load_module modules/ngx_http_brotli_static_module.so; user nginx; worker_processes auto; error_log /var/log/nginx/error.log notice; pid /var/run/nginx.pid; events { worker_connections 1024; } http { include /etc/nginx/mime.types; default_type application/octet-stream; log_format main '$remote_addr - $remote_user [$time_local] "$request" ' '$status $body_bytes_sent "$http_referer" ' '"$http_user_agent" "$http_x_forwarded_for"'; access_log /var/log/nginx/access.log main; sendfile on; keepalive_timeout 65; #gzip-static on; proxy_cache_path /var/cache/nginx keys_zone=owl_cache:20m inactive=24h; upstream backend { # Within Kubernetes: server owlboard-backend:8460; # External to Kubernetes: #server 172.30.129.19:8460; # Within Docker: #server owlboard-backend:8460 } server { listen 80; listen [::]:80; server_name localhost; proxy_cache owl_cache; add_header Content-Security-Policy "default-src 'self'"; location / { root /usr/share/nginx/html; index index; gzip_static on; brotli_static on; error_page 500 502 503 504 /err/50x.html; error_page 404 /err/404; try_files $uri.html $uri $uri/index.html $uri/ =404; add_header Cache-Control "public, no-transform, max-age=1209600"; if ($uri ~* \.html$) { return 404; } } location /misc/ { proxy_pass http://backend; } location /api/ { proxy_pass http://backend; proxy_cache_key $scheme://$host$uri$is_args$query_string; proxy_ignore_headers Cache-Control; proxy_cache_valid 200 2m; # Evaluate whether 2m or 1m is more appropriate add_header Cache-Control "private, no-transform, max-age=120"; } } }