geo $geointel_trusted_forwarder { default 0; 127.0.0.0/8 1; ::1/128 1; 172.16.0.0/12 1; } map "$geointel_trusted_forwarder:$http_x_forwarded_proto" $geointel_forwarded_proto { default $scheme; "1:https" https; "1:http" http; } server { listen 80; server_name _; client_max_body_size 250m; proxy_read_timeout 600s; proxy_send_timeout 600s; add_header Content-Security-Policy "frame-ancestors 'none'" always; add_header X-Frame-Options "DENY" always; add_header X-Content-Type-Options "nosniff" always; add_header Referrer-Policy "strict-origin-when-cross-origin" always; add_header Permissions-Policy "camera=(), microphone=(), geolocation=()" always; root /usr/share/nginx/html; index index.html; location = /index.html { add_header Cache-Control "no-cache"; add_header Content-Security-Policy "frame-ancestors 'none'" always; add_header X-Frame-Options "DENY" always; add_header X-Content-Type-Options "nosniff" always; add_header Referrer-Policy "strict-origin-when-cross-origin" always; add_header Permissions-Policy "camera=(), microphone=(), geolocation=()" always; try_files /index.html =404; } location /assets/ { add_header Cache-Control "no-cache"; add_header Content-Security-Policy "frame-ancestors 'none'" always; add_header X-Frame-Options "DENY" always; add_header X-Content-Type-Options "nosniff" always; add_header Referrer-Policy "strict-origin-when-cross-origin" always; add_header Permissions-Policy "camera=(), microphone=(), geolocation=()" always; try_files $uri =404; } location /api/ { proxy_pass http://backend:8000/api/; proxy_http_version 1.1; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $geointel_forwarded_proto; } location = /health { proxy_pass http://backend:8000/health; proxy_http_version 1.1; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $geointel_forwarded_proto; } location = /health/live { proxy_pass http://backend:8000/health/live; proxy_http_version 1.1; proxy_set_header Host $host; } location = /health/ready { proxy_pass http://backend:8000/health/ready; proxy_http_version 1.1; proxy_set_header Host $host; } location / { try_files $uri $uri/ /index.html; } }