274 Commits

Author SHA1 Message Date
Daniel Micay
6251dc371d consistent whitespace style 2023-05-05 14:45:11 -04:00
Daniel Micay
8f2b158041 drop configuration to clear legacy push cookie 2023-03-24 18:46:50 -04:00
Daniel Micay
bab21cb7c4 improve HTTP request logging
* add $upstream_cache_status
* add '-$connection_requests' after $connection
* enable subrequest logging

$connection_requests makes it much easier to see connection reuse in the
logs and also helps to understand subrequests.
2023-03-09 11:00:51 -05:00
Daniel Micay
84219d55fe add upstream timing to http log format 2023-03-07 14:17:51 -05:00
Daniel Micay
ea521a790b enable minimal stderr logging 2023-03-07 10:56:36 -05:00
Daniel Micay
c82d81e018 ssl_reject_handshake is working as intended 2023-03-07 10:32:56 -05:00
Daniel Micay
31e0ab3807 work around unreliable ssl_reject_handshake 2023-03-06 10:58:56 -05:00
Daniel Micay
365d7ecfd0 avoid double logging for nginx error log 2023-03-06 00:52:05 -05:00
Daniel Micay
89ab32dbe3 disable keepalive for stub HTTP service 2023-02-27 02:41:28 -05:00
Daniel Micay
563a5bf330 use consistent configuration style 2023-02-26 10:48:55 -05:00
Daniel Micay
50e3e2355f disable keepalive for MTA-STS 2023-02-24 17:37:26 -05:00
Daniel Micay
bccb2250ae add back request method to log format 2023-02-19 22:40:14 -05:00
Daniel Micay
c137947453 set baseline nginx root directory in http block 2023-02-19 11:52:54 -05:00
Daniel Micay
3ab9e97549 work around nginx keepalive configuration bug
https://trac.nginx.org/nginx/ticket/2012
2023-02-18 12:31:03 -05:00
Daniel Micay
7aad49766b reject connections to invalid names 2023-02-18 08:55:32 -05:00
Daniel Micay
dc894526df entirely disable access log for status socket 2023-02-18 08:16:20 -05:00
Daniel Micay
907757043b disable multipart range requests 2023-02-14 10:14:02 -05:00
Daniel Micay
f672e046fd improve naming for http limit conn zone 2023-02-11 04:25:11 -05:00
Daniel Micay
7fcd8bf9a8 move error_log configuration to top level 2023-02-11 04:05:33 -05:00
Daniel Micay
30b5aafe32 add request time to log format 2023-02-10 08:28:02 -05:00
Daniel Micay
b903dd72ac switch to improved custom log format
This switches to a fully custom log format instead of using a variant of
the standard combined format since we don't use any tools requiring the
logs to be a standard format. This provides a cleaner format, allows us
to freely add new fields and gets rid of legacy/redundant fields.

The redundant timestamp already provided as the syslog timestamp is
dropped along with the legacy identd field always set to a dash.

This adds the connection serial number for identifying requests coming
from the same connection. TLS version is added as a replacement for our
previous addition of the URI scheme. This also adds the total request
length and total bytes sent to the client instead of only the body bytes
sent.
2023-02-10 08:04:25 -05:00
Daniel Micay
1bc589d45f drop HTTP/2 Push support since Chromium dropped it
This only improves performance for the initial page load by sending
resources that are almost always needed before the client receives the
preload headers and fetches them. It can degrade performance in some
edge cases such as clients with web fonts disabled or if the session
cookie is cleared without the cache being cleared. Clients can cancel
the push transfers once they start receiving them, but it's wasteful.

