57 lines
2.5 KiB
Nginx Configuration File
57 lines
2.5 KiB
Nginx Configuration File
|
|
# Cache for live GTFS-Realtime answers: the feeds change about every 30 s, so 15 s protects ZTP from a flood of identical requests.
|
||
|
|
proxy_cache_path /var/cache/nginx/rt levels=1 keys_zone=rt:1m max_size=20m inactive=2m use_temp_path=off;
|
||
|
|
|
||
|
|
server {
|
||
|
|
listen 80;
|
||
|
|
server_name _;
|
||
|
|
root /usr/share/nginx/html;
|
||
|
|
index index.html;
|
||
|
|
|
||
|
|
gzip on;
|
||
|
|
gzip_vary on;
|
||
|
|
gzip_min_length 512;
|
||
|
|
gzip_types application/json application/javascript text/javascript text/css image/svg+xml application/manifest+json application/wasm;
|
||
|
|
|
||
|
|
add_header X-Content-Type-Options nosniff always;
|
||
|
|
add_header Referrer-Policy strict-origin-when-cross-origin always;
|
||
|
|
|
||
|
|
location = /healthz {
|
||
|
|
access_log off;
|
||
|
|
default_type text/plain;
|
||
|
|
return 200 "ok\n";
|
||
|
|
}
|
||
|
|
|
||
|
|
# Live transit delays. ZTP sends no CORS headers, so the browser cannot call it directly; the app asks for /rt/* on its own origin.
|
||
|
|
location /rt/ {
|
||
|
|
resolver 127.0.0.11 1.1.1.1 valid=300s ipv6=off; # resolved at request time: a ZTP outage must not stop nginx from starting
|
||
|
|
set $ztp gtfs.ztp.krakow.pl;
|
||
|
|
rewrite ^/rt/(.*)$ /$1 break;
|
||
|
|
proxy_pass https://$ztp;
|
||
|
|
proxy_ssl_server_name on;
|
||
|
|
proxy_set_header Host $ztp;
|
||
|
|
proxy_connect_timeout 3s;
|
||
|
|
proxy_read_timeout 6s;
|
||
|
|
proxy_cache rt;
|
||
|
|
proxy_cache_valid 200 15s;
|
||
|
|
proxy_ignore_headers Cache-Control Expires Set-Cookie; # cache by our rule below, whatever the upstream says
|
||
|
|
proxy_cache_use_stale error timeout updating;
|
||
|
|
add_header Cache-Control "no-store" always;
|
||
|
|
}
|
||
|
|
|
||
|
|
# The service worker and the app shell must always be revalidated, or an update would never reach installed apps.
|
||
|
|
location = /sw.js { add_header Cache-Control "no-cache"; try_files $uri =404; }
|
||
|
|
location = /index.html { add_header Cache-Control "no-cache"; }
|
||
|
|
location = /manifest.webmanifest { add_header Cache-Control "no-cache"; types { application/manifest+json webmanifest; } }
|
||
|
|
|
||
|
|
# Hashed build output never changes under the same name.
|
||
|
|
location /assets/ { add_header Cache-Control "public, max-age=31536000, immutable"; try_files $uri =404; }
|
||
|
|
location ~ ^/workbox-.*\.js$ { add_header Cache-Control "public, max-age=31536000, immutable"; try_files $uri =404; }
|
||
|
|
|
||
|
|
# Data files keep their names: revalidate (the service worker precaches them by content hash).
|
||
|
|
location /data/ { add_header Cache-Control "no-cache"; try_files $uri =404; }
|
||
|
|
|
||
|
|
location / {
|
||
|
|
try_files $uri $uri/ /index.html;
|
||
|
|
}
|
||
|
|
}
|