# Cache for live GTFS-Realtime answers: the feeds change about every 30 s, so 15 s protects ZTP from a flood of identical requests. proxy_cache_path /var/cache/nginx/rt levels=1 keys_zone=rt:1m max_size=20m inactive=2m use_temp_path=off; server { listen 80; server_name _; root /usr/share/nginx/html; index index.html; gzip on; gzip_vary on; gzip_min_length 512; gzip_types application/json application/javascript text/javascript text/css image/svg+xml application/manifest+json application/wasm; add_header X-Content-Type-Options nosniff always; add_header Referrer-Policy strict-origin-when-cross-origin always; location = /healthz { access_log off; default_type text/plain; return 200 "ok\n"; } # Live transit delays. ZTP sends no CORS headers, so the browser cannot call it directly; the app asks for /rt/* on its own origin. location /rt/ { resolver 127.0.0.11 1.1.1.1 valid=300s ipv6=off; # resolved at request time: a ZTP outage must not stop nginx from starting set $ztp gtfs.ztp.krakow.pl; rewrite ^/rt/(.*)$ /$1 break; proxy_pass https://$ztp; proxy_ssl_server_name on; proxy_set_header Host $ztp; proxy_connect_timeout 3s; proxy_read_timeout 6s; proxy_cache rt; proxy_cache_valid 200 15s; proxy_ignore_headers Cache-Control Expires Set-Cookie; # cache by our rule below, whatever the upstream says proxy_cache_use_stale error timeout updating; add_header Cache-Control "no-store" always; } # The service worker and the app shell must always be revalidated, or an update would never reach installed apps. location = /sw.js { add_header Cache-Control "no-cache"; try_files $uri =404; } location = /index.html { add_header Cache-Control "no-cache"; } location = /manifest.webmanifest { add_header Cache-Control "no-cache"; types { application/manifest+json webmanifest; } } # Hashed build output never changes under the same name. location /assets/ { add_header Cache-Control "public, max-age=31536000, immutable"; try_files $uri =404; } location ~ ^/workbox-.*\.js$ { add_header Cache-Control "public, max-age=31536000, immutable"; try_files $uri =404; } # Data files keep their names: revalidate (the service worker precaches them by content hash). location /data/ { add_header Cache-Control "no-cache"; try_files $uri =404; } location / { try_files $uri $uri/ /index.html; } }