From 84288c5c5850d05d1c32ca1ba60b6c21329a5acc Mon Sep 17 00:00:00 2001 From: Bastien Chanot Date: Mon, 6 Jul 2026 01:06:54 +0200 Subject: [PATCH] fix(nginx+compose): dotfile block first, no pdf gzip, single healthcheck (tour J4/N4/J5) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Dotfile location moved above caching regex locations (first match wins). application/pdf out of gzip_types (already flate-compressed). Compose healthcheck block removed — image HEALTHCHECK is the single source, inherited. Oracles: nginx -t, dotfiles 404, PDF no Content-Encoding, HTML still gzipped, headers 5/5, inherited health = healthy. --- docker-compose.yml | 8 ++------ nginx.conf | 13 +++++++------ 2 files changed, 9 insertions(+), 12 deletions(-) diff --git a/docker-compose.yml b/docker-compose.yml index dac3a3f..7ba86bb 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -19,12 +19,8 @@ services: restart: unless-stopped ports: - "127.0.0.1:${PORT:-8080}:8080" - healthcheck: - test: ["CMD", "wget", "-qO-", "http://127.0.0.1:8080/"] - interval: 30s - timeout: 3s - retries: 3 - start_period: 5s + # Healthcheck inherited from the image HEALTHCHECK (Dockerfile) — do not + # redeclare here, one definition only. read_only: true tmpfs: # nginx-unprivileged writes pid + temp files under /tmp only. diff --git a/nginx.conf b/nginx.conf index b066e92..3775ed8 100644 --- a/nginx.conf +++ b/nginx.conf @@ -36,9 +36,15 @@ server { application/javascript application/json application/xml - application/pdf image/svg+xml; + # Block access to dotfiles (defense-in-depth — none are shipped anyway). + # First regex location wins: keep this above the caching regex blocks so + # a hypothetical /.foo.html can't be served by them. + location ~ /\. { + return 404; + } + # Long cache for the PDF (regenerated rarely, content-hash not used). location ~* \.pdf$ { add_header Cache-Control "public, max-age=604800"; @@ -62,11 +68,6 @@ server { access_log /var/log/nginx/access.log; error_log /var/log/nginx/error.log warn; - # Block access to dotfiles (defense-in-depth — none are shipped anyway). - location ~ /\. { - return 404; - } - # Default: serve files, fall back to 404. location / { try_files $uri $uri/ =404;