Dotfile location moved above caching regex locations (first match wins). application/pdf out of gzip_types (already flate-compressed). Compose healthcheck block removed — image HEALTHCHECK is the single source, inherited. Oracles: nginx -t, dotfiles 404, PDF no Content-Encoding, HTML still gzipped, headers 5/5, inherited health = healthy.
32 lines
883 B
YAML
32 lines
883 B
YAML
# docker-compose for bchanot.fr static site.
|
|
#
|
|
# Usage:
|
|
# cp .env.example .env
|
|
# # edit .env to set the host port (default 8080)
|
|
# docker compose up -d --build
|
|
#
|
|
# Host port is bound to 127.0.0.1 so the container is reachable only by a
|
|
# reverse proxy running on the same machine. Change to 0.0.0.0:${PORT} if
|
|
# you need LAN access for testing.
|
|
|
|
services:
|
|
bchanot-web:
|
|
build:
|
|
context: .
|
|
dockerfile: Dockerfile
|
|
image: bchanot-web:latest
|
|
container_name: bchanot-web
|
|
restart: unless-stopped
|
|
ports:
|
|
- "127.0.0.1:${PORT:-8080}:8080"
|
|
# Healthcheck inherited from the image HEALTHCHECK (Dockerfile) — do not
|
|
# redeclare here, one definition only.
|
|
read_only: true
|
|
tmpfs:
|
|
# nginx-unprivileged writes pid + temp files under /tmp only.
|
|
- /tmp
|
|
security_opt:
|
|
- no-new-privileges:true
|
|
cap_drop:
|
|
- ALL
|