# Canonical nginx config for the EpicNabbo CMS edge. # Source of truth: repository deployment/proxy/nginx-cms.conf (the site block) # and this file. Installed/synced by scripts/nginx-sync.sh so it cannot be # lost again while nginx keeps running on an in-memory copy. # # Traffic path: Cloudflare -> Traefik (:443) -> nginx (:9443) -> CMS (:3002), # with direct Cloudflare-origin and game-client (ws.epicnabbo.nl) connections # also terminating on :9443. # nginx is the last layer that can still rewrite Cache-Control, so it owns the # headers it adds explicitly; everything proxied to the CMS is passed through # untouched unless this file says otherwise. user www-data; worker_processes auto; pid /run/nginx.pid; error_log /var/log/nginx/error.log warn; events { worker_connections 2048; use epoll; } http { include /etc/nginx/mime.types; default_type application/octet-stream; # Compression is done once, at the edge (Traefik / Cloudflare). Enabling # gzip here too would double-compress proxied responses and fight Vary. gzip off; sendfile on; tcp_nopush on; server_tokens off; keepalive_timeout 30s; client_max_body_size 64m; client_body_buffer_size 16k; client_header_buffer_size 1k; large_client_header_buffers 4 8k; # Blue/green cutover: ci-deploy.sh writes the active upstream here, and # `proxy_pass http://cms_app` below follows it via graceful nginx -s reload. upstream cms_app { include /etc/nginx/snippets/cms_upstream_servers.conf; } # Cache policy maps and server blocks live in the site file so they are # synced together and can never drift apart. include /etc/nginx/sites-enabled/*.conf; # Trusted edge / real-IP handling (regenerated by scripts/cf-ips-sync.sh # from the live Cloudflare ranges; installed via scripts/nginx-sync.sh). include /etc/nginx/conf.d/cloudflare-ips.conf; }