c0c99a9672
The server still never sees a photo, so the model has to run in the page. Real-ESRGAN x4v3 ships as a 4.9MB ONNX in public/models and is loaded lazily on the first export that actually needs it; the wasm runtime is copied next to CanvasKit at build time and stays lazily fetched, cached for 30 days. Vite is told onnxruntime-web is external-wasm so no 28MB asset lands in the bundle. UNCHANGED keeps the old path and the tier cap; 2K/4K/custom upscale only when the request is larger than the photo being edited, otherwise they resize down. Guests keep UNCHANGED and 2K. Tiling is 256px with an 8px overlap, so memory follows the target size rather than four times it.
66 lines
2.6 KiB
Nginx Configuration File
66 lines
2.6 KiB
Nginx Configuration File
# Static SPA + API proxy. TLS/domain are terminated outside (Nginx Proxy
|
|
# Manager), so this container only ever speaks plain HTTP on port 80.
|
|
server {
|
|
listen 80;
|
|
server_name _;
|
|
root /usr/share/nginx/html;
|
|
index index.html;
|
|
|
|
# Static only, plus the API proxy below; a stricter CSP needs a per-app tune
|
|
# (canvas wasm, the QR image host) and belongs here once it is done.
|
|
add_header X-Content-Type-Options "nosniff" always;
|
|
add_header X-Frame-Options "DENY" always;
|
|
add_header Referrer-Policy "strict-origin-when-cross-origin" always;
|
|
|
|
gzip on;
|
|
gzip_comp_level 5;
|
|
gzip_min_length 1024;
|
|
gzip_types text/css application/javascript application/json application/wasm image/svg+xml;
|
|
|
|
# nginx's stock mime.types has no .mjs, and the browser refuses to run a module
|
|
# the server hands over as octet-stream: onnxruntime's glue is one of those.
|
|
# First match wins among regex locations, so this one stands before the
|
|
# /wasm/ block that would otherwise swallow the file.
|
|
location ~* \.mjs$ {
|
|
types { application/javascript mjs; }
|
|
expires 30d;
|
|
add_header Cache-Control "public, immutable";
|
|
try_files $uri =404;
|
|
}
|
|
|
|
# canvas.wasm is ~8MB and the super-resolution model is ~5MB: immutable, hashed
|
|
# or not, they never change under a given build. Fonts and the wall-frame
|
|
# artwork are likewise static.
|
|
location ~* ^/(wasm|models|assets)/ {
|
|
expires 30d;
|
|
add_header Cache-Control "public, immutable";
|
|
try_files $uri =404;
|
|
}
|
|
|
|
location /api/ {
|
|
# Resolved per request through Docker's embedded DNS, so the frontend can
|
|
# start before the API container without nginx refusing to boot.
|
|
resolver 127.0.0.11 valid=10s ipv6=off;
|
|
set $api_upstream http://api:3000;
|
|
proxy_pass $api_upstream$request_uri;
|
|
proxy_http_version 1.1;
|
|
# $http_host, not $host: keep the port when the visitor hits this container
|
|
# directly (localhost:8090), since the API builds the verification link from
|
|
# the forwarded host.
|
|
proxy_set_header Host $http_host;
|
|
proxy_set_header X-Real-IP $remote_addr;
|
|
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
|
# Hand the API the scheme the visitor actually used (TLS is terminated by
|
|
# Nginx Proxy Manager in front of this container) so it can mark the session
|
|
# cookie Secure. Falls back to nothing when that header is absent.
|
|
proxy_set_header X-Forwarded-Proto $http_x_forwarded_proto;
|
|
# Room for a full-size upload (the API caps photo bodies at 12m itself).
|
|
client_max_body_size 16m;
|
|
}
|
|
|
|
# SPA fallback: /app, /login and /signup are all index.html.
|
|
location / {
|
|
try_files $uri $uri/ /index.html;
|
|
}
|
|
}
|