nginx: listen on PORT, default 8080; server_tokens off (closes #26)
check / check (push) Successful in 15s
check / check (push) Successful in 15s
nginx.conf is now a template the nginx image renders into conf.d at container start. bin/entrypoint.sh sets PORT to 8080 when unset or empty, and stops with an error before starting anything when PORT is not digits only: nginx would take a value such as localhost or unix:/tmp/x.sock as an address and start anyway. NGINX_ENVSUBST_FILTER limits the rendering to PORT, so $uri, $host and every other nginx variable pass through unchanged. server_tokens off drops the version from the Server header and error pages. script/frontend-viewport-test renders the template the same way. EXPOSE still documents 8080; the backend stays on 127.0.0.1:8081. Model: opus-5-5
This commit was merged in pull request #65.
This commit is contained in:
@@ -23,6 +23,12 @@ latest run passes.
|
||||
|
||||
# Completed Steps
|
||||
|
||||
- 2026-09-29: nginx listens on `PORT` (issue #26), 8080 when unset or empty: the
|
||||
nginx image renders `nginx.conf` as a template at container start, filling in
|
||||
`PORT` and no other variable. `bin/entrypoint.sh` refuses to start when `PORT`
|
||||
is not digits only. `server_tokens off` keeps the nginx version out of
|
||||
responses. `script/frontend-viewport-test` renders the template the same way.
|
||||
Gzip and a `50x.html` error page are not added
|
||||
- 2026-09-29: bounded the report endpoint (issue #20): `POST /api/v1/reports`
|
||||
still needs no credentials, but each client address, as resolved through
|
||||
`TRUSTED_PROXIES`, may send `REPORTS_PER_MINUTE` (default 60) reports a
|
||||
|
||||
Reference in New Issue
Block a user