feat(ops): Caddy fragment for mechanic.pptaxi.ru
This commit is contained in:
@@ -0,0 +1,39 @@
|
|||||||
|
# Caddy fragment for Premium Mechanic PWA on mechanic.pptaxi.ru.
|
||||||
|
# Apply on VDS 100.64.0.12 by copying/including into /etc/caddy/Caddyfile
|
||||||
|
# (or /etc/caddy/sites-enabled/ if the main Caddyfile uses imports).
|
||||||
|
#
|
||||||
|
# Assumes:
|
||||||
|
# - TaxiDashboard backend listens on 127.0.0.1:8000
|
||||||
|
# - Frontend PWA build is rsynced to /opt/sites/mechanic-pwa/dist/
|
||||||
|
|
||||||
|
mechanic.pptaxi.ru {
|
||||||
|
encode gzip zstd
|
||||||
|
|
||||||
|
# PWA: pass /api/* to the backend so the frontend can use relative URLs.
|
||||||
|
handle /api/* {
|
||||||
|
reverse_proxy 127.0.0.1:8000
|
||||||
|
}
|
||||||
|
|
||||||
|
# PWA static files with SPA fallback to index.html.
|
||||||
|
handle {
|
||||||
|
root * /opt/sites/mechanic-pwa/dist
|
||||||
|
try_files {path} /index.html
|
||||||
|
file_server
|
||||||
|
}
|
||||||
|
|
||||||
|
log {
|
||||||
|
output file /var/log/caddy/mechanic.pptaxi.ru.log {
|
||||||
|
roll_size 50mb
|
||||||
|
roll_keep 5
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
header {
|
||||||
|
# Basic security headers for a PWA
|
||||||
|
Referrer-Policy strict-origin-when-cross-origin
|
||||||
|
X-Content-Type-Options nosniff
|
||||||
|
X-Frame-Options DENY
|
||||||
|
# Camera permission for our origin only
|
||||||
|
Permissions-Policy "camera=(self), microphone=(self), geolocation=()"
|
||||||
|
}
|
||||||
|
}
|
||||||
Reference in New Issue
Block a user