From f18ceeb663120138c279ccb50fa327bd1fdde12b Mon Sep 17 00:00:00 2001 From: TheMaddax Date: Wed, 11 Dec 2024 22:07:29 -0600 Subject: [PATCH] Rearrange log tracking sections --- Dockerfile | 5 ++- default.conf | 106 +++++++++++++++++++++++++++++++++++++++++++++ nginx.conf | 120 +++++++-------------------------------------------- 3 files changed, 126 insertions(+), 105 deletions(-) create mode 100644 default.conf diff --git a/Dockerfile b/Dockerfile index ccf23de..ae85477 100644 --- a/Dockerfile +++ b/Dockerfile @@ -45,8 +45,11 @@ COPY --from=builder /app/dist /usr/share/nginx/html COPY --from=builder /app/public/images/ /usr/share/nginx/html/images/ COPY --from=builder /app/public/subtitles /usr/share/nginx/html/subtitles COPY --from=builder /app/public/transcriptions /usr/share/nginx/html/transcriptions +# Copy configurations +COPY nginx.conf /etc/nginx/nginx.conf COPY matomo_log_format.conf /etc/nginx/conf.d/ -COPY nginx.conf /etc/nginx/conf.d/default.conf +COPY default.conf /etc/nginx/conf.d/ + # Add runner stage verification to the file RUN echo "\n=== RUNNER STAGE: Verifying nginx html directory structure ===" >> /verification.txt && \ diff --git a/default.conf b/default.conf new file mode 100644 index 0000000..f3b1e9c --- /dev/null +++ b/default.conf @@ -0,0 +1,106 @@ +server { + listen 804; + server_name localhost; + root /usr/share/nginx/html; + index index.html; + + # Updated log paths and format + access_log /var/log/nginx/deafgain-website/access.log matomo_tracking buffer=512k flush=1m; + error_log /var/log/nginx/deafgain-website/error.log error; + + # Increased buffer sizes + large_client_header_buffers 8 32k; + client_header_buffer_size 32k; + client_max_body_size 10M; + client_body_buffer_size 128k; + + # Security headers + add_header X-Frame-Options "SAMEORIGIN"; + add_header X-XSS-Protection "1; mode=block"; + add_header X-Content-Type-Options "nosniff"; + add_header Strict-Transport-Security "max-age=31536000"; + + # Compression + gzip on; + gzip_types text/plain text/css application/json application/javascript text/xml application/xml application/xml+rss text/javascript; + + # API endpoint + location /api/contact { + proxy_pass http://api:3000; + proxy_http_version 1.1; + proxy_set_header Host $host; + proxy_set_header X-Real-IP $remote_addr; + proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; + proxy_set_header X-Forwarded-Proto $scheme; + + access_log /var/log/nginx/deafgain-website/access.log matomo_tracking buffer=512k flush=1m; + error_log /var/log/nginx/deafgain-website/error.log error; + + # CORS headers + add_header 'Access-Control-Allow-Origin' '*'; + add_header 'Access-Control-Allow-Methods' 'GET, POST, OPTIONS'; + add_header 'Access-Control-Allow-Headers' 'DNT,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range'; + + # Handle OPTIONS method + if ($request_method = 'OPTIONS') { + add_header 'Access-Control-Allow-Origin' '*'; + add_header 'Access-Control-Allow-Methods' 'GET, POST, OPTIONS'; + add_header 'Access-Control-Allow-Headers' 'DNT,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range'; + add_header 'Access-Control-Max-Age' 1728000; + add_header 'Content-Type' 'text/plain; charset=utf-8'; + add_header 'Content-Length' 0; + return 204; + } + } + + location / { + try_files $uri $uri/ /index.html; + expires 1h; + add_header Cache-Control "public, no-transform"; + } + + # Video files handling + location /videos/ { + alias /usr/share/nginx/html/videos/; + add_header Cache-Control "public, no-transform"; + types { + video/mp4 mp4; + } + add_header Accept-Ranges bytes; + } + + # Images handling + location /images/ { + alias /usr/share/nginx/html/images/; + add_header Cache-Control "public, no-transform"; + types { + image/png png; + image/jpeg jpg jpeg; + image/svg+xml svg; + } + } + + # Subtitles handling + location /subtitles/ { + alias /usr/share/nginx/html/subtitles/; + add_header Cache-Control "public, no-transform"; + types { + text/vtt vtt; + } + } + + # Transcriptions handling + location /transcriptions/ { + alias /usr/share/nginx/html/transcriptions/; + add_header Cache-Control "public, no-transform"; + types { + text/plain txt; + } + } + + # Static asset caching + location ~* \.