Files
SocialPub/deploy/nginx/privapub.thepra.dev.conf
T
thepraandClaude Opus 5.5 f9658a8e7a
Build / Build (push) Successful in 37s
Deploy / privapub.thepra.dev (push) Successful in 57s
P6: remote video and audio play through the proxy
- The media proxy streams ranged requests from the origin (passing the range on, never caching), downloads and caches
  whole files otherwise, and serves cached files with range support. A PeerTube video is never fetched whole for one
  viewer, and clients still never contact the remote host.
- PeerTube's fragmented MP4 files inside an HLS entry are read as variants, so HLS-only instances play too.
- A remote Video or Audio post becomes one playable Mastodon attachment: the best MP4 up to 720p that carries both
  sound and picture, with its poster and duration; the card is kept only when nothing is playable.
- nginx: /media/proxy/ with proxy_buffering off and a 600 s read timeout (applied on the box, with a backup).

Checked live: a GoToSocial image through the proxy answers 206 with exactly the asked range when streamed, 200 when
cached, and 206 with the right Content-Range from the cache.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012CzABvBkbcFqoHdmi8b9WB
2026-10-01 18:59:14 +02:00

74 lines
2.0 KiB
Plaintext

server {
listen 80;
listen [::]:80;
server_name privapub.thepra.dev;
location ^~ /.well-known/acme-challenge/ {
root /var/www/acme;
default_type "text/plain";
}
location / {
return 301 https://$host$request_uri;
}
}
server {
listen 443 ssl;
listen 8444 ssl proxy_protocol;
listen [::]:443 ssl;
server_name privapub.thepra.dev;
http2 on;
include /etc/nginx/ssl.conf;
ssl_certificate /root/.acme.sh/privapub.thepra.dev_ecc/fullchain.cer;
ssl_certificate_key /root/.acme.sh/privapub.thepra.dev_ecc/privapub.thepra.dev.key;
include /etc/nginx/snippets/privapub-headers.conf;
access_log /var/log/nginx/privapub.thepra.dev.access.log;
error_log /var/log/nginx/privapub.thepra.dev.error.log;
client_max_body_size 2m;
location ^~ /.well-known/acme-challenge/ {
root /var/www/acme;
default_type "text/plain";
}
location ~ ^/api/v[12]/media$|^/api/v1/accounts/update_credentials$ {
client_max_body_size 100m;
proxy_request_buffering off;
proxy_pass http://127.0.0.1:6970;
proxy_http_version 1.1;
proxy_set_header Connection "";
proxy_set_header Host $host;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_read_timeout 300s;
}
location ^~ /media/proxy/ {
proxy_buffering off;
proxy_pass http://127.0.0.1:6970;
proxy_http_version 1.1;
proxy_set_header Connection "";
proxy_set_header Host $host;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_read_timeout 600s;
}
location / {
proxy_pass http://127.0.0.1:6970;
proxy_http_version 1.1;
proxy_set_header Connection "";
proxy_set_header Host $host;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_read_timeout 60s;
}
}