fix(nginx+compose): dotfile block first, no pdf gzip, single healthcheck (tour J4/N4/J5)
Dotfile location moved above caching regex locations (first match wins). application/pdf out of gzip_types (already flate-compressed). Compose healthcheck block removed — image HEALTHCHECK is the single source, inherited. Oracles: nginx -t, dotfiles 404, PDF no Content-Encoding, HTML still gzipped, headers 5/5, inherited health = healthy.
This commit is contained in:
+2
-6
@@ -19,12 +19,8 @@ services:
|
||||
restart: unless-stopped
|
||||
ports:
|
||||
- "127.0.0.1:${PORT:-8080}:8080"
|
||||
healthcheck:
|
||||
test: ["CMD", "wget", "-qO-", "http://127.0.0.1:8080/"]
|
||||
interval: 30s
|
||||
timeout: 3s
|
||||
retries: 3
|
||||
start_period: 5s
|
||||
# Healthcheck inherited from the image HEALTHCHECK (Dockerfile) — do not
|
||||
# redeclare here, one definition only.
|
||||
read_only: true
|
||||
tmpfs:
|
||||
# nginx-unprivileged writes pid + temp files under /tmp only.
|
||||
|
||||
+7
-6
@@ -36,9 +36,15 @@ server {
|
||||
application/javascript
|
||||
application/json
|
||||
application/xml
|
||||
application/pdf
|
||||
image/svg+xml;
|
||||
|
||||
# Block access to dotfiles (defense-in-depth — none are shipped anyway).
|
||||
# First regex location wins: keep this above the caching regex blocks so
|
||||
# a hypothetical /.foo.html can't be served by them.
|
||||
location ~ /\. {
|
||||
return 404;
|
||||
}
|
||||
|
||||
# Long cache for the PDF (regenerated rarely, content-hash not used).
|
||||
location ~* \.pdf$ {
|
||||
add_header Cache-Control "public, max-age=604800";
|
||||
@@ -62,11 +68,6 @@ server {
|
||||
access_log /var/log/nginx/access.log;
|
||||
error_log /var/log/nginx/error.log warn;
|
||||
|
||||
# Block access to dotfiles (defense-in-depth — none are shipped anyway).
|
||||
location ~ /\. {
|
||||
return 404;
|
||||
}
|
||||
|
||||
# Default: serve files, fall back to 404.
|
||||
location / {
|
||||
try_files $uri $uri/ =404;
|
||||
|
||||
Reference in New Issue
Block a user