# Static serving for the ModelForge operator console. # # The console is a single-page application that talks to the control plane directly from the # browser, so this server only ever returns files from its own build output. It proxies nothing, # which keeps it out of the request path between an operator and an authenticated admin route. # # nginx only inherits `add_header` into a location that declares none of its own, so the security # headers are included in every location rather than set once on the server. Setting them at the # server level alone silently drops them from exactly the responses that matter most. server { listen 3000; server_name _; root /usr/share/nginx/html; index index.html; server_tokens off; # The console holds an operator credential in memory. These headers cost nothing and remove # the easiest ways to get someone else's script or frame near it. include /etc/nginx/conf.d/security-headers.inc; # Hashed assets are immutable; the entry document must never be cached, or an operator can be # left driving a console that no longer matches the control plane it is talking to. location /assets/ { include /etc/nginx/conf.d/security-headers.inc; add_header Cache-Control "public, max-age=31536000, immutable" always; try_files $uri =404; } location = /index.html { include /etc/nginx/conf.d/security-headers.inc; add_header Cache-Control "no-store" always; } location / { include /etc/nginx/conf.d/security-headers.inc; add_header Cache-Control "no-store" always; try_files $uri $uri/ /index.html; } # Nothing else is served: no directory listings, no dotfiles, no source maps by path guess. location ~ /\. { deny all; } }