initial commit
This commit is contained in:
183
nginx.conf.template
Normal file
183
nginx.conf.template
Normal file
@@ -0,0 +1,183 @@
|
||||
# Nginx for the deployed console.
|
||||
#
|
||||
# A `.template`, not a plain conf: the nginx:alpine entrypoint runs `envsubst`
|
||||
# over everything in /etc/nginx/templates and writes the result into conf.d at
|
||||
# container start. That is what lets the ingest API key arrive as a runtime
|
||||
# environment variable instead of being committed to this repository.
|
||||
#
|
||||
# ── Why this file exists in this shape ───────────────────────────────────────
|
||||
#
|
||||
# The previous version was inherited from the old console and proxied `/hasura/`
|
||||
# — a path this console never calls — while having no block for `/fiesta/` at
|
||||
# all. Every API call therefore fell through to `try_files … /index.html`, and
|
||||
# nginx answers a POST to a static file with **405 Method Not Allowed** and an
|
||||
# HTML body. The console reported "Malformed response (HTTP 405)", which was
|
||||
# accurate and pointed nowhere near the cause: sign-in was never reaching the
|
||||
# backend.
|
||||
#
|
||||
# The rule this file follows: every prefix the Vite dev server proxies must have
|
||||
# a matching block here. `vite.config.ts` is the other half of this file, and
|
||||
# the two drift apart silently — it works on every developer machine and fails
|
||||
# only once deployed.
|
||||
|
||||
server {
|
||||
listen 80;
|
||||
listen 3000;
|
||||
server_name _;
|
||||
|
||||
# 10 MB is the ingest service's own file limit, so anything larger is going
|
||||
# to be refused anyway — but nginx's default is 1 MB, and it rejects the
|
||||
# upload itself with a 413 before the request ever leaves this container.
|
||||
# A merchant's product sheet passes 1 MB easily.
|
||||
client_max_body_size 12m;
|
||||
|
||||
# ── The app ──────────────────────────────────────────────────────────────
|
||||
location / {
|
||||
root /usr/share/nginx/html;
|
||||
index index.html;
|
||||
# React Router owns the paths, so an unknown one is a route, not a 404.
|
||||
try_files $uri $uri/ /index.html;
|
||||
|
||||
# index.html must be revalidated on every visit, and until now it was
|
||||
# not — the line below is new, and its absence was a real outage.
|
||||
#
|
||||
# The block above said "index.html must NOT be cached" and then set no
|
||||
# cache header at all, which is not the same thing. With neither
|
||||
# `Cache-Control` nor `Expires`, a browser falls back to HEURISTIC
|
||||
# caching: RFC 9111 lets it invent a freshness lifetime from
|
||||
# `Last-Modified`, commonly a tenth of the document's age, and serve the
|
||||
# document from disk WITHOUT revalidating. So a tab kept the previous
|
||||
# index.html, that index.html named `InventoryPage-BAzj-ICF.js`, the
|
||||
# deploy had replaced it with `InventoryPage-Cbh53mHU.js`, and the
|
||||
# import 404'd on a screen that had worked ten minutes earlier.
|
||||
#
|
||||
# `no-cache` does NOT mean "do not store" — it means "revalidate before
|
||||
# use". The ETag still answers 304 on an unchanged deploy, so this costs
|
||||
# one conditional request per visit and never a re-download.
|
||||
add_header Cache-Control "no-cache" always;
|
||||
}
|
||||
|
||||
# Hashed filenames, so these can be cached hard — the hash changes when the
|
||||
# content does, which is what makes a year safe.
|
||||
location /assets/ {
|
||||
root /usr/share/nginx/html;
|
||||
|
||||
# ONE header, not two. `expires 1y` emits its own
|
||||
# `Cache-Control: max-age=31536000`, and the `add_header` beside it
|
||||
# appended a second, so every asset went out with two conflicting
|
||||
# `Cache-Control` lines — `max-age=31536000` and `public, immutable`,
|
||||
# neither complete. Browsers mostly cope; caches and CDNs in between are
|
||||
# entitled to take the first and drop `immutable`, or to treat the pair
|
||||
# as malformed. Merged into a single directive, with `expires` dropped
|
||||
# because it exists only to emit the header this now sets by hand.
|
||||
add_header Cache-Control "public, max-age=31536000, immutable" always;
