java -jar myapp.jar
java -jar myapp.jar --spring.config.additional-location=file:/etc/myapp/
server {
listen 80 default_server;
listen [::]:80 default_server;
location / {
return 301 https://$host$request_uri;
server {
listen 443 ssl http2;
listen [::]:443 ssl http2;
ssl_certificate /etc/letsencrypt/live/;
ssl_certificate_key /etc/letsencrypt/live/;
ssl_session_timeout 1d;
ssl_session_cache shared:MozSSL:10m; # about 40000 sessions
ssl_session_tickets off;
# curl > /path/to/dhparam
# ssl_dhparam /path/to/dhparam;
# intermediate configuration
ssl_protocols TLSv1.2 TLSv1.3;
ssl_prefer_server_ciphers off;
# HSTS (ngx_http_headers_module is required) (63072000 seconds)
add_header Strict-Transport-Security "max-age=63072000" always;
ssl_stapling on;
ssl_stapling_verify on;
location / {
root /var/www/html/;
autoindex off;
if ( $request_uri ~ "/index.html" ) {
rewrite ^(|/(.*))/index\.html$ /$2 permanent;
<div sec:authorize="isAuthenticated()">
This content is only shown to authenticated users.
<div sec:authorize="hasRole('ROLE_ADMIN')">
This content is only shown to administrators.
<div sec:authorize="hasRole('ROLE_USER')">
This content is only shown to users.