diff --git a/docker-compose.yml b/docker-compose.yml index dac3a3f..7ba86bb 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -19,12 +19,8 @@ services: restart: unless-stopped ports: - "127.0.0.1:${PORT:-8080}:8080" - healthcheck: - test: ["CMD", "wget", "-qO-", "http://127.0.0.1:8080/"] - interval: 30s - timeout: 3s - retries: 3 - start_period: 5s + # Healthcheck inherited from the image HEALTHCHECK (Dockerfile) — do not + # redeclare here, one definition only. read_only: true tmpfs: # nginx-unprivileged writes pid + temp files under /tmp only. diff --git a/nginx.conf b/nginx.conf index b066e92..3775ed8 100644 --- a/nginx.conf +++ b/nginx.conf @@ -36,9 +36,15 @@ server { application/javascript application/json application/xml - application/pdf image/svg+xml; + # Block access to dotfiles (defense-in-depth — none are shipped anyway). + # First regex location wins: keep this above the caching regex blocks so + # a hypothetical /.foo.html can't be served by them. + location ~ /\. { + return 404; + } + # Long cache for the PDF (regenerated rarely, content-hash not used). location ~* \.pdf$ { add_header Cache-Control "public, max-age=604800"; @@ -62,11 +68,6 @@ server { access_log /var/log/nginx/access.log; error_log /var/log/nginx/error.log warn; - # Block access to dotfiles (defense-in-depth — none are shipped anyway). - location ~ /\. { - return 404; - } - # Default: serve files, fall back to 404. location / { try_files $uri $uri/ =404;