce52c8d4b9f</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Use rsync for nginx root copy.</title>
<updated>2023-02-11T16:49:06Z</updated>
<author>
<name>Luke Hoersten</name>
<email>luke@hoersten.org</email>
</author>
<published>2023-02-11T16:49:06Z</published>
<link rel='alternate' type='text/html' href='https://src.nth.io/luke/ansible-roles/commit/?id=c2fc624dd77c8e50564e7619cf6f52f2e174f67f'/>
<id>urn:sha1:c2fc624dd77c8e50564e7619cf6f52f2e174f67f</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Changing www root content does not require an nginx reload.</title>
<updated>2021-07-26T21:08:03Z</updated>
<author>
<name>Luke Hoersten</name>
<email>luke@hoersten.org</email>
</author>
<published>2021-07-26T21:08:03Z</published>
<link rel='alternate' type='text/html' href='https://src.nth.io/luke/ansible-roles/commit/?id=c2e3b8017d94161dbf170e02c26b52cbd9d45429'/>
<id>urn:sha1:c2e3b8017d94161dbf170e02c26b52cbd9d45429</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Added nginx and oragono HUP reloading to systemd handlers. Added nginx config.</title>
<updated>2020-07-05T15:25:32Z</updated>
<author>
<name>Luke Hoersten</name>
<email>luke@hoersten.org</email>
</author>
<published>2020-07-05T15:25:32Z</published>
<link rel='alternate' type='text/html' href='https://src.nth.io/luke/ansible-roles/commit/?id=d67fdf8ed71f6927a00cf6bc812777091e5a026d'/>
<id>urn:sha1:d67fdf8ed71f6927a00cf6bc812777091e5a026d</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Minor update.</title>
<updated>2020-06-16T15:54:40Z</updated>
<author>
<name>Luke Hoersten</name>
<email>luke@hoersten.org</email>
</author>
<published>2020-06-16T15:54:40Z</published>
<link rel='alternate' type='text/html' href='https://src.nth.io/luke/ansible-roles/commit/?id=28e0e53a0f4fb020c8d01c75f3dd16c7819dab5f'/>
<id>urn:sha1:28e0e53a0f4fb020c8d01c75f3dd16c7819dab5f</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Added stream support to nginx configs.</title>
<updated>2020-06-16T04:25:16Z</updated>
<author>
<name>Luke Hoersten</name>
<email>luke@hoersten.org</email>
</author>
<published>2020-06-16T04:25:16Z</published>
<link rel='alternate' type='text/html' href='https://src.nth.io/luke/ansible-roles/commit/?id=a10a0a3f06f514e4e7968b1b8db37342211979a7'/>
<id>urn:sha1:a10a0a3f06f514e4e7968b1b8db37342211979a7</id>
<content type='text'>
</content>
</entry>
</feed>
