Nginx

Last updated

This page covers the routing blocks, caching, and security headers in config/nginx/nodejs.conf, and how to restrict upload and delete by source IP.

Routing Blocks

location Upstream Behavior
~ /\. — deny all; rejects any path containing /. (including .trash)
~* ^/c/img/ http://nodejs:8080 proxy_cache enabled, 120-second timeouts
~* ^/upload/ http://nodejs:3000 proxy_no_cache 1, proxy_cache_bypass 1
~* ^/del/ http://nodejs:3000 Not cached
/ http://nodejs:3000 Not cached

In the default config /upload/, /del/, and / point to 3000 while NODE_PORT is 8080. Align them, or these paths return 502 through Nginx.

Caching

Directive Value
proxy_cache_path /var/cache/nginx/images, levels=1:2, keys_zone=images_cache:10m, max_size=2g, inactive=30d
proxy_cache_valid 200 302 301 304 for 7 days, everything else 1 minute
proxy_cache_use_stale error timeout updating http_500 http_502 http_503 http_504
proxy_cache_lock, proxy_cache_revalidate, proxy_cache_background_update on
Response headers X-Cache-Status, Cache-Control: public, max-age=604800, expires 7d
gzip image/webp image/jpeg image/png image/svg+xml image/avif application/pdf, level 6, minimum 1000 bytes
# Check cache status (HIT / MISS / EXPIRED)
curl -sI "http://localhost:8080/c/img/blog/a.jpg?w=800" | grep -i x-cache-status

Security Settings

Setting Value
server_tokens off, plus proxy_hide_header for X-Powered-By and other framework headers
HTTP methods Anything other than GET HEAD POST DELETE PUT OPTIONS returns 444
Upload size client_max_body_size 100M
server-level headers X-Content-Type-Options, X-Frame-Options, X-XSS-Protection, Referrer-Policy, Permissions-Policy, Content-Security-Policy
/c/img/ headers Only X-Content-Type-Options and X-Frame-Options: once a location uses add_header, server-level add_header directives are not inherited

Restrict Upload and Delete

The app has no authentication. The /upload/ and /del/ blocks already contain commented lines; uncomment them and use your own internal network:

location ~* ^/upload/ {
    allow 10.0.0.0/8;
    deny all;

    proxy_pass http://nodejs:8080;
    # ...
}

Reload after editing:

docker compose exec nginx nginx -s reload
中文