fix(security): unprivileged nginx + security headers on every location
- base image -> nginxinc/nginx-unprivileged:1.28-alpine, digest-pinned (BREAKING for the docker path: container port 80 -> 8080; compose mapping/healthcheck updated in the same change, cap_add dropped) - nginx add_header inheritance fix: shared snippets file re-included in every location that sets Cache-Control -- previously ALL security headers were dropped on real responses (verified live before/after) - server_tokens off; set_real_ip_from restricted to 127.0.0.1 - expires directives removed (duplicated Cache-Control); gzip_types text/html redundancy removed (nginx -t warn)
This commit is contained in:
+10
-8
@@ -1,27 +1,29 @@
|
||||
# Static site for bchanot.fr
|
||||
# nginx:alpine serves index.html + CV (HTML + PDF).
|
||||
# nginx-unprivileged serves index.html + CV (HTML + PDF) as uid 101 —
|
||||
# no root master process in the container (tag + digest pinned).
|
||||
|
||||
FROM nginx:1.27-alpine
|
||||
FROM nginxinc/nginx-unprivileged:1.28-alpine@sha256:209331cfcaec00da781f5b8a38e0d1c0abd00cb2b51e6ad385a30abbbdb04e15
|
||||
|
||||
# Custom nginx config (gzip, cache, security headers).
|
||||
COPY nginx.conf /etc/nginx/conf.d/default.conf
|
||||
COPY nginx-security-headers.conf /etc/nginx/snippets/security-headers.conf
|
||||
|
||||
# Site assets.
|
||||
# Site assets — clean the default content, then copy ours.
|
||||
WORKDIR /usr/share/nginx/html
|
||||
USER root
|
||||
RUN rm -rf ./*
|
||||
USER nginx
|
||||
|
||||
COPY index.html ./
|
||||
COPY CV_Bastien_Chanot.html ./
|
||||
COPY CV_Bastien_Chanot.pdf ./
|
||||
COPY favicon.svg favicon-32.png favicon.ico apple-touch-icon.png ./
|
||||
|
||||
# Non-root hardening: nginx:alpine already drops privileges to "nginx" user
|
||||
# for worker processes. Master runs as root only to bind port 80 inside
|
||||
# the container — fine because the host port is the one exposed.
|
||||
EXPOSE 80
|
||||
# nginx-unprivileged listens on 8080 (>1024, no NET_BIND_SERVICE needed).
|
||||
EXPOSE 8080
|
||||
|
||||
# Basic healthcheck: nginx must serve index.html.
|
||||
HEALTHCHECK --interval=30s --timeout=3s --start-period=5s --retries=3 \
|
||||
CMD wget -qO- http://127.0.0.1/ >/dev/null || exit 1
|
||||
CMD wget -qO- http://127.0.0.1:8080/ >/dev/null || exit 1
|
||||
|
||||
CMD ["nginx", "-g", "daemon off;"]
|
||||
|
||||
Reference in New Issue
Block a user