Safari and Firefox still support this feature but are likely to follow
the lead of Chromium and drop support for it. Few websites are going to
bother with it without Chromium support and usage is already dropping.
2023-02-10 03:56:20 -05:00
Daniel Micay
3b4c47b51b reduce client body / header timeouts to 15s 2023-02-09 18:42:15 -05:00
Daniel Micay
5260801290 reduce sendfile max chunk to 256k 2023-02-09 17:51:01 -05:00
Daniel Micay
76cc4ae336 avoid unnecessary ACME challenge redirects 2023-02-09 10:12:20 -05:00
Daniel Micay
763c17a058 unify HTTP redirect server blocks 2023-02-09 09:50:08 -05:00
Daniel Micay
3909151fc8 use default HTTP/2 input buffer size 2023-02-09 05:13:03 -05:00
Daniel Micay
3bb002fcd1 simplify nginx status path 2023-01-31 21:50:35 -05:00
Daniel Micay
6280211cc5 SSH commit signing will be used going forward 2023-01-05 02:04:19 -05:00
Daniel Micay
fb5b72e121 add empty traffic-advice configuration 2022-12-15 12:16:08 -05:00
Daniel Micay
d656b32161 update Permissions-Policy for web installer 2022-11-01 18:15:51 -04:00
smdyv
12ee1c8293 Update device image
This is a vectorized image of the Pixel 7 Pro, and saves 98 % of the
byte length of the previously used image.
2022-10-18 15:03:06 -04:00
Daniel Micay
f0a151b35e increase resolver timeout 2022-10-12 16:32:31 -04:00
Daniel Micay
7d0ad1a4de disable local-fonts in Permissions Policy 2022-10-11 11:15:10 -04:00
Daniel Micay
94f838f80d rename conn limit memory zone 2022-10-01 12:52:38 -04:00
Daniel Micay
ba88a05a53 use custom format for access log again 2022-09-27 10:23:23 -04:00
Daniel Micay
942959c75f enable caching for Matrix discovery API 2022-09-26 18:32:58 -04:00
Daniel Micay
0263524db7 reduce HTTP/2 chunk size to match TLS record size 2022-09-26 13:10:12 -04:00
Daniel Micay
c8ba885d32 use syslog (journald) for nginx access log 2022-09-25 14:15:18 -04:00
Daniel Micay
511be885bf reduce keepalive requests 2022-09-24 11:50:35 -04:00
Daniel Micay
e57765c650 reduce connection limit to 128 2022-09-24 11:24:41 -04:00
Daniel Micay
329bc8fd62 reduce HTTP/2 concurrent streams to 16 2022-09-24 11:19:18 -04:00
Daniel Micay
2ef894ca47 reduce max client header buffer size 2022-09-24 11:06:42 -04:00
Daniel Micay
0d728b6cfb no longer need location block for PDFs 2022-08-25 23:15:08 -04:00
Daniel Micay
cca5454c03 redirect legacy counterclaim document to history
The purpose of this document was to respond to false claims from James
Donaldson about myself and GrapheneOS. He changed his story about what
happened many times since this was posted. He didn't move forward with
his attempt at taking us to court and this was never used beyond being
posted on our site as a public response.

Nearly all of his supporters realized he was misleading them and left
for greener pastures. Most of them are now using GrapheneOS. We don't
need to refute outdated attacks on GrapheneOS from a person that's now
almost completely irrelevant, especially since he's now trying not to
draw attention to this since he came out looking so terrible. He quietly
misleads people about what happened with his latest historical revisions
and those are countered better by our newer pages summarizing it.
2022-08-25 23:15:08 -04:00
Daniel Micay
0403d17364 move nginx status API to socket 2022-08-25 23:15:08 -04:00
Daniel Micay
a057a16cc7 configuration style fixes 2022-06-27 23:57:35 -04:00
Daniel Micay
fda40376c7 raise expected nginx version 2022-06-10 19:39:06 -04:00
Daniel Micay
6541335b8c RFC 9239 obsoletes application/javascript 2022-05-12 16:59:25 -04:00
Daniel Micay
d2fc01a154 enable thread pool AIO support 2022-05-03 19:20:58 -04:00