diff --git a/write-server/docker-compose.yml b/write-server/docker-compose.yml index 063fd85f..4d24dd71 100644 --- a/write-server/docker-compose.yml +++ b/write-server/docker-compose.yml @@ -54,6 +54,7 @@ services: - ./nginx/nginx.conf:/etc/nginx/nginx.conf:ro - ./nginx/conf.d:/etc/nginx/conf.d:ro - ./nginx/ssl:/etc/nginx/ssl:ro + - ./.htpasswd:/etc/nginx/.htpasswd:ro - ./logs/nginx:/var/log/nginx depends_on: write-server: diff --git a/write-server/nginx/conf.d/write-server.conf b/write-server/nginx/conf.d/write-server.conf index c102947b..6f47aa4f 100644 --- a/write-server/nginx/conf.d/write-server.conf +++ b/write-server/nginx/conf.d/write-server.conf @@ -1,35 +1,24 @@ # Write Server Nginx 站点配置 -# 反向代理配置 +# 反向代理配置 + Basic Auth 认证 -# HTTP 重定向到 HTTPS(可选) -# server { -# listen 80; -# server_name write.your-domain.com; -# return 301 https://$server_name$request_uri; -# } - -# 主站点配置 server { listen 80; - # listen 443 ssl http2; # 启用 HTTPS 时取消注释 - server_name write.your-domain.com; # 替换为你的域名 - - # SSL 配置(启用 HTTPS 时取消注释) - # ssl_certificate /etc/nginx/ssl/fullchain.pem; - # ssl_certificate_key /etc/nginx/ssl/privkey.pem; - # ssl_protocols TLSv1.2 TLSv1.3; - # ssl_ciphers HIGH:!aNULL:!MD5; - # ssl_prefer_server_ciphers on; + server_name _; # 匹配所有域名和 IP # 日志 access_log /var/log/nginx/write-server-access.log; error_log /var/log/nginx/write-server-error.log; - # 安全限制 - # 限制访问 IP(可选) - # allow 192.168.1.0/24; - # allow 10.0.0.0/8; - # deny all; + # Basic Auth 认证(保护管理后台) + auth_basic "Write Server Admin"; + auth_basic_user_file /etc/nginx/.htpasswd; + + # 健康检查(不需要认证) + location /health { + auth_basic off; + proxy_pass http://write-server:8016/api/stats; + access_log off; + } # 代理到 Write Server location / { @@ -46,30 +35,8 @@ server { # 超时设置 proxy_connect_timeout 60s; proxy_send_timeout 60s; - proxy_read_timeout 60s; - } - - # 静态资源缓存 - location ~* \.(js|css|png|jpg|jpeg|gif|ico|svg|woff|woff2|ttf|eot)$ { - proxy_pass http://write-server:8016; - expires 1y; - add_header Cache-Control "public, immutable"; - } - - # API 路径不缓存 - location /api/ { - proxy_pass http://write-server:8016; - proxy_http_version 1.1; - proxy_set_header Upgrade $http_upgrade; - proxy_set_header Connection 'upgrade'; - proxy_set_header Host $host; - proxy_set_header X-Real-IP $remote_addr; - proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; - proxy_set_header X-Forwarded-Proto $scheme; - proxy_cache_bypass $http_upgrade; - - # 禁止缓存 API 响应 - add_header Cache-Control "no-cache, no-store, must-revalidate"; + proxy_read_timeout 120s; + client_max_body_size 50m; } # 禁止访问隐藏文件 @@ -78,10 +45,4 @@ server { access_log off; log_not_found off; } - - # 健康检查端点 - location /health { - proxy_pass http://write-server:8016/api/stats; - access_log off; - } }