Files
2026-09-01 01:04:57 +01:00

60 lines
1.9 KiB
Nginx Configuration File

# /etc/nginx/sites-available/model.southwest-roleplay.dev
#
# Plain HTTP to start with. Run
# sudo certbot --nginx -d model.southwest-roleplay.dev
# and certbot adds the listen 443 / ssl_certificate lines and the redirect,
# the same way it manages the other sites on this box.
#
# Only /samp/skin/<id> and the assets that page needs are exposed; everything
# else returns 404. Model files are not served here at all - MODELS_BASE_URL
# points the browser straight at static.southwest-roleplay.com.
server {
listen 80;
listen [::]:80;
server_name model.southwest-roleplay.dev;
# Nothing caches in front of this origin, so compress here. three.module.js
# is 1.3 MB uncompressed. gzip_proxied is required: every response comes
# from the Node upstream, and nginx skips proxied responses without it.
gzip on;
gzip_proxied any;
gzip_types application/javascript;
gzip_min_length 1024;
location /samp/skin/ {
proxy_pass http://127.0.0.1:3000;
proxy_set_header Host $host;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
}
location /api/skin/ {
proxy_pass http://127.0.0.1:3000;
proxy_set_header Host $host;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
}
location /js/ {
proxy_pass http://127.0.0.1:3000;
}
location /vendor/ {
proxy_pass http://127.0.0.1:3000;
add_header Cache-Control "public, max-age=31536000, immutable";
}
# The catch-all below does not block certbot: the nginx plugin inserts a
# more specific location for /.well-known/acme-challenge/ while it runs.
# Only if you switch to the webroot plugin would you need this permanently:
#
# location ^~ /.well-known/acme-challenge/ {
# root /var/www/html;
# }
location / {
return 404;
}
}