Nginx must key the cert map on $ssl_server_name during handshake, and www-data needs ssl-cert group access to Let's Encrypt files when certificates are loaded via variables. Co-authored-by: Cursor <cursoragent@cursor.com>
15 lines
709 B
Plaintext
15 lines
709 B
Plaintext
# Per-tenant dashboard cert paths (default → shared meshkee-dashboards cert).
|
|
# Must key on $ssl_server_name (SNI). $host is empty during the TLS handshake,
|
|
# so a $host map always falls through to default.
|
|
# Tenant rows are appended by deploy/ssl-issue-tenant.sh when Issue SSL runs for one domain.
|
|
#
|
|
# Variable ssl_certificate is loaded by nginx workers (www-data), so
|
|
# /etc/letsencrypt/{live,archive} must be group-readable by ssl-cert (see ssl-issue-tenant.sh).
|
|
map $ssl_server_name $meshkee_dashboard_ssl_cert {
|
|
default /etc/letsencrypt/live/meshkee-dashboards/fullchain.pem;
|
|
}
|
|
|
|
map $ssl_server_name $meshkee_dashboard_ssl_key {
|
|
default /etc/letsencrypt/live/meshkee-dashboards/privkey.pem;
|
|
}
|