Commit Graph
5 Commits
Author SHA1 Message Date
Bastien Chanot 84288c5c58 fix(nginx+compose): dotfile block first, no pdf gzip, single healthcheck (tour J4/N4/J5)
Dotfile location moved above caching regex locations (first match wins).
application/pdf out of gzip_types (already flate-compressed). Compose
healthcheck block removed — image HEALTHCHECK is the single source,
inherited. Oracles: nginx -t, dotfiles 404, PDF no Content-Encoding,
HTML still gzipped, headers 5/5, inherited health = healthy.
2026-07-06 01:06:54 +02:00
Bastien Chanot 613bfc0d49 chore(clean): dedup CV/index CSS, drop dead directives (tour F1-F8)
CV: shared block for xp/project/edu headers + date chips + roles + tags,
2 identical inline style attrs -> .inline-link class, no-op body margin/
padding removed, stray blank collapsed. Proven behavior-preserving: PDF
text-hash + per-page render-hash + full byte-identity vs committed PDF.
index: .stack-note/.theme-list code grouped, 2 no-op .formation overrides
removed. nginx.conf: dead 'deny all' after return 404 removed (nginx -t +
dotfile-404 oracle PASS). .dockerignore: phantom nginx.conf.bak entry.
Snippet comment: CV style attrs no longer exist. CSP hash unchanged.
2026-07-05 22:52:39 +02:00
Bastien Chanot ba13d697a5 fix(security): unprivileged nginx + security headers on every location
- base image -> nginxinc/nginx-unprivileged:1.28-alpine, digest-pinned
  (BREAKING for the docker path: container port 80 -> 8080; compose
  mapping/healthcheck updated in the same change, cap_add dropped)
- nginx add_header inheritance fix: shared snippets file re-included in
  every location that sets Cache-Control -- previously ALL security
  headers were dropped on real responses (verified live before/after)
- server_tokens off; set_real_ip_from restricted to 127.0.0.1
- expires directives removed (duplicated Cache-Control); gzip_types
  text/html redundancy removed (nginx -t warn)
2026-07-05 14:10:55 +02:00
Bastien ChanotandClaude Opus 4.7 f1e4392c65 fix(docker): COPY favicon assets into image + cache header
Dockerfile selectively COPYs files into /usr/share/nginx/html. Favicon
assets (favicon.svg, favicon-32.png, favicon.ico, apple-touch-icon.png)
were added to the repo in ef31fb3 but never wired into the Dockerfile,
so a rebuilt container served 404 for /favicon.svg and friends — broken
favicon in prod even after `docker compose up -d --build`.

nginx.conf gets a matching long-cache rule for icon/image assets
(30 days, immutable, access_log off) — they rarely change and the file
name is the cache key anyway.

Deploy: on the VPS, `docker compose up -d --build`.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-17 04:07:32 +02:00
bastienandClaude Opus 4.7 7957b04de0 feat(docker): containerize site with configurable host port
Add Dockerfile (nginx:1.27-alpine), nginx.conf (gzip, cache, CSP and
security headers, no HSTS — left to outer proxy), and docker-compose
service `bchanot-web`. Host port is configurable via PORT env var
(default 8080) and bound to 127.0.0.1 so the container sits behind a
reverse proxy. Container hardened with read_only fs, cap_drop ALL,
no-new-privileges, and tmpfs for nginx runtime dirs. Healthcheck via
wget on /. Also adds .dockerignore and .env.example, and ignores .env.

Usage:
  cp .env.example .env
  docker compose up -d --build

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-15 16:53:20 +02:00