check / check (push) Successful in 21s
nginx sent none of the security headers REPO_POLICIES.md requires. security-headers.conf now sets all six with always, included at server level and again in /assets/, whose own add_header would otherwise drop them. nginx hides the copies netwatch-server sets, so /api/ and the health check carry each header once. The content security policy allows no inline script or style; the host row's status dot took its grey from a style attribute, now a class. connect-src is * because several probed hosts redirect to other hosts and the browser checks every redirect against it. Referrer-Policy is no-referrer, as the backend already sends. Model: opus-5-5
72 lines
2.5 KiB
Nginx Configuration File
72 lines
2.5 KiB
Nginx Configuration File
# A template: the nginx image renders it into conf.d at container start,
|
|
# filling in PORT and nothing else. bin/entrypoint.sh sets PORT and that
|
|
# limit.
|
|
server {
|
|
listen ${PORT};
|
|
server_name _;
|
|
|
|
# Keep the nginx version out of the Server header and error pages.
|
|
server_tokens off;
|
|
|
|
# The security headers, on every response. An add_header in a
|
|
# location drops every add_header from here, so a location with one
|
|
# of its own includes this file again.
|
|
include /etc/nginx/security-headers.conf;
|
|
|
|
root /usr/share/nginx/html;
|
|
index index.html;
|
|
|
|
# The client address comes from X-Forwarded-For only on a request
|
|
# from the reverse proxies in TRUSTED_PROXIES: bin/entrypoint.sh
|
|
# writes one set_real_ip_from line for each into this file, and
|
|
# leaves it empty when TRUSTED_PROXIES is unset, so that by default
|
|
# the client address is the one each request comes from.
|
|
include /etc/nginx/trusted-proxies.conf;
|
|
real_ip_header X-Forwarded-For;
|
|
real_ip_recursive on;
|
|
|
|
# Access log to stdout (Docker best practice)
|
|
access_log /dev/stdout combined;
|
|
error_log /dev/stderr warn;
|
|
|
|
location / {
|
|
try_files $uri $uri/ /index.html;
|
|
}
|
|
|
|
# Cache static assets aggressively
|
|
location /assets/ {
|
|
expires 1y;
|
|
add_header Cache-Control "public, immutable";
|
|
include /etc/nginx/security-headers.conf;
|
|
}
|
|
|
|
# netwatch-server, the Go backend, runs in the same container and
|
|
# listens on loopback only: bin/entrypoint.sh starts it on
|
|
# 127.0.0.1:8081. These headers go with every request passed to it.
|
|
# X-Forwarded-For carries only the client address, as resolved by
|
|
# the real IP settings above, and not the chain the request came
|
|
# with: the backend takes the first entry, which a client can write.
|
|
proxy_set_header Host $host;
|
|
proxy_set_header X-Real-IP $remote_addr;
|
|
proxy_set_header X-Forwarded-For $remote_addr;
|
|
proxy_set_header X-Forwarded-Proto $scheme;
|
|
|
|
# netwatch-server sets the same security headers on its own
|
|
# responses. Its copies are dropped so that each header goes out
|
|
# once, as security-headers.conf sets it.
|
|
proxy_hide_header Strict-Transport-Security;
|
|
proxy_hide_header Content-Security-Policy;
|
|
proxy_hide_header X-Frame-Options;
|
|
proxy_hide_header X-Content-Type-Options;
|
|
proxy_hide_header Referrer-Policy;
|
|
proxy_hide_header Permissions-Policy;
|
|
|
|
location /api/ {
|
|
proxy_pass http://127.0.0.1:8081;
|
|
}
|
|
|
|
location = /.well-known/healthcheck {
|
|
proxy_pass http://127.0.0.1:8081;
|
|
}
|
|
}
|