Files
daily_console_web/nginx.conf.template
2026-08-28 11:15:47 +05:30

148 lines
7.9 KiB
Plaintext

# Nginx for the deployed console.
#
# A `.template`, not a plain conf: the nginx:alpine entrypoint runs `envsubst`
# over everything in /etc/nginx/templates and writes the result into conf.d at
# container start. That is what lets the ingest API key arrive as a runtime
# environment variable instead of being committed to this repository.
#
# ── Why this file exists in this shape ───────────────────────────────────────
#
# The previous version was inherited from the old console and proxied `/hasura/`
# — a path this console never calls — while having no block for `/fiesta/` at
# all. Every API call therefore fell through to `try_files … /index.html`, and
# nginx answers a POST to a static file with **405 Method Not Allowed** and an
# HTML body. The console reported "Malformed response (HTTP 405)", which was
# accurate and pointed nowhere near the cause: sign-in was never reaching the
# backend.
#
# The rule this file follows: every prefix the Vite dev server proxies must have
# a matching block here. `vite.config.ts` is the other half of this file, and
# the two drift apart silently — it works on every developer machine and fails
# only once deployed.
server {
listen 80;
listen 3000;
server_name _;
# 10 MB is the ingest service's own file limit, so anything larger is going
# to be refused anyway — but nginx's default is 1 MB, and it rejects the
# upload itself with a 413 before the request ever leaves this container.
# A merchant's product sheet passes 1 MB easily.
client_max_body_size 12m;
# ── The app ──────────────────────────────────────────────────────────────
location / {
root /usr/share/nginx/html;
index index.html;
# React Router owns the paths, so an unknown one is a route, not a 404.
try_files $uri $uri/ /index.html;
# index.html must be revalidated on every visit, and until now it was
# not — the line below is new, and its absence was a real outage.
#
# The block above said "index.html must NOT be cached" and then set no
# cache header at all, which is not the same thing. With neither
# `Cache-Control` nor `Expires`, a browser falls back to HEURISTIC
# caching: RFC 9111 lets it invent a freshness lifetime from
# `Last-Modified`, commonly a tenth of the document's age, and serve the
# document from disk WITHOUT revalidating. So a tab kept the previous
# index.html, that index.html named `InventoryPage-BAzj-ICF.js`, the
# deploy had replaced it with `InventoryPage-Cbh53mHU.js`, and the
# import 404'd on a screen that had worked ten minutes earlier.
#
# `no-cache` does NOT mean "do not store" — it means "revalidate before
# use". The ETag still answers 304 on an unchanged deploy, so this costs
# one conditional request per visit and never a re-download.
add_header Cache-Control "no-cache" always;
}
# Hashed filenames, so these can be cached hard — the hash changes when the
# content does, which is what makes a year safe.
location /assets/ {
root /usr/share/nginx/html;
# ONE header, not two. `expires 1y` emits its own
# `Cache-Control: max-age=31536000`, and the `add_header` beside it
# appended a second, so every asset went out with two conflicting
# `Cache-Control` lines — `max-age=31536000` and `public, immutable`,
# neither complete. Browsers mostly cope; caches and CDNs in between are
# entitled to take the first and drop `immutable`, or to treat the pair
# as malformed. Merged into a single directive, with `expires` dropped
# because it exists only to emit the header this now sets by hand.
add_header Cache-Control "public, max-age=31536000, immutable" always;
}
# ── Fiesta ───────────────────────────────────────────────────────────────
#
# Mirrors the dev proxy exactly: `/fiesta/live/api/...` → `/live/api/...` on
# fiesta.nearle.app. The trailing slash on proxy_pass is what strips the
# prefix — without it the upstream receives `/fiesta/live/...` and 404s.
#
# Proxied rather than called directly from the browser so the API stays
# same-origin. That keeps CORS out of the picture and means the deployed
# console and a developer's machine take the same code path.
location /fiesta/ {
proxy_pass https://fiesta.nearle.app/;
proxy_ssl_server_name on;
proxy_set_header Host fiesta.nearle.app;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_http_version 1.1;
}
# ── Catalogue ingest ─────────────────────────────────────────────────────
#
# The API key is attached HERE, by nginx, from an environment variable set
# on the container. It never reaches the browser — which matters more than
# usual for this one: the key carries `require_admin` on that service, which
# is a superuser, so the same key also reaches /api/catalog/generate and
# /api/system/init. A key compiled into the JavaScript bundle is a key
# handed to every visitor.
#
# This also settles CORS. The owning team's allow-list does not include this
# console's origin and should not need to: the browser only ever talks to
# its own host, and this container makes the cross-origin call.
location /ingest/ {
# Say when the token is missing, rather than letting it look like a
# rejected one.
#
# nginx omits a header whose value is empty, so an unset INGEST_TOKEN
# sends no `X-API-Key` at all — and the ingest service answers that with
# the same 401 it gives a wrong key. Two very different problems, one
# indistinguishable message, and the one that is actually ours reads as
# the other team's. This names it.
#
# `if` is a blunt instrument in nginx and mostly to be avoided, but
# `return` inside a location is the one use that is documented as safe.
set $ingest_token "${INGEST_TOKEN}";
# At location level: `default_type` is not permitted inside `if`.
default_type application/json;
if ($ingest_token = "") {
return 503 '{"detail":"INGEST_TOKEN is not set on this container, so no X-API-Key was sent. Set it in the deployment environment and restart — envsubst runs at container start, so a running container will not pick it up."}';
}
proxy_pass https://mcp.nearle.ai.in/;
proxy_ssl_server_name on;
proxy_set_header Host mcp.nearle.ai.in;
proxy_set_header X-API-Key $ingest_token;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_http_version 1.1;
# Ingest submits return 202 immediately, but a sheet near the size limit
# takes a moment to upload and the service can be slow to accept it.
proxy_read_timeout 300s;
proxy_send_timeout 300s;
# Send the upload straight through rather than spooling it to disk
# first — nginx would otherwise buffer the whole workbook before the
# upstream saw a byte.
proxy_request_buffering off;
}
# The `/hasura/` block that used to be here is gone. It belonged to the old
# console (daily_merchant_web) and nothing in this app has ever called it —
# it also carried a Hasura admin secret hardcoded in plain text, committed
# to the repository. That secret should be rotated.
}