server { listen 80; listen 443 ssl; server_name ${HHZ_DOMAIN}; root /data/tuoheng_hhz_web/dist; client_max_body_size 2g; # SSL证书配置 ssl_certificate /etc/nginx/t-aaron.com.pem; ssl_certificate_key /etc/nginx/t-aaron.com.key; ssl_session_timeout 5m; ssl_ciphers ECDHE-RSA-AES128-GCM-SHA256:ECDHE:ECDH:AES:HIGH:!NULL:!aNULL:!MD5:!ADH:!RC4; ssl_protocols TLSv1.1 TLSv1.2 TLSv1.3; ssl_prefer_server_ciphers on; # 开启gzip功能 gzip on; gzip_min_length 10k; gzip_comp_level 9; gzip_types text/plain text/css application/javascript application/x-javascript text/javascript application/xml; gzip_vary on; gzip_disable "MSIE [1-6]\."; location /{ try_files $uri $uri/ @router; index index.html; } location @router{ rewrite ^.*$ /index.html last; } location /permission { proxy_pass http://${HHZ_ADMIN_NAME}:9055; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; } location /wxapp { proxy_pass http://${HHZ_API_NAME}:9056/api; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; } location /hhz { proxy_pass http://gatewayService/hhz; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; } }