# A template: the nginx image renders it into conf.d at container start, # filling in PORT and nothing else. bin/entrypoint.sh sets PORT and that # limit. server { listen ${PORT}; server_name _; # Keep the nginx version out of the Server header and error pages. server_tokens off; root /usr/share/nginx/html; index index.html; # Trust RFC1918 reverse proxies for X-Forwarded-For set_real_ip_from 10.0.0.0/8; set_real_ip_from 172.16.0.0/12; set_real_ip_from 192.168.0.0/16; real_ip_header X-Forwarded-For; real_ip_recursive on; # Access log to stdout (Docker best practice) access_log /dev/stdout combined; error_log /dev/stderr warn; location / { try_files $uri $uri/ /index.html; } # Cache static assets aggressively location /assets/ { expires 1y; add_header Cache-Control "public, immutable"; } # netwatch-server, the Go backend, runs in the same container and # listens on loopback only: bin/entrypoint.sh starts it on # 127.0.0.1:8081. These headers go with every request passed to it. # X-Forwarded-For carries only the client address, as resolved by # the real IP settings above, and not the chain the request came # with: the backend takes the first entry, which a client can write. proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $remote_addr; proxy_set_header X-Forwarded-Proto $scheme; location /api/ { proxy_pass http://127.0.0.1:8081; } location = /.well-known/healthcheck { proxy_pass http://127.0.0.1:8081; } }