56 lines
2 KiB
Text
56 lines
2 KiB
Text
# Groupe Méditation — NGINX (seul, sans Apache)
|
|
# Sert les fichiers statiques + reverse proxy vers FastAPI
|
|
#
|
|
# Installation :
|
|
# sudo cp deploy/nginx-groupe-meditation.conf /etc/nginx/sites-available/groupe-meditation
|
|
# sudo ln -s /etc/nginx/sites-available/groupe-meditation /etc/nginx/sites-enabled/
|
|
# sudo nginx -t && sudo systemctl reload nginx
|
|
# sudo certbot --nginx -d groupe-meditation.87-16.org
|
|
|
|
server {
|
|
listen 80;
|
|
server_name groupe-meditation.87-16.org;
|
|
|
|
# ── Headers de sécurité ──
|
|
add_header X-Content-Type-Options nosniff always;
|
|
add_header X-Frame-Options DENY always;
|
|
add_header X-XSS-Protection "1; mode=block" always;
|
|
add_header Referrer-Policy strict-origin-when-cross-origin always;
|
|
|
|
# ── Backend API → FastAPI (Uvicorn sur port 8000) ──
|
|
location /api/ {
|
|
proxy_pass http://127.0.0.1:8000;
|
|
proxy_set_header Host $host;
|
|
proxy_set_header X-Real-IP $remote_addr;
|
|
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
|
proxy_set_header X-Forwarded-Proto $scheme;
|
|
|
|
# Rate limiting anti-brute force (PIN)
|
|
# Décommenter après avoir ajouté dans nginx.conf section http :
|
|
# limit_req_zone $binary_remote_addr zone=api_limit:10m rate=5r/s;
|
|
# limit_req zone=api_limit burst=10 nodelay;
|
|
}
|
|
|
|
# ── Frontend — fichiers statiques (React build) ──
|
|
root /var/www/groupe-meditation;
|
|
index index.html;
|
|
|
|
# Cache longue durée sur les assets (JS, CSS, images)
|
|
location ~* \.(js|css|png|jpg|svg|woff2|ico)$ {
|
|
expires 1y;
|
|
add_header Cache-Control "public, immutable";
|
|
try_files $uri =404;
|
|
}
|
|
|
|
# SPA routing : toute route qui n'est pas un fichier → index.html
|
|
location / {
|
|
try_files $uri $uri/ /index.html;
|
|
}
|
|
|
|
# Pas de cache sur index.html (pour que les mises à jour PWA passent)
|
|
location = /index.html {
|
|
add_header Cache-Control "no-cache, no-store, must-revalidate";
|
|
}
|
|
|
|
client_max_body_size 5M;
|
|
}
|