-
Notifications
You must be signed in to change notification settings - Fork 126
Expand file tree
/
Copy pathnginx.conf
More file actions
131 lines (114 loc) · 5.06 KB
/
Copy pathnginx.conf
File metadata and controls
131 lines (114 loc) · 5.06 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
worker_processes 1;
pid /tmp/nginx.pid;
events {
worker_connections 1024;
}
http {
charset utf-8;
sendfile on;
tcp_nopush on;
tcp_nodelay on;
server_tokens off;
log_not_found off;
types_hash_max_size 2048;
client_max_body_size 16M;
# MIME
include /etc/nginx/mime.types;
default_type application/octet-stream;
# HSTS: only set when the request was proxied over HTTPS
map $http_x_forwarded_proto $hsts_header {
https "max-age=31536000; includeSubDomains";
default "";
}
# gzip
gzip on;
gzip_vary on;
gzip_proxied any;
gzip_comp_level 6;
gzip_types text/plain text/css text/xml application/json application/javascript application/rss+xml application/atom+xml image/svg+xml;
server {
listen 8080;
server_name localhost;
root /usr/share/nginx/html;
index index.html;
# CSP header variable
set $csp_header "object-src 'none'; default-src 'self' data: *.uservoice.com; script-src 'self' status.reportportal.io www.google-analytics.com www.googletagmanager.com stats.g.doubleclick.net *.saucelabs.com *.epam.com *.uservoice.com *.rawgit.com; worker-src 'self' blob:; font-src 'self' data: fonts.googleapis.com fonts.gstatic.com *.rawgit.com; style-src-elem 'self' data: 'unsafe-inline' *.googleapis.com *.rawgit.com; style-src 'self' 'unsafe-inline' https://tagmanager.google.com; media-src 'self' *.saucelabs.com *.browserstack.com blob:; img-src * 'self' data: blob: http: https: www.google-analytics.com; connect-src 'self' *.google-analytics.com *.analytics.google.com https://stats.g.doubleclick.net; frame-src 'self' https://webto.salesforce.com https://app.mobitru.com https://access.epam.com";
# Optional deployment-specific server and location directives
include ${EXTRA_NGINX_CONFIG};
#fallback
location / {
add_header Cache-Control "no-cache";
add_header Strict-Transport-Security $hsts_header always;
add_header X-Frame-Options "DENY";
add_header X-Content-Type-Options "nosniff";
add_header X-XSS-Protection "1; mode=block";
add_header Content-Security-Policy $csp_header;
try_files $uri /index.html;
}
location /ui/ {
add_header Cache-Control "no-cache";
add_header Strict-Transport-Security $hsts_header always;
add_header X-Frame-Options "DENY";
add_header X-Content-Type-Options "nosniff";
add_header X-XSS-Protection "1; mode=block";
add_header Content-Security-Policy $csp_header;
try_files $uri /index.html;
}
# build info
location /info {
add_header Cache-Control "public, must-revalidate";
add_header Strict-Transport-Security $hsts_header always;
add_header Content-Security-Policy $csp_header;
try_files $uri /buildInfo.json 404;
}
location /ui/info {
add_header Cache-Control "public, must-revalidate";
add_header Strict-Transport-Security $hsts_header always;
add_header Content-Security-Policy $csp_header;
try_files $uri /buildInfo.json 404;
}
# health check
location /health {
default_type application/json;
return 200 '{"status": "UP"}';
}
location /ui/health {
default_type application/json;
return 200 '{"status": "UP"}';
}
location /ui/config {
add_header Cache-Control "no-cache";
add_header X-Frame-Options "DENY";
add_header X-Content-Type-Options "nosniff";
add_header X-XSS-Protection "1; mode=block";
add_header Content-Security-Policy $csp_header;
try_files $uri /config.json 404;
}
location /config {
add_header Cache-Control "no-cache";
add_header X-Frame-Options "DENY";
add_header X-Content-Type-Options "nosniff";
add_header X-XSS-Protection "1; mode=block";
add_header Content-Security-Policy $csp_header;
try_files $uri /config.json 404;
}
# media, fonts
location ~* ([^/\\&\?]+\.+(jpg|jpeg|png|gif|eot|otf|webp|svg|ttf|woff|woff2))$ {
add_header Cache-Control "${STATIC_CACHE_CONTROL}";
add_header Strict-Transport-Security $hsts_header always;
add_header X-Content-Type-Options "nosniff";
add_header X-XSS-Protection "1; mode=block";
add_header Content-Security-Policy $csp_header;
try_files $uri /media/$1 404;
}
# assets
location ~* ([^/\\&\?]+\.+(js|css|ico))$ {
add_header Cache-Control "${STATIC_CACHE_CONTROL}";
add_header Strict-Transport-Security $hsts_header always;
add_header X-Content-Type-Options "nosniff";
add_header X-XSS-Protection "1; mode=block";
add_header Content-Security-Policy $csp_header;
try_files $uri /$1 404;
}
}
}