Files
wecom_it_smart_desk/nginx/nginx.conf
T

709 lines
31 KiB
Nginx Configuration File
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# =============================================================================
# 企微IT智能服务台 — Nginx 反向代理配置
# =============================================================================
# 部署说明:
# - 本 nginx 运行在 Docker 容器内,负责统一路由
# - 数据查询平台运行在**另一台主机**,通过 proxy_pass 转发
# - 修改 DATAQUERY_HOST 为数据平台实际 IP 地址
#
# 路由规则:
# /itdesk/ → H5 员工端静态文件
# /itagent/ → 坐席工作台静态文件
# /itadmin/ → 管理后台静态文件
# /itterminal/ → 小鱼终端大屏静态文件
# /itportal/meetingroom/ → 会议室API(终端+H5共用,代理到后端)
# /api/ → 后端 FastAPI(容器名 backend:8000
# /ws/ → WebSocket(容器名 backend:8000,支持升级)
# / → IT 数据查询平台(远程主机)
#
# 2026-08-03 fix:
# - /itportal/ 静态前端块已移除(portal 源码在 commit bea288e4 已删除,dist 不存在导致 500)
# - 仅保留 /itportal/meetingroom/ API 块
# =============================================================================
events {
worker_connections 1024;
}
http {
include /etc/nginx/mime.types;
default_type application/octet-stream;
# ------------------------------------------------------------------
# 日志格式
# ------------------------------------------------------------------
log_format main '$remote_addr - $remote_user [$time_local] "$request" '
'$status $body_bytes_sent "$http_referer" '
'"$http_user_agent" "$http_x_forwarded_for"';
access_log /var/log/nginx/access.log main;
error_log /var/log/nginx/error.log warn;
# ------------------------------------------------------------------
# 基础配置
# ------------------------------------------------------------------
sendfile on;
tcp_nopush on;
tcp_nodelay on;
keepalive_timeout 65;
types_hash_max_size 2048;
client_max_body_size 50m; # 支持文件上传(企微媒体文件)
# ------------------------------------------------------------------
# Gzip 压缩(前端静态资源)
# ------------------------------------------------------------------
gzip on;
gzip_vary on;
gzip_min_length 1024;
gzip_types text/plain text/css text/xml text/javascript
application/javascript application/xml+rss
application/json application/ld+json;
# =================================================================
# 上游服务定义(Docker 内部网络)
# =================================================================
upstream backend_api {
server backend:8000;
}
# =================================================================
# HTTPS 服务:监听 443 端口(SSL
# =================================================================
server {
listen 80;
listen 443 ssl;
server_name itsupport.servyou.com.cn;
# SSL 证书配置(使用通配符证书 *.servyou.com.cn
ssl_certificate /etc/nginx/ssl/servyou.com.cn.crt;
ssl_certificate_key /etc/nginx/ssl/servyou.com.cn.key;
ssl_protocols TLSv1.2 TLSv1.3;
ssl_ciphers HIGH:!aNULL:!MD5;
ssl_prefer_server_ciphers on;
ssl_session_cache shared:SSL:10m;
ssl_session_timeout 1d;
# ------------------------------------------------------------------
# H5 员工端 — /itdesk/
# ------------------------------------------------------------------
location /itdesk/ {
alias /usr/share/nginx/html/itdesk/;
index index.html;
try_files $uri /itdesk/index.html;
}
# ------------------------------------------------------------------
# 坐席工作台 — /itagent/
# ------------------------------------------------------------------
location /itagent/ {
alias /usr/share/nginx/html/itagent/;
index index.html;
try_files $uri /itagent/index.html;
}
# ------------------------------------------------------------------
# 管理后台 — /itadmin/
# ------------------------------------------------------------------
location /itadmin/ {
alias /usr/share/nginx/html/itadmin/;
index index.html;
try_files $uri /itadmin/index.html;
}
