# Nginx for the deployed console. # # A `.template`, not a plain conf: the nginx:alpine entrypoint runs `envsubst` # over everything in /etc/nginx/templates and writes the result into conf.d at # container start. That is what lets the ingest API key arrive as a runtime # environment variable instead of being committed to this repository. # # ── Why this file exists in this shape ─────────────────────────────────────── # # The previous version was inherited from the old console and proxied `/hasura/` # — a path this console never calls — while having no block for `/fiesta/` at # all. Every API call therefore fell through to `try_files … /index.html`, and # nginx answers a POST to a static file with **405 Method Not Allowed** and an # HTML body. The console reported "Malformed response (HTTP 405)", which was # accurate and pointed nowhere near the cause: sign-in was never reaching the # backend. # # The rule this file follows: every prefix the Vite dev server proxies must have # a matching block here. `vite.config.ts` is the other half of this file, and # the two drift apart silently — it works on every developer machine and fails # only once deployed. server { listen 80; listen 3000; server_name _; # 10 MB is the ingest service's own file limit, so anything larger is going # to be refused anyway — but nginx's default is 1 MB, and it rejects the # upload itself with a 413 before the request ever leaves this container. # A merchant's product sheet passes 1 MB easily. client_max_body_size 12m; # ── The app ────────────────────────────────────────────────────────────── location / { root /usr/share/nginx/html; index index.html; # React Router owns the paths, so an unknown one is a route, not a 404. try_files $uri $uri/ /index.html; # index.html must be revalidated on every visit, and until now it was # not — the line below is new, and its absence was a real outage. # # The block above said "index.html must NOT be cached" and then set no # cache header at all, which is not the same thing. With neither # `Cache-Control` nor `Expires`, a browser falls back to HEURISTIC # caching: RFC 9111 lets it invent a freshness lifetime from # `Last-Modified`, commonly a tenth of the document's age, and serve the # document from disk WITHOUT revalidating. So a tab kept the previous # index.html, that index.html named `InventoryPage-BAzj-ICF.js`, the # deploy had replaced it with `InventoryPage-Cbh53mHU.js`, and the # import 404'd on a screen that had worked ten minutes earlier. # # `no-cache` does NOT mean "do not store" — it means "revalidate before # use". The ETag still answers 304 on an unchanged deploy, so this costs # one conditional request per visit and never a re-download. add_header Cache-Control "no-cache" always; } # Hashed filenames, so these can be cached hard — the hash changes when the # content does, which is what makes a year safe. location /assets/ { root /usr/share/nginx/html; # ONE header, not two. `expires 1y` emits its own # `Cache-Control: max-age=31536000`, and the `add_header` beside it # appended a second, so every asset went out with two conflicting # `Cache-Control` lines — `max-age=31536000` and `public, immutable`, # neither complete. Browsers mostly cope; caches and CDNs in between are # entitled to take the first and drop `immutable`, or to treat the pair # as malformed. Merged into a single directive, with `expires` dropped # because it exists only to emit the header this now sets by hand. add_header Cache-Control "public, max-age=31536000, immutable" always; } # ── Fiesta ─────────────────────────────────────────────────────────────── # # Mirrors the dev proxy exactly: `/fiesta/live/api/...` → `/live/api/...` on # fiesta.nearle.app. The trailing slash on proxy_pass is what strips the # prefix — without it the upstream receives `/fiesta/live/...` and 404s. # # Proxied rather than called directly from the browser so the API stays # same-origin. That keeps CORS out of the picture and means the deployed # console and a developer's machine take the same code path. location /fiesta/ { proxy_pass https://fiesta.nearle.app/; proxy_ssl_server_name on; proxy_set_header Host fiesta.nearle.app; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; proxy_http_version 1.1; } # ── Catalogue ingest ───────────────────────────────────────────────────── # # The API key is attached HERE, by nginx, from an environment variable set # on the container. It never reaches the browser — which matters more than # usual for this one: the key carries `require_admin` on that service, which # is a superuser, so the same key also reaches /api/catalog/generate and # /api/system/init. A key compiled into the JavaScript bundle is a key # handed to every visitor. # # This also settles CORS. The owning team's allow-list does not include this # console's origin and should not need to: the browser only ever talks to # its own host, and this container makes the cross-origin call. location /ingest/ { # ── Where the ingest service is, and how we prove who we are ───────── # # Both are environment variables so the deployment can move between two # arrangements without a rebuild: # # INGEST_UPSTREAM=https://mcp.nearle.ai.in INGEST_TOKEN= # The public host. Needs a credential, because that host is on the # internet and its guards do not care who is asking. # # INGEST_UPSTREAM=http://: INGEST_TOKEN= # The internal Docker network. `app.nearledaily.com` and # `mcp.nearle.ai.in` both resolve to 72.60.218.25 — the same host — # so the two containers can talk without going out to the internet # and back. No secret has to exist on this side at all, which is # the whole point: a credential that is never issued cannot leak, # expire, or be pasted into a chat window. # # The second needs the ingest service to trust its own machine. That is # their change, not ours; this side is ready for either. set $ingest_token "${INGEST_TOKEN}"; # No 503 guard for a missing token any more, deliberately. # # It existed because an unset token sent no header and the service # answered with the same flat 401 it gives a wrong key. Two problems, # one message. It cannot stay: on the internal network an empty token is # the CORRECT configuration, and a guard that refuses the intended setup # is worse than the ambiguity it was written to remove. The service's own # 401 now names the fix — "Send a bearer token ... or an X-API-Key # header" — which is the sentence the guard was standing in for. # # nginx omits a header whose value is empty, so the line below sends # `X-API-Key` on the public host and nothing at all internally. One # directive, both modes, no branching. # `${INGEST_UPSTREAM}` and not `$upstream_variable`, and the difference # is not cosmetic. # # envsubst rewrites this line at container start, so nginx parses a # literal address and behaves exactly as it did when the host was # hardcoded. Putting an nginx VARIABLE in proxy_pass instead changes # three things at once: nginx resolves the name per request rather than # at startup, which requires a `resolver` directive; 127.0.0.11 (Docker's # embedded DNS) exists only on a user-defined network, so on a default # bridge every ingest call fails with "recv() failed ... while resolving"; # and a variable proxy_pass stops stripping the location prefix, so the # upstream starts receiving `/ingest/api/...` and 404s. Measured, not # guessed — the first version of this did all three. # # The trailing slash is what strips `/ingest/`, so INGEST_UPSTREAM must # NOT end in one. A name that cannot be resolved now fails at startup # rather than per request, which is the better place to find out. proxy_pass ${INGEST_UPSTREAM}/; proxy_ssl_server_name on; # Derived from the upstream rather than hardcoded, so it stays correct # when the upstream becomes a container name. proxy_set_header Host $proxy_host; proxy_set_header X-API-Key $ingest_token; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_http_version 1.1; # Ingest submits return 202 immediately, but a sheet near the size limit # takes a moment to upload and the service can be slow to accept it. proxy_read_timeout 300s; proxy_send_timeout 300s; # Send the upload straight through rather than spooling it to disk # first — nginx would otherwise buffer the whole workbook before the # upstream saw a byte. proxy_request_buffering off; } # The `/hasura/` block that used to be here is gone. It belonged to the old # console (daily_merchant_web) and nothing in this app has ever called it — # it also carried a Hasura admin secret hardcoded in plain text, committed # to the repository. That secret should be rotated. }