ServerName ai.succhia.cz # Define the load balancer cluster BalancerMember "http://ai.kowa.localhost:4322" loadfactor=90 BalancerMember "http://ai.bozz.localhost:4321" loadfactor=10 # Set proxy timeout ProxyTimeout 10 # Proxy settings for the root location ProxyPass balancer://myclusterhantani/ ProxyPassReverse balancer://myclusterhantani/ # Conditional SSL configuration SSLEngine on SSLCertificateFile /etc/letsencrypt/live/ai.succhia.cz/cert.pem SSLCertificateKeyFile /etc/letsencrypt/live/ai.succhia.cz/privkey.pem SSLCertificateChainFile /etc/letsencrypt/live/ai.succhia.cz/chain.pem # Harden SSL by setting HSTS header Header set Strict-Transport-Security "max-age=31536000" # Optional: Additional SSL security settings SSLProtocol all -SSLv3 -TLSv1 -TLSv1.1 SSLCipherSuite HIGH:!aNULL:!MD5 SSLHonorCipherOrder on # Optional: Enable logging ErrorLog ${APACHE_LOG_DIR}/error.log CustomLog ${APACHE_LOG_DIR}/access.log combined ServerName ai.succhia.cz Include /etc/apache2/my-includes/redirect-to-https.conf