# ------------------------------------------------------------------
# 小鱼终端大屏 — /itterminal/
# ------------------------------------------------------------------
location /itterminal/ {
alias /usr/share/nginx/html/itterminal/;
index index.html;
try_files $uri /itterminal/index.html;
}
# ------------------------------------------------------------------
# 会议室 API — /itportal/meetingroom/
# 说明:终端和H5共用的会议室预定/报修/指南API
# 必须在 /itportal/ 静态文件之前匹配(nginx最长前缀优先)
# ------------------------------------------------------------------
location /itportal/meetingroom/ {
proxy_pass http://backend_api;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_connect_timeout 60s;
proxy_send_timeout 300s;
proxy_read_timeout 300s;
}
# ------------------------------------------------------------------
# ⚠️ /itportal/ 静态前端块已移除 (2026-08-03 fix)
# 历史: portal 源码 frontend-portal/ 在 commit bea288e4 (2026-07-11) 已删除,
# dist 目录不存在, alias 指向空目录导致 try_files 全部 500。
# 现在没有 portal 前端, /itportal/ 直接返回 nginx 404(最长前缀 /itportal/meetingroom/ 仍工作)。
# 关联 issue: 滴答清单任务 6a6bfc29e4b06440c36701e1 (P0)
# ------------------------------------------------------------------
# ------------------------------------------------------------------
# 后端 API — /api/
# ------------------------------------------------------------------
# ------------------------------------------------------------------
# P0-NEW11 安全加固:禁止公网访问 API 文档端点(字典级暴露止血)
# 仅对精确路径返回 404;业务 /api/ 其余路径不受影响
# ------------------------------------------------------------------
location = /api/openapi.json { return 404; }
location = /api/docs { return 404; }
location = /api/redoc { return 404; }
location = /api/docs/oauth2-redirect { return 404; }
# ============================================================
# 预生产测试通道 (REQ-通用-006) - nginx 内网闸门
# 仅内网可访问 /api/dev/*,公网 403。部署后须双向 curl 验证
# ============================================================
location /api/dev/ {
allow 10.0.0.0/8;
allow 172.16.0.0/12;
allow 192.168.0.0/16;
deny all;
proxy_pass http://backend_api/;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
}
# ------------------------------------------------------------------
# P0-NEW9/10 安全加固:禁止公网访问调试/诊断端点
# 与 P0-NEW11 同源治理:nginx 边缘层兜底
# 仅 test-/debug- 与 metrics/version 返回 404/health、/ready 保留供探针
# ------------------------------------------------------------------
location ~ ^/api/(test-|debug/) { return 404; }
location = /api/metrics { return 404; }
location = /api/version { return 404; }
location /api/ {
proxy_pass http://backend_api/;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_connect_timeout 60s;
proxy_send_timeout 300s;
proxy_read_timeout 300s;
}
# ------------------------------------------------------------------
# H5 用户端 — /h5/
# 说明:H5 是静态前端应用,必须配置为静态文件服务(alias)!
# ⚠️ 禁止改为 proxy_pass,否则返回 404(后端无 /h5/ 路由)
# 关联 CASECASE-20260714-02 / CASE-20260716-01
# ------------------------------------------------------------------
# === 2026-08-06 WAF path-cache bypass: versioned entry ===
# 精确匹配 /h5(无斜杠)→ 302 到 /h5/go,防 404
location = /h5 {
return 302 /h5/go;
}
location = /h5/go {
add_header Cache-Control "no-store" always;
return 302 /h5/v20260811/$is_args$args;
add_header Strict-Transport-Security "max-age=31536000" always;
add_header X-Frame-Options "SAMEORIGIN" always;
add_header X-XSS-Protection "1; mode=block" always;
add_header Referrer-Policy "no-referrer-when-downgrade" always;
add_header Permissions-Policy "geolocation=(), microphone=(), camera=()" always;
add_header Cross-Origin-Opener-Policy "same-origin" always;
add_header X-Content-Type-Options "nosniff" always;
}
# === /itservice/ 前缀(替换 /h5/,绕开 WAF 旧缓存) ===
location = /itservice/go {
