diff --git a/Dockerfile b/Dockerfile index bb3771e..ccf23de 100644 --- a/Dockerfile +++ b/Dockerfile @@ -45,6 +45,7 @@ COPY --from=builder /app/dist /usr/share/nginx/html COPY --from=builder /app/public/images/ /usr/share/nginx/html/images/ COPY --from=builder /app/public/subtitles /usr/share/nginx/html/subtitles COPY --from=builder /app/public/transcriptions /usr/share/nginx/html/transcriptions +COPY matomo_log_format.conf /etc/nginx/conf.d/ COPY nginx.conf /etc/nginx/conf.d/default.conf # Add runner stage verification to the file diff --git a/matomo_log_format.conf b/matomo_log_format.conf new file mode 100644 index 0000000..ea7e6c1 --- /dev/null +++ b/matomo_log_format.conf @@ -0,0 +1,4 @@ +log_format matomo_tracking '$remote_addr - $remote_user [$time_local] ' + '"$request" $status $body_bytes_sent ' + '"$http_referer" "$http_user_agent" ' + '$request_time'; diff --git a/nginx.conf b/nginx.conf index b1d8e06..f3b1e9c 100644 --- a/nginx.conf +++ b/nginx.conf @@ -1,121 +1,106 @@ -http { - include /etc/nginx/mime.types; - default_type application/octet-stream; +server { + listen 804; + server_name localhost; + root /usr/share/nginx/html; + index index.html; - # Matomo tracking log format - log_format matomo_tracking '$remote_addr - $remote_user [$time_local] ' - '"$request" $status $body_bytes_sent ' - '"$http_referer" "$http_user_agent" ' - '$request_time'; + # Updated log paths and format + access_log /var/log/nginx/deafgain-website/access.log matomo_tracking buffer=512k flush=1m; + error_log /var/log/nginx/deafgain-website/error.log error; + + # Increased buffer sizes + large_client_header_buffers 8 32k; + client_header_buffer_size 32k; + client_max_body_size 10M; + client_body_buffer_size 128k; + + # Security headers + add_header X-Frame-Options "SAMEORIGIN"; + add_header X-XSS-Protection "1; mode=block"; + add_header X-Content-Type-Options "nosniff"; + add_header Strict-Transport-Security "max-age=31536000"; # Compression gzip on; gzip_types text/plain text/css application/json application/javascript text/xml application/xml application/xml+rss text/javascript; - server { - listen 804; - server_name localhost; - root /usr/share/nginx/html; - index index.html; - - # Log paths and format + # API endpoint + location /api/contact { + proxy_pass http://api:3000; + proxy_http_version 1.1; + proxy_set_header Host $host; + proxy_set_header X-Real-IP $remote_addr; + proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; + proxy_set_header X-Forwarded-Proto $scheme; + access_log /var/log/nginx/deafgain-website/access.log matomo_tracking buffer=512k flush=1m; error_log /var/log/nginx/deafgain-website/error.log error; - - # Increased buffer sizes - large_client_header_buffers 8 32k; - client_header_buffer_size 32k; - client_max_body_size 10M; - client_body_buffer_size 128k; - - # Security headers - add_header X-Frame-Options "SAMEORIGIN"; - add_header X-XSS-Protection "1; mode=block"; - add_header X-Content-Type-Options "nosniff"; - add_header Strict-Transport-Security "max-age=31536000"; - - # API endpoint - location /api/contact { - proxy_pass http://api:3000; - proxy_http_version 1.1; - proxy_set_header Host $host; - proxy_set_header X-Real-IP $remote_addr; - proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; - proxy_set_header X-Forwarded-Proto $scheme; - - access_log /var/log/nginx/deafgain-website/access.log matomo_tracking buffer=512k flush=1m; - error_log /var/log/nginx/deafgain-website/error.log error; - - # CORS headers + + # CORS headers + add_header 'Access-Control-Allow-Origin' '*'; + add_header 'Access-Control-Allow-Methods' 'GET, POST, OPTIONS'; + add_header 'Access-Control-Allow-Headers' 'DNT,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range'; + + # Handle OPTIONS method + if ($request_method = 'OPTIONS') { add_header 'Access-Control-Allow-Origin' '*'; add_header 'Access-Control-Allow-Methods' 'GET, POST, OPTIONS'; add_header 'Access-Control-Allow-Headers' 'DNT,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range'; - - # Handle OPTIONS method - if ($request_method = 'OPTIONS') { - add_header 'Access-Control-Allow-Origin' '*'; - add_header 'Access-Control-Allow-Methods' 'GET, POST, OPTIONS'; - add_header 'Access-Control-Allow-Headers' 'DNT,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range'; - add_header 'Access-Control-Max-Age' 1728000; - add_header 'Content-Type' 'text/plain; charset=utf-8'; - add_header 'Content-Length' 0; - return 204; - } - } - - location / { - try_files $uri $uri/ /index.html; - expires 1h; - add_header Cache-Control "public, no-transform"; - } - - # Video files handling - location /videos/ { - alias /usr/share/nginx/html/videos/; - add_header Cache-Control "public, no-transform"; - types { - video/mp4 mp4; - } - add_header Accept-Ranges bytes; - } - - # Images handling - location /images/ { - alias /usr/share/nginx/html/images/; - add_header Cache-Control "public, no-transform"; - types { - image/png png; - image/jpeg jpg jpeg; - image/svg+xml svg; - } - } - - # Subtitles handling - location /subtitles/ { - alias /usr/share/nginx/html/subtitles/; - add_header Cache-Control "public, no-transform"; - types { - text/vtt vtt; - } - } - - # Transcriptions handling - location /transcriptions/ { - alias /usr/share/nginx/html/transcriptions/; - add_header Cache-Control "public, no-transform"; - types { - text/plain txt; - } - } - - # Static asset caching - location ~* \.(js|css|png|jpg|jpeg|gif|ico|svg|vtt|txt)$ { - expires 30d; - add_header Cache-Control "public, no-transform"; + add_header 'Access-Control-Max-Age' 1728000; + add_header 'Content-Type' 'text/plain; charset=utf-8'; + add_header 'Content-Length' 0; + return 204; } } -} -events { - worker_connections 1024; + location / { + try_files $uri $uri/ /index.html; + expires 1h; + add_header Cache-Control "public, no-transform"; + } + + # Video files handling + location /videos/ { + alias /usr/share/nginx/html/videos/; + add_header Cache-Control "public, no-transform"; + types { + video/mp4 mp4; + } + add_header Accept-Ranges bytes; + } + + # Images handling + location /images/ { + alias /usr/share/nginx/html/images/; + add_header Cache-Control "public, no-transform"; + types { + image/png png; + image/jpeg jpg jpeg; + image/svg+xml svg; + } + } + + # Subtitles handling + location /subtitles/ { + alias /usr/share/nginx/html/subtitles/; + add_header Cache-Control "public, no-transform"; + types { + text/vtt vtt; + } + } + + # Transcriptions handling + location /transcriptions/ { + alias /usr/share/nginx/html/transcriptions/; + add_header Cache-Control "public, no-transform"; + types { + text/plain txt; + } + } + + # Static asset caching + location ~* \.(js|css|png|jpg|jpeg|gif|ico|svg|vtt|txt)$ { + expires 30d; + add_header Cache-Control "public, no-transform"; + } }