- base image -> nginxinc/nginx-unprivileged:1.28-alpine, digest-pinned (BREAKING for the docker path: container port 80 -> 8080; compose mapping/healthcheck updated in the same change, cap_add dropped) - nginx add_header inheritance fix: shared snippets file re-included in every location that sets Cache-Control -- previously ALL security headers were dropped on real responses (verified live before/after) - server_tokens off; set_real_ip_from restricted to 127.0.0.1 - expires directives removed (duplicated Cache-Control); gzip_types text/html redundancy removed (nginx -t warn)
36 lines
918 B
YAML
36 lines
918 B
YAML
# docker-compose for bchanot.fr static site.
|
|
#
|
|
# Usage:
|
|
# cp .env.example .env
|
|
# # edit .env to set the host port (default 8080)
|
|
# docker compose up -d --build
|
|
#
|
|
# Host port is bound to 127.0.0.1 so the container is reachable only by a
|
|
# reverse proxy running on the same machine. Change to 0.0.0.0:${PORT} if
|
|
# you need LAN access for testing.
|
|
|
|
services:
|
|
bchanot-web:
|
|
build:
|
|
context: .
|
|
dockerfile: Dockerfile
|
|
image: bchanot-web:latest
|
|
container_name: bchanot-web
|
|
restart: unless-stopped
|
|
ports:
|
|
- "127.0.0.1:${PORT:-8080}:8080"
|
|
healthcheck:
|
|
test: ["CMD", "wget", "-qO-", "http://127.0.0.1:8080/"]
|
|
interval: 30s
|
|
timeout: 3s
|
|
retries: 3
|
|
start_period: 5s
|
|
read_only: true
|
|
tmpfs:
|
|
# nginx-unprivileged writes pid + temp files under /tmp only.
|
|
- /tmp
|
|
security_opt:
|
|
- no-new-privileges:true
|
|
cap_drop:
|
|
- ALL
|