add_header Cache-Control "no-store" always;
return 302 /itservice/v20260811/$is_args$args;
add_header Strict-Transport-Security "max-age=31536000" always;
add_header X-Frame-Options "SAMEORIGIN" always;
add_header X-XSS-Protection "1; mode=block" always;
add_header Referrer-Policy "no-referrer-when-downgrade" always;
add_header Permissions-Policy "geolocation=(), microphone=(), camera=()" always;
add_header Cross-Origin-Opener-Policy "same-origin" always;
add_header X-Content-Type-Options "nosniff" always;
}
location /itservice/v20260807f/ {
alias /usr/share/nginx/html/h5/;
index index.html;
try_files $uri /itservice/v20260807f/index.html;
add_header Cache-Control "no-store" always;
add_header Strict-Transport-Security "max-age=31536000" always;
add_header X-Frame-Options "SAMEORIGIN" always;
add_header X-XSS-Protection "1; mode=block" always;
add_header Referrer-Policy "no-referrer-when-downgrade" always;
add_header Permissions-Policy "geolocation=(), microphone=(), camera=()" always;
add_header Cross-Origin-Opener-Policy "same-origin" always;
add_header X-Content-Type-Options "nosniff" always;
}
location /itservice/v20260808/ {
alias /usr/share/nginx/html/h5/;
index index.html;
try_files $uri /itservice/v20260808/index.html;
add_header Cache-Control "no-store" always;
add_header Strict-Transport-Security "max-age=31536000" always;
add_header X-Frame-Options "SAMEORIGIN" always;
}
location /itservice/v20260811/ {
alias /usr/share/nginx/html/h5/;
index index.html;
try_files $uri /itservice/v20260811/index.html;
add_header Cache-Control "no-store" always;
add_header Strict-Transport-Security "max-age=31536000" always;
add_header X-Frame-Options "SAMEORIGIN" always;
}
location /itservice/ {
alias /usr/share/nginx/html/h5/;
index index.html;
try_files $uri $uri/ /itservice/index.html =404;
add_header Cache-Control "no-store" always;
add_header Strict-Transport-Security "max-age=31536000" always;
add_header X-Frame-Options "SAMEORIGIN" always;
add_header X-XSS-Protection "1; mode=block" always;
add_header Referrer-Policy "no-referrer-when-downgrade" always;
add_header Permissions-Policy "geolocation=(), microphone=(), camera=()" always;
add_header Cross-Origin-Opener-Policy "same-origin" always;
add_header X-Content-Type-Options "nosniff" always;
}
location = /itservice {
return 302 /itservice/go;
}
location /h5/v20260807f/ {
alias /usr/share/nginx/html/h5/;
index index.html;
try_files $uri /h5/v20260807f/index.html;
add_header Cache-Control "no-store" always;
add_header Strict-Transport-Security "max-age=31536000" always;
add_header X-Frame-Options "SAMEORIGIN" always;
add_header X-XSS-Protection "1; mode=block" always;
add_header Referrer-Policy "no-referrer-when-downgrade" always;
add_header Permissions-Policy "geolocation=(), microphone=(), camera=()" always;
add_header Cross-Origin-Opener-Policy "same-origin" always;
add_header X-Content-Type-Options "nosniff" always;
}
location /h5/v20260808/ {
alias /usr/share/nginx/html/h5/;
index index.html;
try_files $uri /h5/v20260808/index.html;
add_header Cache-Control "no-store" always;
add_header Strict-Transport-Security "max-age=31536000" always;
add_header X-Frame-Options "SAMEORIGIN" always;
}
location /h5/v20260811/ {
alias /usr/share/nginx/html/h5/;
index index.html;
try_files $uri /h5/v20260811/index.html;
add_header Cache-Control "no-store" always;
add_header Strict-Transport-Security "max-age=31536000" always;
add_header X-Frame-Options "SAMEORIGIN" always;
}
location /h5/ {
alias /usr/share/nginx/html/h5/;
index index.html;
try_files $uri $uri/ /h5/index.html =404;
