From 840632a6f890ded3fe4ce863c613a16a9bad12ff Mon Sep 17 00:00:00 2001 From: Bastien Chanot Date: Sun, 5 Jul 2026 14:12:43 +0200 Subject: [PATCH] docs: .githooks + hooksPath clone note; deploy section synced (native-nginx prod, hardened container path, headers snippet) --- README.md | 20 +++++++++++++++----- 1 file changed, 15 insertions(+), 5 deletions(-) diff --git a/README.md b/README.md index d4634b0..a23462c 100644 --- a/README.md +++ b/README.md @@ -15,10 +15,18 @@ Static single-page site (no framework, no build step). Lives at https://bchanot. | `.claude/` | Memory registries, tasks, audits | | `Dockerfile` | Container image build — copies static assets into nginx | | `docker-compose.yml` | Service def — host port, hardening (read-only, cap_drop), tmpfs | -| `nginx.conf` | In-container nginx — security headers, CSP, gzip, cache | +| `nginx.conf` | In-container nginx — CSP, gzip, cache rules | +| `nginx-security-headers.conf` | Shared security-headers snippet, re-included per location (nginx `add_header` inheritance is all-or-nothing) | | `.env.example` | Sample env — `PORT` for the host bind | +| `.githooks/` | Versioned git hooks — pre-commit blocks direct code commits on `main`/`develop` (gitflow) | | `favicon.*`, `apple-touch-icon.png` | Favicon set — SVG primary + ICO/PNG + 180×180 apple-touch | +After cloning, wire the versioned hooks once: + +```bash +git config core.hooksPath .githooks +``` + ## Local preview ```bash @@ -75,10 +83,12 @@ WCAG AA contrast. Focus visible. Semantic HTML. ## Deploy -Production runs as a Docker container (`bchanot-web`, `nginx:1.27-alpine`) -behind the host's nginx reverse proxy, which terminates TLS and `proxy_pass`es -to it. The host port is set via `PORT` (default 8080) and bound to `127.0.0.1`, -so all traffic goes through the front proxy. +Production currently serves the static files directly from the VPS's native +nginx (which also terminates TLS). The repo additionally maintains a hardened +container path (`bchanot-web`, `nginxinc/nginx-unprivileged:1.28-alpine`, +digest-pinned, runs as uid 101 on port 8080) for when a containerized deploy +is preferred: the host port is set via `PORT` (default 8080) and bound to +`127.0.0.1`, so all traffic goes through the front proxy. ```bash cp .env.example .env # optional: set PORT