|
||||
}
|
||||
|
||||
# ── Fiesta ───────────────────────────────────────────────────────────────
|
||||
#
|
||||
# Mirrors the dev proxy exactly: `/fiesta/live/api/...` → `/live/api/...` on
|
||||
# fiesta.nearle.app. The trailing slash on proxy_pass is what strips the
|
||||
# prefix — without it the upstream receives `/fiesta/live/...` and 404s.
|
||||
#
|
||||
# Proxied rather than called directly from the browser so the API stays
|
||||
# same-origin. That keeps CORS out of the picture and means the deployed
|
||||
# console and a developer's machine take the same code path.
|
||||
location /fiesta/ {
|
||||
proxy_pass https://fiesta.nearle.app/;
|
||||
proxy_ssl_server_name on;
|
||||
proxy_set_header Host fiesta.nearle.app;
|
||||
proxy_set_header X-Real-IP $remote_addr;
|
||||
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
||||
proxy_set_header X-Forwarded-Proto $scheme;
|
||||
proxy_http_version 1.1;
|
||||
}
|
||||
|
||||
# ── Catalogue ingest ─────────────────────────────────────────────────────
|
||||
#
|
||||
# The API key is attached HERE, by nginx, from an environment variable set
|
||||
# on the container. It never reaches the browser — which matters more than
|
||||
# usual for this one: the key carries `require_admin` on that service, which
|
||||
# is a superuser, so the same key also reaches /api/catalog/generate and
|
||||
# /api/system/init. A key compiled into the JavaScript bundle is a key
|
||||
# handed to every visitor.
|
||||
#
|
||||
# This also settles CORS. The owning team's allow-list does not include this
|
||||
# console's origin and should not need to: the browser only ever talks to
|
||||
# its own host, and this container makes the cross-origin call.
|
||||
location /ingest/ {
|
||||
# ── Where the ingest service is, and how we prove who we are ─────────
|
||||
#
|
||||
# Both are environment variables so the deployment can move between two
|
||||
# arrangements without a rebuild:
|
||||
#
|
||||
# INGEST_UPSTREAM=https://mcp.nearle.ai.in INGEST_TOKEN=<secret>
|
||||
# The public host. Needs a credential, because that host is on the
|
||||
# internet and its guards do not care who is asking.
|
||||
#
|
||||
# INGEST_UPSTREAM=http://<container>:<port> INGEST_TOKEN=
|
||||
# The internal Docker network. `app.nearledaily.com` and
|
||||
# `mcp.nearle.ai.in` both resolve to 72.60.218.25 — the same host —
|
||||
# so the two containers can talk without going out to the internet
|
||||
# and back. No secret has to exist on this side at all, which is
|
||||
# the whole point: a credential that is never issued cannot leak,
|
||||
# expire, or be pasted into a chat window.
|
||||
#
|
||||
# The second needs the ingest service to trust its own machine. That is
|
||||
# their change, not ours; this side is ready for either.
|
||||
set $ingest_token "${INGEST_TOKEN}";
|
||||
|
||||
# No 503 guard for a missing token any more, deliberately.
|
||||
#
|
||||
# It existed because an unset token sent no header and the service
|
||||
# answered with the same flat 401 it gives a wrong key. Two problems,
|
||||
# one message. It cannot stay: on the internal network an empty token is
|
||||
# the CORRECT configuration, and a guard that refuses the intended setup
|
||||
# is worse than the ambiguity it was written to remove. The service's own
|
||||
# 401 now names the fix — "Send a bearer token ... or an X-API-Key
|
||||
# header" — which is the sentence the guard was standing in for.
|
||||
#
|
||||
# nginx omits a header whose value is empty, so the line below sends
|
||||
# `X-API-Key` on the public host and nothing at all internally. One
|
||||
# directive, both modes, no branching.
|
||||
|
||||
# `${INGEST_UPSTREAM}` and not `$upstream_variable`, and the difference
|
||||
# is not cosmetic.
|
||||
#
|
||||
# envsubst rewrites this line at container start, so nginx parses a
|
||||
# literal address and behaves exactly as it did when the host was
|
||||
# hardcoded. Putting an nginx VARIABLE in proxy_pass instead changes
|
||||
# three things at once: nginx resolves the name per request rather than
|
||||
# at startup, which requires a `resolver` directive; 127.0.0.11 (Docker's
|
||||
# embedded DNS) exists only on a user-defined network, so on a default
|
||||
# bridge every ingest call fails with "recv() failed ... while resolving";
|
||||
# and a variable proxy_pass stops stripping the location prefix, so the
|
||||
# upstream starts receiving `/ingest/api/...` and 404s. Measured, not
|
||||
# guessed — the first version of this did all three.
|
||||
#
|
||||
# The trailing slash is what strips `/ingest/`, so INGEST_UPSTREAM must
|
||||
# NOT end in one. A name that cannot be resolved now fails at startup
|
||||
# rather than per request, which is the better place to find out.
|
||||
proxy_pass ${INGEST_UPSTREAM}/;
|
||||
proxy_ssl_server_name on;
|
||||
# Derived from the upstream rather than hardcoded, so it stays correct
|
||||
# when the upstream becomes a container name.
|
||||
proxy_set_header Host $proxy_host;
|
||||
proxy_set_header X-API-Key $ingest_token;
|
||||
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
||||
proxy_http_version 1.1;
|
||||
|
||||
# Ingest submits return 202 immediately, but a sheet near the size limit
|
||||
# takes a moment to upload and the service can be slow to accept it.
|
||||
proxy_read_timeout 300s;
|
||||
proxy_send_timeout 300s;
|
||||
# Send the upload straight through rather than spooling it to disk
|
||||
# first — nginx would otherwise buffer the whole workbook before the
|
||||
# upstream saw a byte.
|
||||
proxy_request_buffering off;
|
||||
}
|
||||
|
||||
# The `/hasura/` block that used to be here is gone. It belonged to the old
|
||||
# console (daily_merchant_web) and nothing in this app has ever called it —
|
||||
# it also carried a Hasura admin secret hardcoded in plain text, committed
|
||||
# to the repository. That secret should be rotated.
|
||||
}
|
||||
Reference in New Issue
Block a user