nginx: listen on PORT, default 8080; server_tokens off (closes #26)
check / check (push) Successful in 11s

nginx.conf is now a template the nginx image renders into conf.d at
container start. bin/entrypoint.sh gives nginx PORT, 8080 when unset or
empty, and limits the rendering to PORT with NGINX_ENVSUBST_FILTER, so
$uri, $host and every other nginx variable pass through unchanged. A
PORT nginx cannot listen on stops the container non-zero.
server_tokens off drops the version from the Server header and error
pages. script/frontend-viewport-test renders the template the same way.
EXPOSE still documents 8080; the backend stays on 127.0.0.1:8081.

Model: opus-5-5
This commit is contained in:
2026-09-29 01:44:32 +00:00
parent bbcc7d921d
commit e0fa31341f
5 changed files with 27 additions and 5 deletions
+7 -2
View File
@@ -23,8 +23,13 @@ backend=$!
# nginx starts through the nginx image's own entrypoint, which applies
# the image's start-up configuration and then replaces itself with
# nginx.
/docker-entrypoint.sh nginx -g 'daemon off;' &
# nginx. Part of that start-up configuration renders nginx.conf into
# conf.d with nginx listening on PORT, the public port, 8080 unless
# set. NGINX_ENVSUBST_FILTER limits that rendering to PORT: a variable
# nginx itself uses, such as $uri, would otherwise be replaced by an
# environment variable of the same name.
PORT="${PORT:-8080}" NGINX_ENVSUBST_FILTER='^PORT$' \
/docker-entrypoint.sh nginx -g 'daemon off;' &
nginx=$!
running() {