add_header Cache-Control "no-cache, must-revalidate" always;
add_header Strict-Transport-Security "max-age=31536000" always;
add_header X-Frame-Options "SAMEORIGIN" always;
add_header X-XSS-Protection "1; mode=block" always;
add_header Referrer-Policy "no-referrer-when-downgrade" always;
add_header Permissions-Policy "geolocation=(), microphone=(), camera=()" always;
add_header Cross-Origin-Opener-Policy "same-origin" always;
add_header X-Content-Type-Options "nosniff" always;
}
# ------------------------------------------------------------------
# 静态媒体文件 — /media/ (企微下载的图片/H5上传的文件)
# 代理到后端 /api/media/ 接口(容器内路径 /app/uploads/
# ------------------------------------------------------------------
location /media/ {
proxy_pass http://backend_api/media/;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
expires 30d;
add_header Cache-Control "public, immutable";
add_header Strict-Transport-Security "max-age=31536000" always;
add_header X-Frame-Options "SAMEORIGIN" always;
add_header X-XSS-Protection "1; mode=block" always;
add_header Referrer-Policy "no-referrer-when-downgrade" always;
add_header Permissions-Policy "geolocation=(), microphone=(), camera=()" always;
add_header Cross-Origin-Opener-Policy "same-origin" always;
add_header X-Content-Type-Options "nosniff" always;
}
# ------------------------------------------------------------------
# WebSocket — /ws/
# ------------------------------------------------------------------
location /ws/ {
proxy_pass http://backend_api;
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "upgrade";
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_read_timeout 86400s;
}
# ------------------------------------------------------------------
# IT 数据查询平台 — /(根路径,反代到远程主机)
# ------------------------------------------------------------------
location / {
proxy_pass http://10.80.0.130:8080;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_connect_timeout 30s;
proxy_send_timeout 60s;
proxy_read_timeout 60s;
}
# ------------------------------------------------------------------
# 看板 / 巡检 HTML 静态目录 — /docs/
# 2026-08-06 P0-NEW7 修复(看板-部署脱节):
# - 来源:宿主 /opt/wecom-it-desk/docs-public/(由 docker-compose.yml 挂载)
# - 子目录:kanban/ 项目状态看板;inspection/YYYY-MM/ 巡检报告
# - charset utf-8 解决中文文件名编码
# - 不缓存 HTML,确保看板/报告更新后用户立即看到
# 关联:看板 v1.9.0-FROZEN 顶部服务发布策略 + scripts/deploy_kanban_to_jumpserver.sh
# ------------------------------------------------------------------
location /docs/ {
alias /opt/wecom-it-desk/docs-public/;
charset utf-8;
add_header Cache-Control "no-cache, must-revalidate" always;
add_header Content-Type "text/html; charset=utf-8" always;
try_files $uri $uri/ $uri.html =404;
autoindex off;
add_header Strict-Transport-Security "max-age=31536000" always;
add_header X-Frame-Options "SAMEORIGIN" always;
add_header X-XSS-Protection "1; mode=block" always;
add_header Referrer-Policy "no-referrer-when-downgrade" always;
add_header Permissions-Policy "geolocation=(), microphone=(), camera=()" always;
add_header Cross-Origin-Opener-Policy "same-origin" always;
add_header X-Content-Type-Options "nosniff" always;
}
add_header Strict-Transport-Security "max-age=31536000" always;
add_header X-Frame-Options "SAMEORIGIN" always;
add_header X-XSS-Protection "1; mode=block" always;
add_header Referrer-Policy "no-referrer-when-downgrade" always;
add_header Permissions-Policy "geolocation=(), microphone=(), camera=()" always;
add_header Cross-Origin-Opener-Policy "same-origin" always;
add_header X-Content-Type-Options "nosniff" always;
}
