# Nginx

This page covers the routing blocks, image cache settings, and security headers in `config/nginx/nodes.conf`.

## Routing Blocks

| location | Upstream | Cache | Notes |
|---|---|---|---|
| `~ /\.` | — | — | `deny all`; blocks any path containing `/.` (including the trash) |
| `~* ^/c/img/` | `http://golang:8080` | `images_cache` | 120-second read / send timeouts |
| `~* ^/upload/` | `http://golang:8080` | None | Commented-out `allow` / `deny` |
| `~* ^/del/` | `http://golang:8080` | None | Commented-out `allow` / `deny` |
| `/` | `http://golang:8080` | None | Everything else (including `/check/state`) |

Regex locations match in order of appearance, and `~ /\.` comes first, so it wins over `/c/img/`.

## Image Cache

| Directive | Value | Effect |
|---|---|---|
| `proxy_cache_path` | `/var/cache/nginx/images`, `keys_zone=images_cache:10m`, `max_size=2g`, `inactive=30d` | Evicted after 30 days without access |
| `proxy_cache_valid` | `200 302 301 304 7d`; `any 1m` | 7 days for success, 1 minute otherwise |
| `proxy_cache_use_stale` | `error timeout updating http_500 http_502 http_503 http_504` | Serve stale entries when the upstream fails |
| `proxy_cache_lock` | `on` | Only one request per key goes upstream |
| `proxy_cache_background_update` | `on` | Refresh stale entries in the background |
| `add_header X-Cache-Status` | `$upstream_cache_status` | Shows HIT / MISS |

`/c/img/` also adds `add_header Cache-Control "public, max-age=604800"` and `expires 7d`, which coexist with the headers the Go service sends. gzip is enabled for image types (`gzip_comp_level 6`, `gzip_min_length 1000`).

## Security Settings

| Item | Setting |
|---|---|
| Upload size | `client_max_body_size 100M` |
| HTTP methods | Anything other than `GET` / `HEAD` / `POST` / `DELETE` / `PUT` / `OPTIONS` returns `444` (connection closed) |
| Hidden headers | `server_tokens off`, plus upstream headers such as `X-Powered-By` |
| Security headers | `X-Content-Type-Options`, `X-Frame-Options`, `X-XSS-Protection`, `Referrer-Policy`, `Permissions-Policy`, `Content-Security-Policy` |

## Enabling the Upload and Delete Allowlist

The Go service has no authentication; before exposing it, uncomment the rules in the `/upload/` and `/del/` blocks and list the allowed sources:

```nginx
location ~* ^/upload/ {
    allow 203.0.113.10;
    deny all;
    proxy_pass http://golang:8080;
}
```
