LoVisual/backend/deploy/nginx-visual.loki-code.dev.conf
loki5512344 4a722259a5
Some checks failed
CI / backend (cargo test + clippy) (push) Successful in 7m0s
CI / frontend (lint + test + build) (push) Failing after 26s
CI / mod (gradle test + checkFolderLimit) (push) Successful in 1m34s
deploy(nginx): serve the mod jar from nginx with a speed cap (750k per connection) and 2 connections per IP
2026-10-09 22:26:27 +02:00

64 lines
2.5 KiB
Text

server {
server_name visual.loki-code.dev;
root /var/www/visual.loki-code.dev/html;
index index.html;
# Forgejo's API sends no CORS headers, so the download page reads the
# release list through this cached proxy (5 min) instead of from the browser.
location = /api/releases {
proxy_pass https://git.wihuk.pro/api/v1/repos/boba/LoVisual/releases?limit=10;
proxy_ssl_server_name on;
proxy_set_header Host git.wihuk.pro;
proxy_set_header Authorization "";
proxy_set_header Cookie "";
proxy_hide_header Set-Cookie;
proxy_cache lv_releases;
proxy_cache_valid 200 5m;
proxy_cache_use_stale error timeout updating http_500 http_502 http_503;
add_header Cache-Control "public, max-age=60" always;
}
# The mod jar is served by nginx itself (not through the gateway) so the
# speed can be capped: ~6 Mbit/s per connection and at most 2 connections
# per client IP keep a flood of downloads from saturating the link.
location = /api/downloads/lovisual.jar {
alias /opt/lovisual/backend/downloads/lovisual.jar;
default_type application/java-archive;
add_header Content-Disposition 'attachment; filename="lovisual.jar"' always;
limit_rate 750k;
limit_conn lv_downloads 2;
limit_conn_status 429;
}
location = /api/downloads/lovisual.jar.sha256 {
alias /opt/lovisual/backend/downloads/lovisual.jar.sha256;
default_type text/plain;
}
location /api/ {
proxy_pass http://127.0.0.1:8080/;
proxy_http_version 1.1;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
# The backend scopes the refresh cookie to Path=/auth, but the frontend calls it
# under /api/auth/* through this proxy — without this rewrite the browser never
# sends the cookie back on /api/auth/refresh and the session is lost on reload.
proxy_cookie_path /auth /api/auth;
}
# Fingerprinted build output (assets/<name>-<hash>.js/.css/...) -- the filename changes
# whenever the content does, so it's safe to cache "forever"; a stale copy is never served
# under the old URL after a deploy.
location /assets/ {
add_header Cache-Control "public, max-age=31536000, immutable" always;
try_files $uri =404;
}
location / {
try_files $uri /index.html;
}
listen 80;
}