# /etc/nginx/sites-available/model.southwest-roleplay.dev # # Only /samp/skin/ and the assets that page needs are exposed. Everything # else, including the root, returns 404. certbot rewrites this for 443 and # leaves the location blocks untouched. server { listen 80; server_name model.southwest-roleplay.dev; location /samp/skin/ { proxy_pass http://127.0.0.1:3000; proxy_set_header Host $host; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; } location /api/skin/ { proxy_pass http://127.0.0.1:3000; proxy_set_header Host $host; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; } location /js/ { proxy_pass http://127.0.0.1:3000; } location /vendor/ { proxy_pass http://127.0.0.1:3000; add_header Cache-Control "public, max-age=31536000, immutable"; } # Path A only: model files come from S3 through nginx, so they stay # same-origin and no bucket CORS rule is needed. Delete this block if you # set MODELS_BASE_URL and let the browser fetch the CDN directly. location /models/ { proxy_pass https://your-bucket.s3.eu-west-2.amazonaws.com/skins/; proxy_set_header Host your-bucket.s3.eu-west-2.amazonaws.com; proxy_hide_header x-amz-id-2; proxy_hide_header x-amz-request-id; proxy_hide_header x-amz-server-side-encryption; add_header Cache-Control "public, max-age=31536000, immutable"; } location / { return 404; } }