types { text/javascript js mjs; application/pdf pdf; } server { listen 80; server_name _; # Block internal inter-app endpoints from public access location /kitchen/api/internal/ { return 403; } # Central auth proxy — must be before the general /api/ block location /kitchen/api/auth/ { proxy_pass http://10.10.10.101:3001/api/auth/; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; } # App backend (FastAPI on port 8000) # /kitchen/api/foo → backend:8000/api/foo (prefix preserved) location /kitchen/api/ { proxy_pass http://backend:8000/api/; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header Cookie $http_cookie; proxy_read_timeout 600s; proxy_connect_timeout 30s; client_max_body_size 800m; } # Health location /kitchen/health { proxy_pass http://backend:8000/health; } # Static assets — long cache location ~* /kitchen/assets/ { root /usr/share/nginx/html; expires 1y; add_header Cache-Control "public, immutable"; } # SPA fallback location /kitchen/ { root /usr/share/nginx/html; try_files $uri $uri/ /kitchen/index.html; } }