load_module modules/ngx_http_brotli_static_module.so; load_module modules/ngx_http_brotli_filter_module.so; user nginx; worker_processes auto; error_log /var/log/nginx/error.log notice; pid /var/run/nginx.pid; events { worker_connections 1024; } http { include /etc/nginx/mime.types; default_type application/octet-stream; log_format main '$remote_addr - $remote_user [$time_local] "$request" ' '$status $body_bytes_sent "$http_referer" ' '"$http_user_agent" "$http_x_forwarded_for"'; access_log /dev/stdout main; sendfile on; keepalive_timeout 65; #gzip-static on; proxy_cache_path /var/cache/nginx keys_zone=owl_cache:20m inactive=24h; upstream backend { # Within Kubernetes: #server owlboard-backend:8460; # External to Kubernetes: server 172.30.129.19:8460; # Within Docker: #server owlboard-backend:8460 } server { listen 80; listen [::]:80; server_name localhost; proxy_cache owl_cache; add_header Content-Security-Policy "default-src 'self'"; location / { root /usr/share/nginx/html; index /index.html; gzip_static on; brotli_static on; error_page 500 502 503 504 /err/50x.html; try_files $uri $uri/ /index.html; add_header Cache-Control "public, no-transform, max-age=1209600"; rewrite ^([^.]*[^/])$ $1/ permanent; } location /misc/ { proxy_pass http://backend; brotli on; brotli_comp_level 6; brotli_types *; gzip on; gzip_comp_level 6; gzip_types *; } location /api/ { proxy_pass http://backend; brotli on; brotli_comp_level 6; brotli_types *; gzip on; gzip_comp_level 6; gzip_types *; proxy_cache_key $scheme://$host$uri$is_args$query_string; proxy_ignore_headers Cache-Control; proxy_cache_valid 200 2m; # Evaluate whether 2m or 1m is more appropriate add_header Cache-Control "private, no-transform, max-age=120"; } } }