feat: Docker images, compose stacks, nginx config, Gitea CI

- site image: multi-stage node build -> unprivileged nginx (non-root, read-only)
- nginx: CSP + security headers, immutable asset caching, revalidated HTML,
  canonical trailing slash, preserved /Linkedin 301, legacy-WP 410s, custom 404
- externalise theme-init so CSP uses script-src 'self' (no inline hash)
- prod + dev compose; .env.example; relay Dockerfile fixed (image ships app user)
- Gitea Actions: quality, e2e, lighthouse budgets, relay build, image push on main
- verified: both images build; relay healthz 200; site serves EN/NO with CSP + redirect

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
cesnimda
2026-07-04 06:21:35 +02:00
parent 033c9ec315
commit 9088dcffb9
11 changed files with 322 additions and 20 deletions
+8
View File
@@ -0,0 +1,8 @@
node_modules
dist
.astro
test
tests
.env
.env.*
*.log
+18
View File
@@ -0,0 +1,18 @@
# syntax=docker/dockerfile:1
# ---- build ----
FROM node:22-alpine AS build
WORKDIR /app
RUN corepack enable
COPY package.json pnpm-lock.yaml ./
RUN pnpm install --frozen-lockfile
COPY . .
ENV ASTRO_TELEMETRY_DISABLED=1
RUN pnpm build
# ---- runtime: static files behind unprivileged nginx (non-root, read-only capable) ----
FROM nginxinc/nginx-unprivileged:1.27-alpine AS final
COPY --chown=nginx:nginx nginx.conf /etc/nginx/conf.d/default.conf
COPY --from=build --chown=nginx:nginx /app/dist /usr/share/nginx/html
EXPOSE 8080
# runs as uid 101 (nginx) by default in this image
+20
View File
@@ -0,0 +1,20 @@
{
"ci": {
"collect": {
"staticDistDir": "./dist",
"url": ["http://localhost/index.html", "http://localhost/projects/jobtrack/index.html"],
"numberOfRuns": 1
},
"assert": {
"assertions": {
"categories:performance": ["error", { "minScore": 0.95 }],
"categories:accessibility": ["error", { "minScore": 1 }],
"categories:seo": ["error", { "minScore": 1 }],
"largest-contentful-paint": ["error", { "maxNumericValue": 1800 }],
"cumulative-layout-shift": ["error", { "maxNumericValue": 0.02 }],
"total-blocking-time": ["error", { "maxNumericValue": 100 }],
"unused-javascript": "off"
}
}
}
}
+71
View File
@@ -0,0 +1,71 @@
# Site nginx config (DOCKER_SPEC §1, ARCHITECTURE §6). Serves the static Astro build
# with security headers, immutable asset caching, revalidated HTML, canonical
# trailing slashes, the preserved /Linkedin redirect, and legacy-WP 410s.
server {
listen 8080;
server_name _;
root /usr/share/nginx/html;
index index.html;
charset utf-8;
sendfile on;
tcp_nopush on;
# --- Security headers (applied to document responses) ---
add_header Content-Security-Policy "default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; font-src 'self'; connect-src 'self'; form-action 'self'; base-uri 'self'; frame-ancestors 'none'; object-src 'none'; upgrade-insecure-requests" always;
add_header X-Content-Type-Options "nosniff" always;
add_header Referrer-Policy "strict-origin-when-cross-origin" always;
add_header Permissions-Policy "geolocation=(), microphone=(), camera=(), interest-cohort=()" always;
add_header X-Frame-Options "DENY" always;
add_header Cache-Control "no-cache" always;
# --- Compression ---
gzip on;
gzip_vary on;
gzip_min_length 256;
gzip_proxied any;
gzip_types text/plain text/css application/javascript application/json image/svg+xml application/xml application/xml+rss;
# --- Preserved LinkedIn redirect (printed on the CVs). Replace slug before cutover. ---
location = /Linkedin {
return 301 https://www.linkedin.com/in/REPLACE-WITH-REAL-SLUG/;
}
# --- Legacy WordPress URLs -> 410 Gone (crawler cleanup) ---
location ~* ^/(wp-admin|wp-login|wp-content|wp-includes|wp-json|xmlrpc\.php|feed|comments/feed) {
return 410;
}
# --- Immutable, content-hashed build assets ---
location /_astro/ {
expires 1y;
add_header Cache-Control "public, immutable" always;
}
# --- Other static media (moderate cache) ---
location ~* \.(?:woff2?|ttf|png|jpe?g|webp|avif|svg|ico)$ {
expires 30d;
add_header Cache-Control "public" always;
}
location = /theme-init.js {
expires 1h;
add_header Cache-Control "public" always;
}
# --- CVs update in place -> short cache so shared links fetch the newest ---
location /cv/ {
expires 1h;
add_header Cache-Control "public, must-revalidate" always;
}
# --- Canonical trailing slash for extensionless paths (SEO) ---
rewrite ^([^.]*[^/])$ $1/ permanent;
# --- HTML documents: revalidate so deploys are instant (inherits headers above) ---
location / {
try_files $uri $uri/ =404;
}
error_page 404 /404.html;
}
+18
View File
@@ -0,0 +1,18 @@
/*
No-flash theme init (external so a strict CSP can use script-src 'self' with no
inline hash). Loaded render-blocking in <head>, runs before first paint: marks
that JS is available (reveal animations are gated behind html.js) and applies the
stored or system theme. First visit follows the system; once set, the choice persists.
*/
(function () {
document.documentElement.classList.add('js');
try {
var t = localStorage.getItem('theme');
if (t !== 'light' && t !== 'dark') {
t = window.matchMedia('(prefers-color-scheme: light)').matches ? 'light' : 'dark';
}
document.documentElement.dataset.theme = t;
} catch (e) {
document.documentElement.dataset.theme = 'dark';
}
})();
+4 -19
View File
@@ -1,24 +1,9 @@
---
/*
No-flash theme init. Runs before paint, sets data-theme from stored preference
or system (ANIMATION_SPEC — the one permitted inline script; CSP-hashed at the
nginx layer). First visit follows the system; once set, the choice persists.
No-flash theme init. Loaded as an external, render-blocking script (served from
/theme-init.js) so a strict CSP can allow script-src 'self' without inline hashes.
Runs before first paint. See public/theme-init.js.
*/
---
<script is:inline>
(function () {
// Mark that JS is available; reveal animations are gated behind html.js so
// content stays visible without JavaScript.
document.documentElement.classList.add('js');
try {
let t = localStorage.getItem('theme');
if (t !== 'light' && t !== 'dark') {
t = window.matchMedia('(prefers-color-scheme: light)').matches ? 'light' : 'dark';
}
document.documentElement.dataset.theme = t;
} catch {
document.documentElement.dataset.theme = 'dark';
}
})();
</script>
<script is:inline src="/theme-init.js"></script>