Files
whatsapp-api-mockup/nginx.conf
T

63 lines
2.0 KiB
Nginx Configuration File

# Servidor del sitio estático. Se copia a /etc/nginx/conf.d/default.conf.
# TLS lo termina Traefik (Coolify); aquí solo HTTP en el 80.
server {
listen 80;
server_name _;
root /usr/share/nginx/html;
index index.html;
charset utf-8;
server_tokens off;
# Compresión
gzip on;
gzip_vary on;
gzip_comp_level 5;
gzip_min_length 256;
gzip_proxied any;
gzip_types text/plain text/css text/xml application/javascript
application/json application/xml image/svg+xml;
# Cabeceras básicas de seguridad
add_header X-Content-Type-Options "nosniff" always;
add_header Referrer-Policy "strict-origin-when-cross-origin" always;
add_header X-Frame-Options "SAMEORIGIN" always;
# Healthcheck (Docker HEALTHCHECK / Coolify)
location = /healthz {
access_log off;
default_type text/plain;
return 200 "ok\n";
}
# HTML: siempre revalidar.
location = /index.html {
add_header Cache-Control "no-cache" always;
add_header X-Content-Type-Options "nosniff" always;
add_header Referrer-Policy "strict-origin-when-cross-origin" always;
add_header X-Frame-Options "SAMEORIGIN" always;
}
# CSS/JS con nombre fijo (sin hash): revalidar con ETag en cada carga.
# No usar "immutable": Cloudflare serviría la versión vieja tras un deploy.
location ~* \.(?:css|js)$ {
add_header Cache-Control "no-cache" always;
add_header X-Content-Type-Options "nosniff" always;
add_header Referrer-Policy "strict-origin-when-cross-origin" always;
add_header X-Frame-Options "SAMEORIGIN" always;
try_files $uri =404;
}
# Imágenes (docs/capturas): caché de 1 día, sin immutable.
location ~* \.(?:png|jpe?g|gif|webp|avif|svg|ico)$ {
add_header Cache-Control "public, max-age=86400" always;
add_header X-Content-Type-Options "nosniff" always;
access_log off;
try_files $uri =404;
}
location / {
try_files $uri $uri/ =404;
}
}