Nginx 設定
本頁說明 config/nginx/nodes.conf 的各路由區塊、圖片快取參數與安全標頭。
路由區塊
| location | 轉發 | 快取 | 備註 |
|---|---|---|---|
~ /\. |
— | — | deny all,擋下任何含 /. 的路徑(含回收桶) |
~* ^/c/img/ |
http://golang:8080 |
images_cache |
讀寫逾時 120 秒 |
~* ^/upload/ |
http://golang:8080 |
不快取 | 預留註解掉的 allow/deny |
~* ^/del/ |
http://golang:8080 |
不快取 | 預留註解掉的 allow/deny |
/ |
http://golang:8080 |
不快取 | 其他路徑(含 /check/state) |
正規表示式 location 依出現順序比對,~ /\. 排在最前面,因此優先於 /c/img/。
圖片快取
| 指令 | 值 | 效果 |
|---|---|---|
proxy_cache_path |
/var/cache/nginx/images,keys_zone=images_cache:10m,max_size=2g,inactive=30d |
30 天未被存取即淘汰 |
proxy_cache_valid |
200 302 301 304 7d;any 1m |
成功回應 7 天,其他 1 分鐘 |
proxy_cache_use_stale |
error timeout updating http_500 http_502 http_503 http_504 |
上游故障時回傳過期快取 |
proxy_cache_lock |
on |
同一 key 只有一個請求回源 |
proxy_cache_background_update |
on |
背景更新過期項目 |
add_header X-Cache-Status |
$upstream_cache_status |
觀察 HIT/MISS |
/c/img/ 另以 add_header Cache-Control "public, max-age=604800" 與 expires 7d 加上快取標頭,會與 Go 服務送出的標頭並存。gzip 對圖片類型啟用(gzip_comp_level 6、gzip_min_length 1000)。
安全設定
| 項目 | 設定 |
|---|---|
| 上傳大小 | client_max_body_size 100M |
| HTTP 方法 | 非 GET/HEAD/POST/DELETE/PUT/OPTIONS 回 444(直接斷線) |
| 隱藏標頭 | server_tokens off,並隱藏 X-Powered-By 等上游標頭 |
| 安全標頭 | X-Content-Type-Options、X-Frame-Options、X-XSS-Protection、Referrer-Policy、Permissions-Policy、Content-Security-Policy |
啟用上傳與刪除白名單
Go 服務沒有驗證機制,對外部署前在 /upload/ 與 /del/ 區塊取消註解並填入允許的來源:
location ~* ^/upload/ {
allow 203.0.113.10;
deny all;
proxy_pass http://golang:8080;
}