Nginx
最後更新
本頁說明 config/nginx/nodejs.conf 的路由區塊、快取設定、安全標頭,以及如何限制上傳與刪除的來源 IP。
路由區塊
location |
上游 | 行為 |
|---|---|---|
~ /\. |
— | deny all,拒絕任何含 /. 的路徑(含 .trash) |
~* ^/c/img/ |
http://nodejs:8080 |
啟用 proxy_cache,逾時 120 秒 |
~* ^/upload/ |
http://nodejs:3000 |
proxy_no_cache 1、proxy_cache_bypass 1 |
~* ^/del/ |
http://nodejs:3000 |
不快取 |
/ |
http://nodejs:3000 |
不快取 |
快取設定
| 指令 | 值 |
|---|---|
proxy_cache_path |
/var/cache/nginx/images,levels=1:2,keys_zone=images_cache:10m,max_size=2g,inactive=30d |
proxy_cache_valid |
200 302 301 304 7 天,其他 1 分鐘 |
proxy_cache_use_stale |
error timeout updating http_500 http_502 http_503 http_504 |
proxy_cache_lock、proxy_cache_revalidate、proxy_cache_background_update |
on |
| 回應標頭 | X-Cache-Status、Cache-Control: public, max-age=604800、expires 7d |
| gzip | image/webp image/jpeg image/png image/svg+xml image/avif application/pdf,等級 6,最小 1000 bytes |
# 檢查快取命中(HIT / MISS / EXPIRED)
curl -sI "http://localhost:8080/c/img/blog/a.jpg?w=800" | grep -i x-cache-status
安全設定
| 設定 | 值 |
|---|---|
server_tokens |
off,並以 proxy_hide_header 隱藏 X-Powered-By 等框架標頭 |
| HTTP 方法 | GET HEAD POST DELETE PUT OPTIONS 以外回 444 |
| 上傳大小 | client_max_body_size 100M |
server 層標頭 |
X-Content-Type-Options、X-Frame-Options、X-XSS-Protection、Referrer-Policy、Permissions-Policy、Content-Security-Policy |
限制上傳與刪除的來源
/upload/ 與 /del/ 區塊內已預留註解,取消註解並改成自己的內網 IP:
location ~* ^/upload/ {
allow 10.0.0.0/8;
deny all;
proxy_pass http://nodejs:8080;
# ...
}
修改後重新載入:
docker compose exec nginx nginx -s reload