# --------------- nuage nextcloud ------------------

server {
        server_name nuage.tykayn.fr;
        listen 80;
        return 301 https://nuage.tykayn.fr$request_uri;
}


server {
        listen 443 ssl http2;
        listen [::]:443 ssl http2;
        server_name nuage.tykayn.fr;
        ssl_certificate /etc/letsencrypt/live/nuage.tykayn.fr/fullchain.pem;
        ssl_certificate_key /etc/letsencrypt/live/nuage.tykayn.fr/privkey.pem;
        location / {
                proxy_set_header   X-Forwarded-For $remote_addr;
                proxy_set_header   Host $http_host;
                # Container nextcloud
                proxy_pass         https://10.10.10.106;
        }
        add_header Permissions-Policy "interest-cohort=()";
}


server {
        server_name cloud.tykayn.fr;
        listen 80;
        return 301 https://cloud.tykayn.fr$request_uri;
}


server {
        listen 443 ssl  http2;
        listen [::]:443 ssl  http2;
        server_name cloud.tykayn.fr;
       ssl_certificate /etc/letsencrypt/live/cloud.tykayn.fr/fullchain.pem;
        ssl_certificate_key /etc/letsencrypt/live/cloud.tykayn.fr/privkey.pem;
        location / {
                proxy_set_header   X-Forwarded-For $remote_addr;
                proxy_set_header   Host $http_host;
                # Container nextcloud
                proxy_pass         https://10.10.10.106;
        }
        add_header Permissions-Policy "interest-cohort=()";
}


# --------------- pass vaultwarden cipherbliss ------------------

server {
        server_name pass.cipherbliss.com;
        listen 80;
        return 301 https://pass.cipherbliss.com$request_uri;
}


server {
        listen 443  http2;
        listen [::]:443  http2;

     #   listen 443 ssl http2;
     #   listen [::]:443 ssl http2;
        server_name pass.cipherbliss.com;
     #   ssl_certificate /etc/letsencrypt/live/pass.cipherbliss.com/fullchain.pem;
     #   ssl_certificate_key /etc/letsencrypt/live/pass.cipherbliss.com/privkey.pem;
        location / {
                proxy_set_header   X-Forwarded-For $remote_addr;
                proxy_set_header   Host $http_host;
                # Container tksites
                proxy_pass         http://10.10.10.105;
        }
        add_header Permissions-Policy "interest-cohort=()";
}