fix(nginx+compose): dotfile block first, no pdf gzip, single healthcheck (tour J4/N4/J5)
Dotfile location moved above caching regex locations (first match wins). application/pdf out of gzip_types (already flate-compressed). Compose healthcheck block removed — image HEALTHCHECK is the single source, inherited. Oracles: nginx -t, dotfiles 404, PDF no Content-Encoding, HTML still gzipped, headers 5/5, inherited health = healthy.
This commit is contained in:
+2
-6
@@ -19,12 +19,8 @@ services:
|
|||||||
restart: unless-stopped
|
restart: unless-stopped
|
||||||
ports:
|
ports:
|
||||||
- "127.0.0.1:${PORT:-8080}:8080"
|
- "127.0.0.1:${PORT:-8080}:8080"
|
||||||
healthcheck:
|
# Healthcheck inherited from the image HEALTHCHECK (Dockerfile) — do not
|
||||||
test: ["CMD", "wget", "-qO-", "http://127.0.0.1:8080/"]
|
# redeclare here, one definition only.
|
||||||
interval: 30s
|
|
||||||
timeout: 3s
|
|
||||||
retries: 3
|
|
||||||
start_period: 5s
|
|
||||||
read_only: true
|
read_only: true
|
||||||
tmpfs:
|
tmpfs:
|
||||||
# nginx-unprivileged writes pid + temp files under /tmp only.
|
# nginx-unprivileged writes pid + temp files under /tmp only.
|
||||||
|
|||||||
+7
-6
@@ -36,9 +36,15 @@ server {
|
|||||||
application/javascript
|
application/javascript
|
||||||
application/json
|
application/json
|
||||||
application/xml
|
application/xml
|
||||||
application/pdf
|
|
||||||
image/svg+xml;
|
image/svg+xml;
|
||||||
|
|
||||||
|
# Block access to dotfiles (defense-in-depth — none are shipped anyway).
|
||||||
|
# First regex location wins: keep this above the caching regex blocks so
|
||||||
|
# a hypothetical /.foo.html can't be served by them.
|
||||||
|
location ~ /\. {
|
||||||
|
return 404;
|
||||||
|
}
|
||||||
|
|
||||||
# Long cache for the PDF (regenerated rarely, content-hash not used).
|
# Long cache for the PDF (regenerated rarely, content-hash not used).
|
||||||
location ~* \.pdf$ {
|
location ~* \.pdf$ {
|
||||||
add_header Cache-Control "public, max-age=604800";
|
add_header Cache-Control "public, max-age=604800";
|
||||||
@@ -62,11 +68,6 @@ server {
|
|||||||
access_log /var/log/nginx/access.log;
|
access_log /var/log/nginx/access.log;
|
||||||
error_log /var/log/nginx/error.log warn;
|
error_log /var/log/nginx/error.log warn;
|
||||||
|
|
||||||
# Block access to dotfiles (defense-in-depth — none are shipped anyway).
|
|
||||||
location ~ /\. {
|
|
||||||
return 404;
|
|
||||||
}
|
|
||||||
|
|
||||||
# Default: serve files, fall back to 404.
|
# Default: serve files, fall back to 404.
|
||||||
location / {
|
location / {
|
||||||
try_files $uri $uri/ =404;
|
try_files $uri $uri/ =404;
|
||||||
|
|||||||
Reference in New Issue
Block a user