# =================================================================
# 备用:监听 80 端口(开发调试用)
# =================================================================
server {
listen 80;
server_name localhost;
# ------------------------------------------------------------------
# 健康检查端点(用于 Docker healthcheck
# ------------------------------------------------------------------
location = /itdesk/health {
access_log off;
return 200 "healthy\n";
add_header Content-Type text/plain;
add_header Strict-Transport-Security "max-age=31536000" always;
add_header X-Frame-Options "SAMEORIGIN" always;
add_header X-XSS-Protection "1; mode=block" always;
add_header Referrer-Policy "no-referrer-when-downgrade" always;
add_header Permissions-Policy "geolocation=(), microphone=(), camera=()" always;
add_header Cross-Origin-Opener-Policy "same-origin" always;
add_header X-Content-Type-Options "nosniff" always;
}
# ------------------------------------------------------------------
# H5 员工端 — /itdesk/
# ------------------------------------------------------------------
# 注意:alias + try_files $uri/ 会导致 301 重定向死循环,
# 移除 $uri/ 避免触发 nginx 的目录重定向行为
location /itdesk/ {
alias /usr/share/nginx/html/itdesk/;
index index.html;
try_files $uri /itdesk/index.html;
}
# ------------------------------------------------------------------
# 坐席工作台 — /itagent/
# ------------------------------------------------------------------
location /itagent/ {
alias /usr/share/nginx/html/itagent/;
index index.html;
try_files $uri /itagent/index.html;
}
# ------------------------------------------------------------------
# 管理后台 — /itadmin/
# ------------------------------------------------------------------
location /itadmin/ {
alias /usr/share/nginx/html/itadmin/;
index index.html;
try_files $uri /itadmin/index.html;
}
# ------------------------------------------------------------------
# 小鱼终端大屏 — /itterminal/
# ------------------------------------------------------------------
location /itterminal/ {
alias /usr/share/nginx/html/itterminal/;
index index.html;
try_files $uri /itterminal/index.html;
}
# ------------------------------------------------------------------
# 会议室 API — /itportal/meetingroom/
# 说明:终端和H5共用的会议室预定/报修/指南API
# 必须在 /itportal/ 静态文件之前匹配(nginx最长前缀优先)
# ------------------------------------------------------------------
location /itportal/meetingroom/ {
proxy_pass http://backend_api;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_connect_timeout 60s;
proxy_send_timeout 300s;
proxy_read_timeout 300s;
}
# ------------------------------------------------------------------
# ⚠️ /itportal/ 静态前端块已移除 (2026-08-03 fix)
# 历史: portal 源码 frontend-portal/ 在 commit bea288e4 (2026-07-11) 已删除,
# dist 目录不存在, alias 指向空目录导致 try_files 全部 500。
# 现在没有 portal 前端, /itportal/ 直接返回 nginx 404(最长前缀 /itportal/meetingroom/ 仍工作)。
# 关联 issue: 滴答清单任务 6a6bfc29e4b06440c36701e1 (P0)
# ------------------------------------------------------------------
# ------------------------------------------------------------------
# 后端 API — /api/
# ------------------------------------------------------------------
# ------------------------------------------------------------------
# P0-NEW9/10 安全加固:禁止公网访问调试/诊断端点
# 与 P0-NEW11 同源治理:nginx 边缘层兜底
# 仅 test-/debug- 与 metrics/version 返回 404/health、/ready 保留供探针
# ------------------------------------------------------------------
location ~ ^/api/(test-|debug/) { return 404; }
location = /api/metrics { return 404; }
location = /api/version { return 404; }
location /api/ {
proxy_pass http://backend_api/;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
# 超时设置(AI 回复可能较慢)
proxy_connect_timeout 60s;
proxy_send_timeout 300s;
proxy_read_timeout 300s;
