Nginx
Last updated
This page covers the routing blocks, caching, and security headers in config/nginx/nodejs.conf, and how to restrict upload and delete by source IP.
Routing Blocks
location |
Upstream | Behavior |
|---|---|---|
~ /\. |
— | deny all; rejects any path containing /. (including .trash) |
~* ^/c/img/ |
http://nodejs:8080 |
proxy_cache enabled, 120-second timeouts |
~* ^/upload/ |
http://nodejs:3000 |
proxy_no_cache 1, proxy_cache_bypass 1 |
~* ^/del/ |
http://nodejs:3000 |
Not cached |
/ |
http://nodejs:3000 |
Not cached |
In the default config
/upload/,/del/, and/point to3000whileNODE_PORTis8080. Align them, or these paths return502through Nginx.
Caching
| Directive | Value |
|---|---|
proxy_cache_path |
/var/cache/nginx/images, levels=1:2, keys_zone=images_cache:10m, max_size=2g, inactive=30d |
proxy_cache_valid |
200 302 301 304 for 7 days, everything else 1 minute |
proxy_cache_use_stale |
error timeout updating http_500 http_502 http_503 http_504 |
proxy_cache_lock, proxy_cache_revalidate, proxy_cache_background_update |
on |
| Response headers | X-Cache-Status, Cache-Control: public, max-age=604800, expires 7d |
| gzip | image/webp image/jpeg image/png image/svg+xml image/avif application/pdf, level 6, minimum 1000 bytes |
# Check cache status (HIT / MISS / EXPIRED)
curl -sI "http://localhost:8080/c/img/blog/a.jpg?w=800" | grep -i x-cache-status
Security Settings
| Setting | Value |
|---|---|
server_tokens |
off, plus proxy_hide_header for X-Powered-By and other framework headers |
| HTTP methods | Anything other than GET HEAD POST DELETE PUT OPTIONS returns 444 |
| Upload size | client_max_body_size 100M |
server-level headers |
X-Content-Type-Options, X-Frame-Options, X-XSS-Protection, Referrer-Policy, Permissions-Policy, Content-Security-Policy |
/c/img/ headers |
Only X-Content-Type-Options and X-Frame-Options: once a location uses add_header, server-level add_header directives are not inherited |
Restrict Upload and Delete
The app has no authentication. The /upload/ and /del/ blocks already contain commented lines; uncomment them and use your own internal network:
location ~* ^/upload/ {
allow 10.0.0.0/8;
deny all;
proxy_pass http://nodejs:8080;
# ...
}
Reload after editing:
docker compose exec nginx nginx -s reload