summaryrefslogtreecommitdiffstats
path: root/roles/httpd/reverseproxy
diff options
context:
space:
mode:
authorPatrick Uiterwijk <puiterwijk@redhat.com>2017-02-21 14:34:37 +0000
committerPatrick Uiterwijk <puiterwijk@redhat.com>2017-02-21 14:34:47 +0000
commit49323cdec7e1b1ff7a7844d17629a3b73e40b068 (patch)
tree210e942e34045dbc651266a0596aec1cb90eb2a0 /roles/httpd/reverseproxy
parentfb85471281d26ccf68cf286991bd50dab60257b5 (diff)
downloadansible-49323cdec7e1b1ff7a7844d17629a3b73e40b068.tar.gz
ansible-49323cdec7e1b1ff7a7844d17629a3b73e40b068.tar.xz
ansible-49323cdec7e1b1ff7a7844d17629a3b73e40b068.zip
Create directory for registry-signatures
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
Diffstat (limited to 'roles/httpd/reverseproxy')
-rw-r--r--roles/httpd/reverseproxy/templates/reversepassproxy.registry.conf6
1 files changed, 6 insertions, 0 deletions
diff --git a/roles/httpd/reverseproxy/templates/reversepassproxy.registry.conf b/roles/httpd/reverseproxy/templates/reversepassproxy.registry.conf
index d501ea8af..51e226501 100644
--- a/roles/httpd/reverseproxy/templates/reversepassproxy.registry.conf
+++ b/roles/httpd/reverseproxy/templates/reversepassproxy.registry.conf
@@ -3,6 +3,8 @@ RequestHeader set X-Scheme https early
RequestHeader set X-Forwarded-Proto https early
ProxyPreserveHost On
+Alias /signatures /srv/web/registry-signatures
+
RewriteEngine on
{% if env == "production" %}
RewriteCond %{HTTP:VIA} !cdn77
@@ -20,6 +22,10 @@ SSLVerifyDepth 1
SSLCACertificateFile /etc/pki/httpd/fedora-server-ca.cert
SSLOptions +FakeBasicAuth
+<Directory /srv/web/registry-signatures>
+ Require all granted
+</Directory>
+
<Location /v2>
Order deny,allow