Commit graph

29 commits

Author SHA1 Message Date
Noah Betzen
474bc19904
Add commented HSTS line to nginx site.conf 2023-03-30 17:04:11 -07:00
El RIDO
8796735e80
issue got moved
Co-authored-by: rugk <rugk+git@posteo.de>
2022-07-31 18:15:36 +02:00
El RIDO
d6cead99eb
disable header preventing opening links to self, fixes #959 2022-07-31 08:49:36 +02:00
El RIDO
90e746b111
remove duplicate Permission-Policy header, now set on the application level
6f3bb25b09
2022-07-18 18:11:45 +02:00
El RIDO
4afa86cb3e
move headers to static location block, makes fastcgi_hide_header unnecessary 2021-10-14 19:27:04 +02:00
El RIDO
25abb55cd0
move Cache-Control header to server block, making js location unnecessary 2021-10-13 19:55:02 +02:00
rugk
df4436b798
Fix syntax error in nginx config
This prevented the startup of the nginx server and thus the container.

Fixes https://github.com/PrivateBin/docker-nginx-fpm-alpine/issues/75
2021-10-09 17:24:10 +02:00
Sylvain Rabot
90b0271bf2
Add Cache-Control header with no-transform directive
This should avoid that proxies like Cloudflare and others break SRI.

Signed-off-by: Sylvain Rabot <sylvain@abstraction.fr>
2021-10-08 13:39:34 +02:00
El RIDO
0928070a04
allow image to run as any non-root user/group, fixes #10 2021-04-28 18:29:58 +02:00
El RIDO
453cff7c01
working on improving #29 2021-04-16 19:13:00 +02:00
El RIDO
7b367cad23
new security headers, recommended by ZAP scan #29 2021-04-05 18:21:55 +02:00
El RIDO
25104d083f
adapt to new nginx 1.18 folder structure 2021-01-17 09:13:47 +01:00
El RIDO
9582113c42
enable ipv6 listening 2020-04-28 07:13:40 +02:00
El RIDO
d83d136f45
remove backwards compatibility with port 80 to drop setcap use, closes #15 2020-04-28 07:10:27 +02:00
El RIDO
79b2d68bf7
updating paths for Alpine 3.11 2019-12-21 16:38:01 +01:00
El RIDO
0c1a2e565c
changing default port to 8080, keeping port 80 for backwards compatibility. updating documentation. ensure the image can be run as root user and services drop privileges, fixes #11 2019-12-07 09:20:39 +01:00
El RIDO
d393fc5c89
increasing file upload support to 10 MiB, the new default in PrivateBin 1.3.1 and documenting how this can be increased further, fixes #7 2019-09-23 07:42:14 +02:00
El RIDO
a1d92a013e
switching from supervisord to s6-overlay, less dependencies and lets us run as non-root 2019-09-23 07:19:50 +02:00
El RIDO
93da5b24a8 Allow up to 3 MiB payload in nginx, privatebin defaults to 2 MiB 2018-06-19 13:23:28 +02:00
El RIDO
f18e51f132 privilege separation, ensuring nginx may access it's own tmp folder and only read /var/www 2018-06-19 13:16:07 +02:00
Simon Rupf
14ea837229 switching to unix socket for communication between nginx & php-fpm, improves performance and fixes #1 2018-06-03 20:33:50 +02:00
El RIDO
aa1cabad94 trimmed down docker image, added GD support, enabled file upload 2018-05-27 23:22:08 +02:00
Michael Contento
40cb55b3d5 Move default access_log config into own overwritable file 2017-04-27 16:02:19 +02:00
Michael Contento
7078cdfe7d Ensure nginx writes properly to stdout/stderr 2017-04-27 15:04:55 +02:00
Michael Contento
4b6ebf31c6 Add custom "hook folders" /etc/nginx/{server.d,location.d} 2017-03-29 19:40:24 +02:00
Michael Contento
023f04c7a4 refactor REDIRECT_PROTO and add some examples 2017-03-29 19:23:29 +02:00
Michael Contento
a0929f0059 support php for nested routes 2017-03-28 21:28:32 +02:00
Michael Contento
48724219b3 add REDIRECT_SCHEME to support running this image behind a SSL-termination proxy 2017-03-28 20:13:15 +02:00
Michael Contento
6181af05f9 initial commit 2017-03-28 19:46:14 +02:00