Nginx
This page covers the routing blocks, image cache settings, and security headers in config/nginx/nodes.conf.
Routing Blocks
| location | Upstream | Cache | Notes |
|---|---|---|---|
~ /\. |
— | — | deny all; blocks any path containing /. (including the trash) |
~* ^/c/img/ |
http://golang:8080 |
images_cache |
120-second read / send timeouts |
~* ^/upload/ |
http://golang:8080 |
None | Commented-out allow / deny |
~* ^/del/ |
http://golang:8080 |
None | Commented-out allow / deny |
/ |
http://golang:8080 |
None | Everything else (including /check/state) |
Regex locations match in order of appearance, and ~ /\. comes first, so it wins over /c/img/.
Image Cache
| Directive | Value | Effect |
|---|---|---|
proxy_cache_path |
/var/cache/nginx/images, keys_zone=images_cache:10m, max_size=2g, inactive=30d |
Evicted after 30 days without access |
proxy_cache_valid |
200 302 301 304 7d; any 1m |
7 days for success, 1 minute otherwise |
proxy_cache_use_stale |
error timeout updating http_500 http_502 http_503 http_504 |
Serve stale entries when the upstream fails |
proxy_cache_lock |
on |
Only one request per key goes upstream |
proxy_cache_background_update |
on |
Refresh stale entries in the background |
add_header X-Cache-Status |
$upstream_cache_status |
Shows HIT / MISS |
/c/img/ also adds add_header Cache-Control "public, max-age=604800" and expires 7d, which coexist with the headers the Go service sends. gzip is enabled for image types (gzip_comp_level 6, gzip_min_length 1000).
Security Settings
| Item | Setting |
|---|---|
| Upload size | client_max_body_size 100M |
| HTTP methods | Anything other than GET / HEAD / POST / DELETE / PUT / OPTIONS returns 444 (connection closed) |
| Hidden headers | server_tokens off, plus upstream headers such as X-Powered-By |
| Security headers | X-Content-Type-Options, X-Frame-Options, X-XSS-Protection, Referrer-Policy, Permissions-Policy, Content-Security-Policy |
Enabling the Upload and Delete Allowlist
The Go service has no authentication; before exposing it, uncomment the rules in the /upload/ and /del/ blocks and list the allowed sources:
location ~* ^/upload/ {
allow 203.0.113.10;
deny all;
proxy_pass http://golang:8080;
}