Documentation

Nginx

This page covers the routing blocks, image cache settings, and security headers in config/nginx/nodes.conf.

Routing Blocks

location Upstream Cache Notes
~ /\. — — deny all; blocks any path containing /. (including the trash)
~* ^/c/img/ http://golang:8080 images_cache 120-second read / send timeouts
~* ^/upload/ http://golang:8080 None Commented-out allow / deny
~* ^/del/ http://golang:8080 None Commented-out allow / deny
/ http://golang:8080 None Everything else (including /check/state)

Regex locations match in order of appearance, and ~ /\. comes first, so it wins over /c/img/.

Image Cache

Directive Value Effect
proxy_cache_path /var/cache/nginx/images, keys_zone=images_cache:10m, max_size=2g, inactive=30d Evicted after 30 days without access
proxy_cache_valid 200 302 301 304 7d; any 1m 7 days for success, 1 minute otherwise
proxy_cache_use_stale error timeout updating http_500 http_502 http_503 http_504 Serve stale entries when the upstream fails
proxy_cache_lock on Only one request per key goes upstream
proxy_cache_background_update on Refresh stale entries in the background
add_header X-Cache-Status $upstream_cache_status Shows HIT / MISS

/c/img/ also adds add_header Cache-Control "public, max-age=604800" and expires 7d, which coexist with the headers the Go service sends. gzip is enabled for image types (gzip_comp_level 6, gzip_min_length 1000).

Security Settings

Item Setting
Upload size client_max_body_size 100M
HTTP methods Anything other than GET / HEAD / POST / DELETE / PUT / OPTIONS returns 444 (connection closed)
Hidden headers server_tokens off, plus upstream headers such as X-Powered-By
Security headers X-Content-Type-Options, X-Frame-Options, X-XSS-Protection, Referrer-Policy, Permissions-Policy, Content-Security-Policy

Enabling the Upload and Delete Allowlist

The Go service has no authentication; before exposing it, uncomment the rules in the /upload/ and /del/ blocks and list the allowed sources:

location ~* ^/upload/ {
    allow 203.0.113.10;
    deny all;
    proxy_pass http://golang:8080;
}
中文