# Nginx 設定

本頁說明 `config/nginx/nodes.conf` 的各路由區塊、圖片快取參數與安全標頭。

## 路由區塊

| location | 轉發 | 快取 | 備註 |
|---|---|---|---|
| `~ /\.` | — | — | `deny all`，擋下任何含 `/.` 的路徑（含回收桶） |
| `~* ^/c/img/` | `http://golang:8080` | `images_cache` | 讀寫逾時 120 秒 |
| `~* ^/upload/` | `http://golang:8080` | 不快取 | 預留註解掉的 `allow`／`deny` |
| `~* ^/del/` | `http://golang:8080` | 不快取 | 預留註解掉的 `allow`／`deny` |
| `/` | `http://golang:8080` | 不快取 | 其他路徑（含 `/check/state`） |

正規表示式 location 依出現順序比對，`~ /\.` 排在最前面，因此優先於 `/c/img/`。

## 圖片快取

| 指令 | 值 | 效果 |
|---|---|---|
| `proxy_cache_path` | `/var/cache/nginx/images`，`keys_zone=images_cache:10m`，`max_size=2g`，`inactive=30d` | 30 天未被存取即淘汰 |
| `proxy_cache_valid` | `200 302 301 304 7d`；`any 1m` | 成功回應 7 天，其他 1 分鐘 |
| `proxy_cache_use_stale` | `error timeout updating http_500 http_502 http_503 http_504` | 上游故障時回傳過期快取 |
| `proxy_cache_lock` | `on` | 同一 key 只有一個請求回源 |
| `proxy_cache_background_update` | `on` | 背景更新過期項目 |
| `add_header X-Cache-Status` | `$upstream_cache_status` | 觀察 HIT／MISS |

`/c/img/` 另以 `add_header Cache-Control "public, max-age=604800"` 與 `expires 7d` 加上快取標頭，會與 Go 服務送出的標頭並存。gzip 對圖片類型啟用（`gzip_comp_level 6`、`gzip_min_length 1000`）。

## 安全設定

| 項目 | 設定 |
|---|---|
| 上傳大小 | `client_max_body_size 100M` |
| HTTP 方法 | 非 `GET`／`HEAD`／`POST`／`DELETE`／`PUT`／`OPTIONS` 回 `444`（直接斷線） |
| 隱藏標頭 | `server_tokens off`，並隱藏 `X-Powered-By` 等上游標頭 |
| 安全標頭 | `X-Content-Type-Options`、`X-Frame-Options`、`X-XSS-Protection`、`Referrer-Policy`、`Permissions-Policy`、`Content-Security-Policy` |

## 啟用上傳與刪除白名單

Go 服務沒有驗證機制，對外部署前在 `/upload/` 與 `/del/` 區塊取消註解並填入允許的來源：

```nginx
location ~* ^/upload/ {
    allow 203.0.113.10;
    deny all;
    proxy_pass http://golang:8080;
}
```
