55 lines
1.6 KiB
Nginx Configuration File
55 lines
1.6 KiB
Nginx Configuration File
# nginx im Container "web" auf endeavour.
|
|
# TLS terminiert der KeyHelp-Webserver auf dem Host und reicht per Proxy an 127.0.0.1:8080 weiter.
|
|
|
|
# Echte Client-IP aus X-Forwarded-For übernehmen, aber nur von Docker-internen Adressen
|
|
# (der Proxy auf dem Host erreicht den Container über das Bridge-Gateway).
|
|
set_real_ip_from 10.0.0.0/8;
|
|
set_real_ip_from 172.16.0.0/12;
|
|
set_real_ip_from 192.168.0.0/16;
|
|
real_ip_header X-Forwarded-For;
|
|
real_ip_recursive on;
|
|
|
|
server {
|
|
listen 80 default_server;
|
|
server_name _;
|
|
|
|
root /var/www/html/public;
|
|
index index.php;
|
|
|
|
server_tokens off;
|
|
client_max_body_size 70m;
|
|
|
|
location / {
|
|
try_files $uri $uri/ /index.php?$query_string;
|
|
}
|
|
|
|
# Vite-Assets sind versioniert (Hash im Dateinamen) und dürfen lange gecacht werden.
|
|
location /build/assets/ {
|
|
expires 1y;
|
|
add_header Cache-Control "public, immutable";
|
|
access_log off;
|
|
try_files $uri =404;
|
|
}
|
|
|
|
location ~ \.php$ {
|
|
try_files $uri =404;
|
|
fastcgi_split_path_info ^(.+\.php)(/.+)$;
|
|
fastcgi_pass app:9000;
|
|
fastcgi_index index.php;
|
|
include fastcgi_params;
|
|
fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;
|
|
|
|
# Nach außen läuft alles über HTTPS (KeyHelp). So erzeugt Laravel https-URLs,
|
|
# ohne dass im App-Code trustProxies gesetzt werden muss.
|
|
fastcgi_param HTTPS on;
|
|
fastcgi_param REQUEST_SCHEME https;
|
|
fastcgi_param SERVER_PORT 443;
|
|
|
|
fastcgi_read_timeout 300;
|
|
}
|
|
|
|
location ~ /\.(?!well-known) {
|
|
deny all;
|
|
}
|
|
}
|