# SPA serving: static assets with long-lived caching, everything else # falls back to index.html (client-side routing). server { listen 8080; server_name _; root /usr/share/nginx/html; index index.html; gzip on; gzip_types text/css application/javascript application/json image/svg+xml; gzip_min_length 1024; location /healthz { add_header Content-Type text/plain; return 200 'ok'; } location /assets/ { # Vite emits content-hashed filenames — safe to cache forever. add_header Cache-Control "public, max-age=31536000, immutable"; try_files $uri =404; } location / { add_header Cache-Control "no-cache"; # Strict CSP (security.md, ADR 0016): everything self-hosted, zero # third-party origins — fonts, scripts, styles, and XHR/WebSocket all # from this origin only (the GDPR "zero external requests" posture). # `style-src 'unsafe-inline'` covers the app's inline style attributes # (CSS custom properties, layout); scripts are all external files. # font-src includes `data:` for the subsetted fonts Excalidraw embeds # into saved sketch SVGs (inlined by the plugin fallback renderer on # public pages). data: fonts trigger no network request, so the # zero-third-party-request guarantee (security.md) is unaffected. add_header Content-Security-Policy "default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'; font-src 'self' data:; img-src 'self' data: blob:; connect-src 'self'; worker-src 'self'; manifest-src 'self'; object-src 'none'; base-uri 'self'; frame-ancestors 'self'" always; add_header X-Content-Type-Options "nosniff" always; try_files $uri /index.html; } }