Gitea Actions Runner Test / test-job (push) Successful in 0s
CI / check (push) Successful in 28s
CI / tests-unit (push) Successful in 1m39s
CI / tests-integration (push) Successful in 1m41s
CI / tests-ui (push) Successful in 2m27s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 3m35s
Rebuild production nginx from the repo (deployment/proxy/*) with a single Cache-Control owner per route: the app stays the source, nginx only manages headers, and Cloudflare stores the public API allowlist at the edge. - deployment/proxy: nginx.conf, mime.types, nginx-cms.conf and the blue/green upstream snippet; config backed by scripts/nginx-sync.sh (idempotent install + reload, --check/--force). - nginx serves Cache-Tag headers on the public allowlist (cms-public), gamedata, client and camera responses so the edge and purge stay in sync. - src/lib/edge-cache.ts + tests: coalesced, fire-and-forget edge purges that no-op unless Cloudflare is configured; scripts/cf-purge.sh and cf-setup-cache.sh create and purge the cache rule. - src/lib/cloudflare-api.ts: purgeCacheByTags/purgeCacheByUrls. - Purge hooks after catalog exports (public + gamedata) and on shop, team, guild, photo and rare-values edits; ci-deploy purges after each release. - src/proxy.ts excludes the imaging/images docs from the middleware matcher.
49 lines
1.6 KiB
Nginx Configuration File
49 lines
1.6 KiB
Nginx Configuration File
# Canonical nginx config for the EpicNabbo CMS edge.
|
|
# Source of truth: repository deployment/proxy/nginx-cms.conf (the site block)
|
|
# and this file. Installed/synced by scripts/nginx-sync.sh so it cannot be
|
|
# lost again while nginx keeps running on an in-memory copy.
|
|
#
|
|
# Traffic path: Cloudflare -> Traefik (:443) -> nginx (:9443) -> CMS (:3002).
|
|
# nginx is the last layer that can still rewrite Cache-Control, so it owns the
|
|
# headers it adds explicitly; everything proxied to the CMS is passed through
|
|
# untouched unless this file says otherwise.
|
|
|
|
user www-data;
|
|
worker_processes auto;
|
|
pid /run/nginx.pid;
|
|
|
|
error_log /var/log/nginx/error.log warn;
|
|
|
|
events {
|
|
worker_connections 2048;
|
|
use epoll;
|
|
}
|
|
|
|
http {
|
|
include /etc/nginx/mime.types;
|
|
default_type application/octet-stream;
|
|
|
|
# Compression is done once, at the edge (Traefik / Cloudflare). Enabling
|
|
# gzip here too would double-compress proxied responses and fight Vary.
|
|
gzip off;
|
|
|
|
sendfile on;
|
|
tcp_nopush on;
|
|
server_tokens off;
|
|
keepalive_timeout 30s;
|
|
|
|
client_max_body_size 64m;
|
|
client_body_buffer_size 16k;
|
|
client_header_buffer_size 1k;
|
|
large_client_header_buffers 4 8k;
|
|
|
|
# Blue/green cutover: ci-deploy.sh writes the active upstream here, and
|
|
# `proxy_pass http://cms_app` below follows it via graceful nginx -s reload.
|
|
upstream cms_app {
|
|
include /etc/nginx/snippets/cms_upstream_servers.conf;
|
|
}
|
|
|
|
# Cache policy maps and server blocks live in the site file so they are
|
|
# synced together and can never drift apart.
|
|
include /etc/nginx/sites-enabled/*.conf;
|
|
} |