Files
ThothII/docker/nginx.conf.template

56 lines
2.1 KiB
Plaintext

server {
listen 8080;
server_name _;
root /usr/share/nginx/html;
location = /health {
proxy_pass ${THT_FRONTEND_API_UPSTREAM}/health;
proxy_http_version 1.1;
proxy_set_header Host $http_host;
proxy_cache off;
}
location /api/ {
# The trailing slash replaces the matched /api/ prefix before the private hop.
proxy_pass ${THT_FRONTEND_API_UPSTREAM}/;
proxy_http_version 1.1;
proxy_set_header Host $http_host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
# Public normalized claims are discarded by mapping only the private-hop values from the
# authenticated host proxy. Private-hop headers are then cleared before reaching core.
proxy_set_header X-Authenticated-User "";
proxy_set_header X-Thoth-Principal-Issuer $http_x_thoth_trusted_principal_issuer;
proxy_set_header X-Thoth-Principal-Subject $http_x_thoth_trusted_principal_subject;
proxy_set_header X-Thoth-Principal-Display-Name $http_x_thoth_trusted_principal_display_name;
proxy_set_header X-Thoth-Is-Admin $http_x_thoth_trusted_is_admin;
proxy_set_header X-Thoth-Trusted-Principal-Issuer "";
proxy_set_header X-Thoth-Trusted-Principal-Subject "";
proxy_set_header X-Thoth-Trusted-Principal-Display-Name "";
proxy_set_header X-Thoth-Trusted-Is-Admin "";
proxy_buffering off;
proxy_cache off;
proxy_read_timeout 3600s;
}
location = /index.html {
add_header Cache-Control "no-store, no-cache, must-revalidate" always;
try_files $uri =404;
}
location = /config.js {
add_header Cache-Control "no-store, no-cache, must-revalidate" always;
try_files $uri =404;
}
location ~* \.(js|css)$ {
add_header Cache-Control "public, max-age=31536000, immutable" always;
try_files $uri =404;
}
location / {
try_files $uri $uri/ /index.html;
}
}