| 12
 3
 4
 5
 6
 7
 8
 9
 10
 11
 12
 13
 14
 15
 16
 17
 18
 19
 20
 21
 22
 23
 24
 25
 26
 27
 28
 29
 30
 31
 32
 33
 34
 35
 36
 37
 38
 39
 40
 41
 42
 43
 44
 45
 46
 
 | worker_processes 4;worker_rlimit_nofile 40000;
 
 events {
 worker_connections 8192;
 }
 
 http {
 upstream rancher {
 server IP_NODE_1:80;
 server IP_NODE_2:80;
 server IP_NODE_3:80;
 }
 
 map $http_upgrade $connection_upgrade {
 default Upgrade;
 ''      close;
 }
 
 server {
 listen 443 ssl http2;
 server_name FQDN;
 ssl_certificate /certs/fullchain.pem;
 ssl_certificate_key /certs/privkey.pem;
 
 location / {
 proxy_set_header Host $host;
 proxy_set_header X-Forwarded-Proto $scheme;
 proxy_set_header X-Forwarded-Port $server_port;
 proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
 proxy_pass http://rancher;
 proxy_http_version 1.1;
 proxy_set_header Upgrade $http_upgrade;
 proxy_set_header Connection $connection_upgrade;
 
 proxy_read_timeout 900s;
 proxy_buffering off;
 }
 }
 
 server {
 listen 80;
 server_name FQDN;
 return 301 https://$server_name$request_uri;
 }
 }
 
 |