feat: Docker images, compose stacks, nginx config, Gitea CI
- site image: multi-stage node build -> unprivileged nginx (non-root, read-only) - nginx: CSP + security headers, immutable asset caching, revalidated HTML, canonical trailing slash, preserved /Linkedin 301, legacy-WP 410s, custom 404 - externalise theme-init so CSP uses script-src 'self' (no inline hash) - prod + dev compose; .env.example; relay Dockerfile fixed (image ships app user) - Gitea Actions: quality, e2e, lighthouse budgets, relay build, image push on main - verified: both images build; relay healthz 200; site serves EN/NO with CSP + redirect Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
@@ -0,0 +1,71 @@
|
||||
# Site nginx config (DOCKER_SPEC §1, ARCHITECTURE §6). Serves the static Astro build
|
||||
# with security headers, immutable asset caching, revalidated HTML, canonical
|
||||
# trailing slashes, the preserved /Linkedin redirect, and legacy-WP 410s.
|
||||
|
||||
server {
|
||||
listen 8080;
|
||||
server_name _;
|
||||
root /usr/share/nginx/html;
|
||||
index index.html;
|
||||
|
||||
charset utf-8;
|
||||
sendfile on;
|
||||
tcp_nopush on;
|
||||
|
||||
# --- Security headers (applied to document responses) ---
|
||||
add_header Content-Security-Policy "default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; font-src 'self'; connect-src 'self'; form-action 'self'; base-uri 'self'; frame-ancestors 'none'; object-src 'none'; upgrade-insecure-requests" always;
|
||||
add_header X-Content-Type-Options "nosniff" always;
|
||||
add_header Referrer-Policy "strict-origin-when-cross-origin" always;
|
||||
add_header Permissions-Policy "geolocation=(), microphone=(), camera=(), interest-cohort=()" always;
|
||||
add_header X-Frame-Options "DENY" always;
|
||||
add_header Cache-Control "no-cache" always;
|
||||
|
||||
# --- Compression ---
|
||||
gzip on;
|
||||
gzip_vary on;
|
||||
gzip_min_length 256;
|
||||
gzip_proxied any;
|
||||
gzip_types text/plain text/css application/javascript application/json image/svg+xml application/xml application/xml+rss;
|
||||
|
||||
# --- Preserved LinkedIn redirect (printed on the CVs). Replace slug before cutover. ---
|
||||
location = /Linkedin {
|
||||
return 301 https://www.linkedin.com/in/REPLACE-WITH-REAL-SLUG/;
|
||||
}
|
||||
|
||||
# --- Legacy WordPress URLs -> 410 Gone (crawler cleanup) ---
|
||||
location ~* ^/(wp-admin|wp-login|wp-content|wp-includes|wp-json|xmlrpc\.php|feed|comments/feed) {
|
||||
return 410;
|
||||
}
|
||||
|
||||
# --- Immutable, content-hashed build assets ---
|
||||
location /_astro/ {
|
||||
expires 1y;
|
||||
add_header Cache-Control "public, immutable" always;
|
||||
}
|
||||
|
||||
# --- Other static media (moderate cache) ---
|
||||
location ~* \.(?:woff2?|ttf|png|jpe?g|webp|avif|svg|ico)$ {
|
||||
expires 30d;
|
||||
add_header Cache-Control "public" always;
|
||||
}
|
||||
location = /theme-init.js {
|
||||
expires 1h;
|
||||
add_header Cache-Control "public" always;
|
||||
}
|
||||
|
||||
# --- CVs update in place -> short cache so shared links fetch the newest ---
|
||||
location /cv/ {
|
||||
expires 1h;
|
||||
add_header Cache-Control "public, must-revalidate" always;
|
||||
}
|
||||
|
||||
# --- Canonical trailing slash for extensionless paths (SEO) ---
|
||||
rewrite ^([^.]*[^/])$ $1/ permanent;
|
||||
|
||||
# --- HTML documents: revalidate so deploys are instant (inherits headers above) ---
|
||||
location / {
|
||||
try_files $uri $uri/ =404;
|
||||
}
|
||||
|
||||
error_page 404 /404.html;
|
||||
}
|
||||
Reference in New Issue
Block a user