(js|css|png|jpg|jpeg|gif|ico|svg|vtt|txt)$ { + expires 30d; + add_header Cache-Control "public, no-transform"; + } +} diff --git a/nginx.conf b/nginx.conf index f3b1e9c..f94f22d 100644 --- a/nginx.conf +++ b/nginx.conf @@ -1,106 +1,18 @@ -server { - listen 804; - server_name localhost; - root /usr/share/nginx/html; - index index.html; +user nginx; +worker_processes auto; +pid /var/run/nginx.pid; - # Updated log paths and format - access_log /var/log/nginx/deafgain-website/access.log matomo_tracking buffer=512k flush=1m; - error_log /var/log/nginx/deafgain-website/error.log error; - - # Increased buffer sizes - large_client_header_buffers 8 32k; - client_header_buffer_size 32k; - client_max_body_size 10M; - client_body_buffer_size 128k; - - # Security headers - add_header X-Frame-Options "SAMEORIGIN"; - add_header X-XSS-Protection "1; mode=block"; - add_header X-Content-Type-Options "nosniff"; - add_header Strict-Transport-Security "max-age=31536000"; - - # Compression - gzip on; - gzip_types text/plain text/css application/json application/javascript text/xml application/xml application/xml+rss text/javascript; - - # API endpoint - location /api/contact { - proxy_pass http://api:3000; - proxy_http_version 1.1; - proxy_set_header Host $host; - proxy_set_header X-Real-IP $remote_addr; - proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; - proxy_set_header X-Forwarded-Proto $scheme; - - access_log /var/log/nginx/deafgain-website/access.log matomo_tracking buffer=512k flush=1m; - error_log /var/log/nginx/deafgain-website/error.log error; - - # CORS headers - add_header 'Access-Control-Allow-Origin' '*'; - add_header 'Access-Control-Allow-Methods' 'GET, POST, OPTIONS'; - add_header 'Access-Control-Allow-Headers' 'DNT,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range'; - - # Handle OPTIONS method - if ($request_method = 'OPTIONS') { - add_header 'Access-Control-Allow-Origin' '*'; - add_header 'Access-Control-Allow-Methods' 'GET, POST, OPTIONS'; - add_header 'Access-Control-Allow-Headers' 'DNT,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range'; - add_header 'Access-Control-Max-Age' 1728000; - add_header 'Content-Type' 'text/plain; charset=utf-8'; - add_header 'Content-Length' 0; - return 204; - } - } - - location / { - try_files $uri $uri/ /index.html; - expires 1h; - add_header Cache-Control "public, no-transform"; - } - - # Video files handling - location /videos/ { - alias /usr/share/nginx/html/videos/; - add_header Cache-Control "public, no-transform"; - types { - video/mp4 mp4; - } - add_header Accept-Ranges bytes; - } - - # Images handling - location /images/ { - alias /usr/share/nginx/html/images/; - add_header Cache-Control "public, no-transform"; - types { - image/png png; - image/jpeg jpg jpeg; - image/svg+xml svg; - } - } - - # Subtitles handling - location /subtitles/ { - alias /usr/share/nginx/html/subtitles/; - add_header Cache-Control "public, no-transform"; - types { - text/vtt vtt; - } - } - - # Transcriptions handling - location /transcriptions/ { - alias /usr/share/nginx/html/transcriptions/; - add_header Cache-Control "public, no-transform"; - types { - text/plain txt; - } - } - - # Static asset caching - location ~* \.(js|css|png|jpg|jpeg|gif|ico|svg|vtt|txt)$ { - expires 30d; - add_header Cache-Control "public, no-transform"; - } +events { + worker_connections 1024; +} + +http { + include /etc/nginx/mime.types; + default_type application/octet-stream; + + # Include Matomo log format + include /etc/nginx/conf.d/matomo_log_format.conf; + + # Include server configurations + include /etc/nginx/conf.d/*.conf; }