fix(nginx+compose): dotfile block first, no pdf gzip, single healthcheck (tour J4/N4/J5)

Dotfile location moved above caching regex locations (first match wins).
application/pdf out of gzip_types (already flate-compressed). Compose
healthcheck block removed — image HEALTHCHECK is the single source,
inherited. Oracles: nginx -t, dotfiles 404, PDF no Content-Encoding,
HTML still gzipped, headers 5/5, inherited health = healthy.
This commit is contained in:
Bastien Chanot
2026-07-06 01:06:54 +02:00
parent a589b99878
commit 84288c5c58
2 changed files with 9 additions and 12 deletions
+2 -6
View File
@@ -19,12 +19,8 @@ services:
restart: unless-stopped restart: unless-stopped
ports: ports:
- "127.0.0.1:${PORT:-8080}:8080" - "127.0.0.1:${PORT:-8080}:8080"
healthcheck: # Healthcheck inherited from the image HEALTHCHECK (Dockerfile) — do not
test: ["CMD", "wget", "-qO-", "http://127.0.0.1:8080/"] # redeclare here, one definition only.
interval: 30s
timeout: 3s
retries: 3
start_period: 5s
read_only: true read_only: true
tmpfs: tmpfs:
# nginx-unprivileged writes pid + temp files under /tmp only. # nginx-unprivileged writes pid + temp files under /tmp only.
+7 -6
View File
@@ -36,9 +36,15 @@ server {
application/javascript application/javascript
application/json application/json
application/xml application/xml
application/pdf
image/svg+xml; image/svg+xml;
# Block access to dotfiles (defense-in-depth — none are shipped anyway).
# First regex location wins: keep this above the caching regex blocks so
# a hypothetical /.foo.html can't be served by them.
location ~ /\. {
return 404;
}
# Long cache for the PDF (regenerated rarely, content-hash not used). # Long cache for the PDF (regenerated rarely, content-hash not used).
location ~* \.pdf$ { location ~* \.pdf$ {
add_header Cache-Control "public, max-age=604800"; add_header Cache-Control "public, max-age=604800";
@@ -62,11 +68,6 @@ server {
access_log /var/log/nginx/access.log; access_log /var/log/nginx/access.log;
error_log /var/log/nginx/error.log warn; error_log /var/log/nginx/error.log warn;
# Block access to dotfiles (defense-in-depth — none are shipped anyway).
location ~ /\. {
return 404;
}
# Default: serve files, fall back to 404. # Default: serve files, fall back to 404.
location / { location / {
try_files $uri $uri/ =404; try_files $uri $uri/ =404;