게임 4개 원래 이름으로, .5 + NPMplus 배포 구성

- 보석 상인 → 스플렌더, 벽 쌓기 길찾기 → 쿼리도, 숫자 타일 → 루미큐브, 주사위 땅따먹기 → 부루마불
- deploy/docker-compose.proxy.yml: Caddy 없이 앱만(.5:2970), HTTPS·헤더는 NPMplus
- deploy/npmplus-advanced.conf: Caddyfile과 같은 보안 헤더
- 문서: 2026-10-06 결정, 배포 7절 (e2e 구십구 0 카드 방향 버튼 반영 포함)

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
EJClaw
2026-10-06 22:16:32 +09:00
parent 7da06d1b27
commit 6390e3e64c
45 changed files with 143 additions and 78 deletions

View File

@@ -0,0 +1,25 @@
# App only, for a host that already has a reverse proxy in front (e.g. NPMplus on 192.168.10.3 → .5:2970).
# The proxy terminates HTTPS and adds the security headers in deploy/npmplus-advanced.conf (same as the Caddyfile).
# cd deploy && docker compose -f docker-compose.proxy.yml up -d --build
name: joke-app
services:
app:
build:
context: ..
dockerfile: deploy/Dockerfile
image: boardgame-site:${APP_VERSION:-latest}
restart: unless-stopped
env_file: .env
environment:
TRUST_PROXY: "1"
ports:
- "${APP_PORT:-2970}:3000"
volumes:
- app-data:/data
stop_grace_period: 15s
logging:
driver: json-file
options: { max-size: "50m", max-file: "5" }
volumes:
app-data:

View File

@@ -0,0 +1,7 @@
# NPMplus proxy host "game.tkrmagid.kr" → Advanced. Same headers as deploy/Caddyfile.
# HSTS is set by NPMplus itself (HSTS option on). /internal/* already returns 404 from the app.
location /internal/ { return 404; }
more_set_headers "X-Content-Type-Options: nosniff";
more_set_headers "Referrer-Policy: strict-origin-when-cross-origin";
more_set_headers "Content-Security-Policy: default-src 'self'; img-src 'self' https://cdn.discordapp.com data:; connect-src 'self' wss://game.tkrmagid.kr; style-src 'self' 'unsafe-inline'; font-src 'self'; frame-ancestors 'none'; base-uri 'self'; form-action 'self'";
more_clear_headers Server;