- The media proxy streams ranged requests from the origin (passing the range on, never caching), downloads and caches whole files otherwise, and serves cached files with range support. A PeerTube video is never fetched whole for one viewer, and clients still never contact the remote host. - PeerTube's fragmented MP4 files inside an HLS entry are read as variants, so HLS-only instances play too. - A remote Video or Audio post becomes one playable Mastodon attachment: the best MP4 up to 720p that carries both sound and picture, with its poster and duration; the card is kept only when nothing is playable. - nginx: /media/proxy/ with proxy_buffering off and a 600 s read timeout (applied on the box, with a backup). Checked live: a GoToSocial image through the proxy answers 206 with exactly the asked range when streamed, 200 when cached, and 206 with the right Content-Range from the cache. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012CzABvBkbcFqoHdmi8b9WB
74 lines
2.0 KiB
Plaintext
74 lines
2.0 KiB
Plaintext
server {
|
|
listen 80;
|
|
listen [::]:80;
|
|
server_name privapub.thepra.dev;
|
|
|
|
location ^~ /.well-known/acme-challenge/ {
|
|
root /var/www/acme;
|
|
default_type "text/plain";
|
|
}
|
|
|
|
location / {
|
|
return 301 https://$host$request_uri;
|
|
}
|
|
}
|
|
|
|
server {
|
|
listen 443 ssl;
|
|
listen 8444 ssl proxy_protocol;
|
|
listen [::]:443 ssl;
|
|
server_name privapub.thepra.dev;
|
|
http2 on;
|
|
|
|
include /etc/nginx/ssl.conf;
|
|
ssl_certificate /root/.acme.sh/privapub.thepra.dev_ecc/fullchain.cer;
|
|
ssl_certificate_key /root/.acme.sh/privapub.thepra.dev_ecc/privapub.thepra.dev.key;
|
|
include /etc/nginx/snippets/privapub-headers.conf;
|
|
|
|
access_log /var/log/nginx/privapub.thepra.dev.access.log;
|
|
error_log /var/log/nginx/privapub.thepra.dev.error.log;
|
|
|
|
client_max_body_size 2m;
|
|
|
|
location ^~ /.well-known/acme-challenge/ {
|
|
root /var/www/acme;
|
|
default_type "text/plain";
|
|
}
|
|
|
|
location ~ ^/api/v[12]/media$|^/api/v1/accounts/update_credentials$ {
|
|
client_max_body_size 100m;
|
|
proxy_request_buffering off;
|
|
proxy_pass http://127.0.0.1:6970;
|
|
proxy_http_version 1.1;
|
|
proxy_set_header Connection "";
|
|
proxy_set_header Host $host;
|
|
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
|
proxy_set_header X-Real-IP $remote_addr;
|
|
proxy_set_header X-Forwarded-Proto $scheme;
|
|
proxy_read_timeout 300s;
|
|
}
|
|
|
|
location ^~ /media/proxy/ {
|
|
proxy_buffering off;
|
|
proxy_pass http://127.0.0.1:6970;
|
|
proxy_http_version 1.1;
|
|
proxy_set_header Connection "";
|
|
proxy_set_header Host $host;
|
|
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
|
proxy_set_header X-Real-IP $remote_addr;
|
|
proxy_set_header X-Forwarded-Proto $scheme;
|
|
proxy_read_timeout 600s;
|
|
}
|
|
|
|
location / {
|
|
proxy_pass http://127.0.0.1:6970;
|
|
proxy_http_version 1.1;
|
|
proxy_set_header Connection "";
|
|
proxy_set_header Host $host;
|
|
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
|
proxy_set_header X-Real-IP $remote_addr;
|
|
proxy_set_header X-Forwarded-Proto $scheme;
|
|
proxy_read_timeout 60s;
|
|
}
|
|
}
|