Release v1.0.0
Some checks failed
CI / Migrations, tests, build, and audit (push) Failing after 10m7s
CI / Production gate and container images (push) Successful in 20m35s

This commit is contained in:
2026-07-31 14:21:43 +08:00
commit 36f466ba11
187 changed files with 98907 additions and 0 deletions

View File

@@ -0,0 +1,83 @@
upstream frameflow_api {
server api:8787;
keepalive 32;
}
server {
listen 80 default_server;
server_name ${APP_HOST};
root /usr/share/nginx/html;
index index.html;
client_max_body_size ${MAX_UPLOAD_SIZE};
add_header X-Content-Type-Options nosniff always;
add_header X-Frame-Options DENY always;
add_header Referrer-Policy strict-origin-when-cross-origin always;
add_header Permissions-Policy "camera=(), geolocation=(), microphone=()" always;
location /api/ {
proxy_pass http://frameflow_api;
proxy_http_version 1.1;
proxy_set_header Host $http_host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_set_header Connection "";
}
location /health/ {
proxy_pass http://frameflow_api;
proxy_http_version 1.1;
proxy_set_header Host $http_host;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
}
location = /metrics {
return 404;
}
location ~* \.(?:css|js|jpg|jpeg|png|webp|avif|svg|ico|woff2?)$ {
try_files $uri =404;
expires 7d;
add_header Cache-Control "public, max-age=604800, immutable";
}
location / {
try_files $uri $uri/ /index.html;
add_header Cache-Control "no-cache";
}
}
server {
listen 80;
server_name ${MEDIA_HOST};
client_max_body_size ${MAX_UPLOAD_SIZE};
location = /minio/v2/metrics {
return 404;
}
location ^~ /minio/v2/metrics/ {
return 404;
}
location = /minio/v3/metrics {
return 404;
}
location ^~ /minio/v3/metrics/ {
return 404;
}
location / {
proxy_pass http://minio:9000;
proxy_http_version 1.1;
proxy_request_buffering off;
proxy_buffering off;
proxy_set_header Host $http_host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
}
}