This commit is contained in:
jack
2026-09-01 01:04:57 +01:00
parent d3d1c12b28
commit 65c6aaac5b
11 changed files with 1068 additions and 106 deletions
+5 -2
View File
@@ -4,13 +4,16 @@
{
"Effect": "Allow",
"Action": "s3:GetObject",
"Resource": "arn:aws:s3:::your-bucket/skins/*"
"Resource": [
"arn:aws:s3:::your-bucket/skins/*",
"arn:aws:s3:::your-bucket/vehicles/*"
]
},
{
"Effect": "Allow",
"Action": "s3:ListBucket",
"Resource": "arn:aws:s3:::your-bucket",
"Condition": { "StringLike": { "s3:prefix": "skins/*" } }
"Condition": { "StringLike": { "s3:prefix": ["skins/*", "vehicles/*"] } }
}
]
}
+24 -14
View File
@@ -1,13 +1,27 @@
# /etc/nginx/sites-available/model.southwest-roleplay.dev
#
# Only /samp/skin/<id> and the assets that page needs are exposed. Everything
# else, including the root, returns 404. certbot rewrites this for 443 and
# leaves the location blocks untouched.
# Plain HTTP to start with. Run
# sudo certbot --nginx -d model.southwest-roleplay.dev
# and certbot adds the listen 443 / ssl_certificate lines and the redirect,
# the same way it manages the other sites on this box.
#
# Only /samp/skin/<id> and the assets that page needs are exposed; everything
# else returns 404. Model files are not served here at all - MODELS_BASE_URL
# points the browser straight at static.southwest-roleplay.com.
server {
listen 80;
listen [::]:80;
server_name model.southwest-roleplay.dev;
# Nothing caches in front of this origin, so compress here. three.module.js
# is 1.3 MB uncompressed. gzip_proxied is required: every response comes
# from the Node upstream, and nginx skips proxied responses without it.
gzip on;
gzip_proxied any;
gzip_types application/javascript;
gzip_min_length 1024;
location /samp/skin/ {
proxy_pass http://127.0.0.1:3000;
proxy_set_header Host $host;
@@ -31,17 +45,13 @@ server {
add_header Cache-Control "public, max-age=31536000, immutable";
}
# Path A only: model files come from S3 through nginx, so they stay
# same-origin and no bucket CORS rule is needed. Delete this block if you
# set MODELS_BASE_URL and let the browser fetch the CDN directly.
location /models/ {
proxy_pass https://your-bucket.s3.eu-west-2.amazonaws.com/skins/;
proxy_set_header Host your-bucket.s3.eu-west-2.amazonaws.com;
proxy_hide_header x-amz-id-2;
proxy_hide_header x-amz-request-id;
proxy_hide_header x-amz-server-side-encryption;
add_header Cache-Control "public, max-age=31536000, immutable";
}
# The catch-all below does not block certbot: the nginx plugin inserts a
# more specific location for /.well-known/acme-challenge/ while it runs.
# Only if you switch to the webroot plugin would you need this permanently:
#
# location ^~ /.well-known/acme-challenge/ {
# root /var/www/html;
# }
location / {
return 404;