Files
RecipesCam/docker/frontend/nginx.conf
T
3dtours d2115941c7 feat(admin): back the data up, and put it back, from the admin tool
A new BACKUP tab downloads the deployment's whole state — the SQLite file
and both media folders, photos included — as one .tar.gz, and takes the same
file back. That one artefact therefore does both jobs: the operator's backup
and the data package that moves an install onto another box.

The database is snapshotted through SQLite's own backup rather than copied,
because the file is written to while the archive streams; the media folders
are tarred straight off the volume, so no second copy of them is made.

A restore replaces the data on disk and then exits — the container's restart
policy brings the API back on the restored files, which is the only moment the
open handle can be dropped. The state being replaced is tarred aside first,
and the archive is checked for `..` entries before anything is unpacked. The
API authenticates that route before it reads a byte, and nginx lets that one
path past the body cap which holds everywhere else.
2026-09-25 08:46:29 +07:00

100 lines
4.5 KiB
Nginx Configuration File

# Static SPA + API proxy. TLS/domain are terminated outside (Nginx Proxy
# Manager), so this container only ever speaks plain HTTP on port 80.
server {
listen 80;
server_name _;
root /usr/share/nginx/html;
index index.html;
# Static only, plus the API proxy below; a stricter CSP needs a per-app tune
# (canvas wasm, the QR image host) and belongs here once it is done.
# Cross-origin isolation: super-resolution runs onnxruntime's threaded wasm,
# which needs a SharedArrayBuffer, which the browser only hands over when the
# page is isolated. Both headers are required, and both must also sit on the
# script responses a nested worker fetches — see the two locations below.
add_header Cross-Origin-Opener-Policy "same-origin" always;
add_header Cross-Origin-Embedder-Policy "require-corp" always;
add_header X-Content-Type-Options "nosniff" always;
add_header X-Frame-Options "DENY" always;
add_header Referrer-Policy "strict-origin-when-cross-origin" always;
gzip on;
gzip_comp_level 5;
gzip_min_length 1024;
gzip_types text/css application/javascript application/json application/wasm image/svg+xml;
# nginx's stock mime.types has no .mjs, and the browser refuses to run a module
# the server hands over as octet-stream: onnxruntime's glue is one of those.
# First match wins among regex locations, so this one stands before the
# /wasm/ block that would otherwise swallow the file.
# (Both locations below restate the isolation headers from above: an add_header
# in a location drops every add_header inherited, and a worker script is fetched
# under the embedder's COEP — Chromium blocks it as
# `coep-frame-resource-needs-coep-header` without them.)
location ~* \.mjs$ {
types { application/javascript mjs; }
expires 30d;
add_header Cache-Control "public, immutable";
add_header Cross-Origin-Opener-Policy "same-origin" always;
add_header Cross-Origin-Embedder-Policy "require-corp" always;
try_files $uri =404;
}
# canvas.wasm is ~8MB and the super-resolution model is ~5MB: immutable, hashed
# or not, they never change under a given build. Fonts and the wall-frame
# artwork are likewise static.
location ~* ^/(wasm|models|assets)/ {
expires 30d;
add_header Cache-Control "public, immutable";
add_header Cross-Origin-Opener-Policy "same-origin" always;
add_header Cross-Origin-Embedder-Policy "require-corp" always;
try_files $uri =404;
}
# The one route that carries a whole data dir back in (see /api/admin/restore
# — who may call it is the API's own admin check, done before it reads a byte).
# The upload cap that holds everywhere else would reject it, and unpacking the
# archive plus the restart takes longer than the stock read timeout. nginx
# takes the longest matching prefix, so this one holds for that route while
# /api/ below keeps the rest.
location /api/admin/restore {
resolver 127.0.0.11 valid=10s ipv6=off;
set $api_upstream http://api:3000;
proxy_pass $api_upstream$request_uri;
proxy_http_version 1.1;
proxy_set_header Host $http_host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $http_x_forwarded_proto;
client_max_body_size 0;
proxy_read_timeout 600s;
proxy_send_timeout 600s;
}
location /api/ {
# Resolved per request through Docker's embedded DNS, so the frontend can
# start before the API container without nginx refusing to boot.
resolver 127.0.0.11 valid=10s ipv6=off;
set $api_upstream http://api:3000;
proxy_pass $api_upstream$request_uri;
proxy_http_version 1.1;
# $http_host, not $host: keep the port when the visitor hits this container
# directly (localhost:8090), since the API builds the verification link from
# the forwarded host.
proxy_set_header Host $http_host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
# Hand the API the scheme the visitor actually used (TLS is terminated by
# Nginx Proxy Manager in front of this container) so it can mark the session
# cookie Secure. Falls back to nothing when that header is absent.
proxy_set_header X-Forwarded-Proto $http_x_forwarded_proto;
# Room for a full-size upload (the API caps photo bodies at 12m itself).
client_max_body_size 16m;
}
# SPA fallback: /app, /login and /signup are all index.html.
location / {
try_files $uri $uri/ /index.html;
}
}