Showing posts with label Nginx. Show all posts
Showing posts with label Nginx. Show all posts

Thursday, July 20, 2017

How to hide your application name using nginx proxy_pass directive

For the showcase purpose I will be using the store application which resides inside WSO2 API Manager 2.1.0

Following are API Manager specific configs which needs to be done.

1. Set proxyPort attribute for connector configs resides in <AM_HOME>/repository/conf/tomcat/catalina-server.xml file.

        <Connector protocol="org.apache.coyote.http11.Http11NioProtocol"
                   port="9763"
                   redirectPort="9443"
                   proxyPort="80"
                   bindOnInit="false"
                   maxHttpHeaderSize="8192"

         />

        <Connector protocol="org.apache.coyote.http11.Http11NioProtocol"
                   port="9443"
                   proxyPort="443"
                   bindOnInit="false"
                   sslProtocol="TLS"
                   maxHttpHeaderSize="8192"
          />

Note that I have removed some attributes for brevity.

2. Update reverseProxy configuration resides inside <AM_HOME>/repository/deployment/server/jaggeryapps/store/site/conf/site.json

    "reverseProxy" : {
        "enabled" : true, 

        "host" : "localhost",
        "context":"",
    }

After above changes start/restart the AM node.


Now the Nginx configuration,

Make sure to generate and store SSL certificate and the key within /etc/nginx/ssl directory.

For the explanation purpose I will be having two server blocks, which can be consolidated to a one.

server{
    listen 80;
    server_name localhost;
    location / {
            proxy_pass http://localhost:9763/store/;
            proxy_redirect off;
            proxy_set_header Host $host;
            proxy_set_header X-Real-IP      $remote_addr;
            proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
            include /etc/nginx/proxy_params;
            proxy_cookie_path ~*^/.* /;
    }
}
server{
    listen 443 ssl;
    ssl_certificate /etc/nginx/ssl/nginx.crt;
    ssl_certificate_key /etc/nginx/ssl/nginx.key;
    server_name localhost;
    location / {
            proxy_pass https://localhost:9443/store/;
            proxy_redirect off;
            proxy_set_header Host $host;
            proxy_set_header X-Real-IP      $remote_addr;
            proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
            include /etc/nginx/proxy_params;
            proxy_cookie_path ~*^/.* /;
    }
}

After reloading the newly added config browse https://localhost or https://localhost,




Thursday, May 29, 2014

Fronting WSO2 Management Console UI with Nginx

I'm going to set up WSO2 API Manager & WSO2 BAM in Linux environment for this exercise.

Since I'm going to run both products within a single machine need following configuration change,

1. Update port offset configuration as follows within <BAM_HOME>/repository/conf/carbon.xml.
<Offset>1</Offset>
 For API Manager I'm going to use the default configurations.

2. Update /etc/hosts with following and update IP address according to your environment.
10.100.0.128 am.wso2.org
10.100.0.128 bam.wso2.org
 3. Use following configuration within Nginx and update  proxy_pass according to your environment.

server {
    listen 443;
    server_name am.wso2.org;
    ssl on;
        ssl_certificate /etc/nginx/ssl/server.crt;
        ssl_certificate_key /etc/nginx/ssl/server.key;

    location /carbon {
            index index.html;
            proxy_set_header X-Forwarded-Host $host;
            proxy_set_header X-Forwarded-Server $host;
            proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
            proxy_pass https://10.100.0.128:9443;
        }
    location /t {
            index index.html;
            proxy_set_header X-Forwarded-Host $host;
            proxy_set_header X-Forwarded-Server $host;
            proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
            proxy_pass https://10.100.0.128:9443;
        }
 }

server {
    listen 443;
    server_name bam.wso2.org;
    ssl on;
        ssl_certificate /etc/nginx/ssl/server.crt;
        ssl_certificate_key /etc/nginx/ssl/server.key;

    location /carbon {
            index index.html;
            proxy_set_header X-Forwarded-Host $host;
            proxy_set_header X-Forwarded-Server $host;
            proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
            proxy_pass https://10.100.0.128:9444;
        }
    location /t {
            index index.html;
            proxy_set_header X-Forwarded-Host $host;
            proxy_set_header X-Forwarded-Server $host;
            proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
            proxy_pass https://10.100.0.128:9444;
        }
 }


So in this configuration I'm having two server directives, one for API Manager and one for BAM.

Read this post if you need help on creating SSL certificates.

I'm done with the configuration now, lets browse our management console now.

If you type https://am.wso2.org/carbon you will get the API Manager Admin Console UI.

 
After logging using defualt username:admin ,password:admin you may create a new tenant using Home > Configure > Multitenancy > Add New Tenant.

Now try to log-in to that tenant. You will get the following,



Ok, Let's try the BAM admin console now. Browse https://bam.wso2.org/carbon ,


Log-in, create a tenant and try to login using those tenant credentials.


Hope this will help to configure any WSO2 Product with Nginx !!