# nginx in front of Sirius Press. # # Static files are served here; only PHP is proxied. That matters more than # usual for this fork: the wallet library and the login script are plain files, # and routing them through PHP-FPM would put a process on the critical path of # every sign-in for no reason. # # TLS is not configured here. Most people putting this on a VPS already have a # reverse proxy, Caddy, or a Cloudflare tunnel in front; baking half a # certificate story into this file would fight all three. docs/install.md # covers the two common arrangements. server { listen 80 default_server; server_name _; root /var/www/html; index index.php; client_max_body_size 64m; # WordPress hands its own version out in a header; there is no reason to # advertise nginx's too. server_tokens off; add_header X-Content-Type-Options "nosniff" always; add_header X-Frame-Options "SAMEORIGIN" always; add_header Referrer-Policy "strict-origin-when-cross-origin" always; # --- things that should never be reachable ------------------------------- # wp-config.php holds the database password and SIRIUS_PRESS_KEY, which is # what the stored publishing phrase is encrypted under. A misconfiguration # that serves it as text hands over the site's wallet. location = /wp-config.php { deny all; } location ~* /wp-config.*\.php$ { deny all; } location ~ /\.(?!well-known) { deny all; } location = /xmlrpc.php { deny all; } location ~* /(?:uploads|files)/.*\.php$ { deny all; } location ~* ^/wp-content/.*\.(?:sql|log|bak|swp)$ { deny all; } # --- routing ------------------------------------------------------------- location / { try_files $uri $uri/ /index.php?$args; } location ~ \.php$ { try_files $uri =404; include fastcgi_params; fastcgi_pass app:9000; fastcgi_index index.php; fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name; fastcgi_param HTTPS $http_x_forwarded_proto if_not_empty; # Signature verification on a BCMath host takes a few hundred # milliseconds, and a full static export batch takes longer. The # default 60s would turn a slow first login into a 504. fastcgi_read_timeout 300; fastcgi_buffers 16 16k; fastcgi_buffer_size 32k; } # --- caching ------------------------------------------------------------- location ~* \.(?:css|js|mjs|woff2?|ttf|otf|eot|svg|png|jpe?g|gif|webp|avif|ico)$ { expires 30d; access_log off; add_header Cache-Control "public, max-age=2592000"; try_files $uri =404; } # The login screen must never be cached anywhere: the challenge it carries # is single-use, and a cached copy would hand every visitor a nonce that # has already been spent. location = /wp-login.php { add_header Cache-Control "no-store, no-cache, must-revalidate" always; include fastcgi_params; fastcgi_pass app:9000; fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name; fastcgi_param HTTPS $http_x_forwarded_proto if_not_empty; fastcgi_read_timeout 300; } }