게임 4개 원래 이름으로, .5 + NPMplus 배포 구성
- 보석 상인 → 스플렌더, 벽 쌓기 길찾기 → 쿼리도, 숫자 타일 → 루미큐브, 주사위 땅따먹기 → 부루마불 - deploy/docker-compose.proxy.yml: Caddy 없이 앱만(.5:2970), HTTPS·헤더는 NPMplus - deploy/npmplus-advanced.conf: Caddyfile과 같은 보안 헤더 - 문서: 2026-10-06 결정, 배포 7절 (e2e 구십구 0 카드 방향 버튼 반영 포함) Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
25
deploy/docker-compose.proxy.yml
Normal file
25
deploy/docker-compose.proxy.yml
Normal file
@@ -0,0 +1,25 @@
|
||||
# App only, for a host that already has a reverse proxy in front (e.g. NPMplus on 192.168.10.3 → .5:2970).
|
||||
# The proxy terminates HTTPS and adds the security headers in deploy/npmplus-advanced.conf (same as the Caddyfile).
|
||||
# cd deploy && docker compose -f docker-compose.proxy.yml up -d --build
|
||||
name: joke-app
|
||||
services:
|
||||
app:
|
||||
build:
|
||||
context: ..
|
||||
dockerfile: deploy/Dockerfile
|
||||
image: boardgame-site:${APP_VERSION:-latest}
|
||||
restart: unless-stopped
|
||||
env_file: .env
|
||||
environment:
|
||||
TRUST_PROXY: "1"
|
||||
ports:
|
||||
- "${APP_PORT:-2970}:3000"
|
||||
volumes:
|
||||
- app-data:/data
|
||||
stop_grace_period: 15s
|
||||
logging:
|
||||
driver: json-file
|
||||
options: { max-size: "50m", max-file: "5" }
|
||||
|
||||
volumes:
|
||||
app-data:
|
||||
7
deploy/npmplus-advanced.conf
Normal file
7
deploy/npmplus-advanced.conf
Normal file
@@ -0,0 +1,7 @@
|
||||
# NPMplus proxy host "game.tkrmagid.kr" → Advanced. Same headers as deploy/Caddyfile.
|
||||
# HSTS is set by NPMplus itself (HSTS option on). /internal/* already returns 404 from the app.
|
||||
location /internal/ { return 404; }
|
||||
more_set_headers "X-Content-Type-Options: nosniff";
|
||||
more_set_headers "Referrer-Policy: strict-origin-when-cross-origin";
|
||||
more_set_headers "Content-Security-Policy: default-src 'self'; img-src 'self' https://cdn.discordapp.com data:; connect-src 'self' wss://game.tkrmagid.kr; style-src 'self' 'unsafe-inline'; font-src 'self'; frame-ancestors 'none'; base-uri 'self'; form-action 'self'";
|
||||
more_clear_headers Server;
|
||||
Reference in New Issue
Block a user