feat(docker): containerize site with configurable host port

Add Dockerfile (nginx:1.27-alpine), nginx.conf (gzip, cache, CSP and
security headers, no HSTS — left to outer proxy), and docker-compose
service `bchanot-web`. Host port is configurable via PORT env var
(default 8080) and bound to 127.0.0.1 so the container sits behind a
reverse proxy. Container hardened with read_only fs, cap_drop ALL,
no-new-privileges, and tmpfs for nginx runtime dirs. Healthcheck via
wget on /. Also adds .dockerignore and .env.example, and ignores .env.

Usage:
  cp .env.example .env
  docker compose up -d --build

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
bastien
2026-05-15 16:53:20 +02:00
co-authored by Claude Opus 4.7
parent 54e830016c
commit 7957b04de0
6 changed files with 165 additions and 0 deletions
+4
View File
@@ -0,0 +1,4 @@
# Host port the bchanot-web container is exposed on.
# Reverse proxy (nginx/Caddy/Traefik) on the host should proxy_pass to
# http://127.0.0.1:${PORT}.
PORT=8080