63 lines
2.0 KiB
Nginx Configuration File
63 lines
2.0 KiB
Nginx Configuration File
# Servidor del sitio estático. Se copia a /etc/nginx/conf.d/default.conf.
|
|
# TLS lo termina Traefik (Coolify); aquí solo HTTP en el 80.
|
|
server {
|
|
listen 80;
|
|
server_name _;
|
|
|
|
root /usr/share/nginx/html;
|
|
index index.html;
|
|
charset utf-8;
|
|
server_tokens off;
|
|
|
|
# Compresión
|
|
gzip on;
|
|
gzip_vary on;
|
|
gzip_comp_level 5;
|
|
gzip_min_length 256;
|
|
gzip_proxied any;
|
|
gzip_types text/plain text/css text/xml application/javascript
|
|
application/json application/xml image/svg+xml;
|
|
|
|
# Cabeceras básicas de seguridad
|
|
add_header X-Content-Type-Options "nosniff" always;
|
|
add_header Referrer-Policy "strict-origin-when-cross-origin" always;
|
|
add_header X-Frame-Options "SAMEORIGIN" always;
|
|
|
|
# Healthcheck (Docker HEALTHCHECK / Coolify)
|
|
location = /healthz {
|
|
access_log off;
|
|
default_type text/plain;
|
|
return 200 "ok\n";
|
|
}
|
|
|
|
# HTML: siempre revalidar.
|
|
location = /index.html {
|
|
add_header Cache-Control "no-cache" always;
|
|
add_header X-Content-Type-Options "nosniff" always;
|
|
add_header Referrer-Policy "strict-origin-when-cross-origin" always;
|
|
add_header X-Frame-Options "SAMEORIGIN" always;
|
|
}
|
|
|
|
# CSS/JS con nombre fijo (sin hash): revalidar con ETag en cada carga.
|
|
# No usar "immutable": Cloudflare serviría la versión vieja tras un deploy.
|
|
location ~* \.(?:css|js)$ {
|
|
add_header Cache-Control "no-cache" always;
|
|
add_header X-Content-Type-Options "nosniff" always;
|
|
add_header Referrer-Policy "strict-origin-when-cross-origin" always;
|
|
add_header X-Frame-Options "SAMEORIGIN" always;
|
|
try_files $uri =404;
|
|
}
|
|
|
|
# Imágenes (docs/capturas): caché de 1 día, sin immutable.
|
|
location ~* \.(?:png|jpe?g|gif|webp|avif|svg|ico)$ {
|
|
add_header Cache-Control "public, max-age=86400" always;
|
|
add_header X-Content-Type-Options "nosniff" always;
|
|
access_log off;
|
|
try_files $uri =404;
|
|
}
|
|
|
|
location / {
|
|
try_files $uri $uri/ =404;
|
|
}
|
|
}
|