}
# ------------------------------------------------------------------
# H5 用户端 — /h5/
# 说明:H5 是静态前端应用,必须配置为静态文件服务(alias)!
# ⚠️ 禁止改为 proxy_pass,否则返回 404(后端无 /h5/ 路由)
# 关联 CASECASE-20260714-02 / CASE-20260716-01
# ------------------------------------------------------------------
# === 2026-08-06 WAF path-cache bypass: versioned entry ===
# 精确匹配 /h5(无斜杠)→ 302 到 /h5/go,防 404
location = /h5 {
return 302 /h5/go;
}
location = /h5/go {
add_header Cache-Control "no-store" always;
return 302 /h5/v20260808/$is_args$args;
add_header Strict-Transport-Security "max-age=31536000" always;
add_header X-Frame-Options "SAMEORIGIN" always;
add_header X-XSS-Protection "1; mode=block" always;
add_header Referrer-Policy "no-referrer-when-downgrade" always;
add_header Permissions-Policy "geolocation=(), microphone=(), camera=()" always;
add_header Cross-Origin-Opener-Policy "same-origin" always;
add_header X-Content-Type-Options "nosniff" always;
}
location /itservice/v20260808/ {
alias /usr/share/nginx/html/h5/;
index index.html;
try_files $uri /itservice/v20260808/index.html;
add_header Cache-Control "no-store" always;
add_header Strict-Transport-Security "max-age=31536000" always;
add_header X-Frame-Options "SAMEORIGIN" always;
}
location /itservice/ {
alias /usr/share/nginx/html/h5/;
index index.html;
try_files $uri $uri/ /itservice/index.html =404;
add_header Cache-Control "no-store" always;
add_header Strict-Transport-Security "max-age=31536000" always;
add_header X-Frame-Options "SAMEORIGIN" always;
add_header X-XSS-Protection "1; mode=block" always;
add_header Referrer-Policy "no-referrer-when-downgrade" always;
add_header Permissions-Policy "geolocation=(), microphone=(), camera=()" always;
add_header Cross-Origin-Opener-Policy "same-origin" always;
add_header X-Content-Type-Options "nosniff" always;
}
location = /itservice {
return 302 /itservice/go;
}
location /h5/v20260808/ {
alias /usr/share/nginx/html/h5/;
index index.html;
try_files $uri /h5/v20260808/index.html;
add_header Cache-Control "no-store" always;
add_header Strict-Transport-Security "max-age=31536000" always;
add_header X-Frame-Options "SAMEORIGIN" always;
}
location /h5/ {
alias /usr/share/nginx/html/h5/;
index index.html;
try_files $uri $uri/ /h5/index.html =404;
add_header Cache-Control "no-cache, must-revalidate" always;
add_header Strict-Transport-Security "max-age=31536000" always;
add_header X-Frame-Options "SAMEORIGIN" always;
add_header X-XSS-Protection "1; mode=block" always;
add_header Referrer-Policy "no-referrer-when-downgrade" always;
add_header Permissions-Policy "geolocation=(), microphone=(), camera=()" always;
add_header Cross-Origin-Opener-Policy "same-origin" always;
add_header X-Content-Type-Options "nosniff" always;
}
# ------------------------------------------------------------------
# WebSocket — /ws/(坐席端实时通信)
# ------------------------------------------------------------------
location /ws/ {
proxy_pass http://backend_api;
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "upgrade";
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_read_timeout 86400s; # WebSocket 长连接
}
# ------------------------------------------------------------------
# IT 数据查询平台 — /(根路径,反代到远程主机)
# ------------------------------------------------------------------
# 说明:数据查询平台部署在另一台主机,
# 通过 Nginx 反代实现同一域名下访问。
# 修改 $dataquery_host 为实际 IP。
# ------------------------------------------------------------------
location / {
# 数据平台远程主机(修改为实际 IP)
# 方式1:在 /etc/nginx/nginx.conf 同目录放 env 文件
# 方式2docker-compose.yml 中通过 command 覆盖
proxy_pass http://10.80.0.130:8080; # ← 修改为数据平台实际 IP:端口
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
# 超时设置
proxy_connect_timeout 30s;
proxy_send_timeout 60s;
proxy_read_timeout 60s;
}
# ------------------------------------------------------------------
# 看板 / 巡检 HTML 静态目录 — /docs/(备用 server 也支持)
# 2026-08-06 P0-NEW7 修复:与主 server 一致
# ------------------------------------------------------------------
location /docs/ {
alias /opt/wecom-it-desk/docs-public/;
charset utf-8;
add_header Cache-Control "no-cache, must-revalidate" always;
add_header Content-Type "text/html; charset=utf-8" always;
try_files $uri $uri/ $uri.html =404;
autoindex off;
add_header Strict-Transport-Security "max-age=31536000" always;
add_header X-Frame-Options "SAMEORIGIN" always;
add_header X-XSS-Protection "1; mode=block" always;
add_header Referrer-Policy "no-referrer-when-downgrade" always;
add_header Permissions-Policy "geolocation=(), microphone=(), camera=()" always;
add_header Cross-Origin-Opener-Policy "same-origin" always;
add_header X-Content-Type-Options "nosniff" always;
}
add_header Strict-Transport-Security "max-age=31536000" always;
add_header X-Frame-Options "SAMEORIGIN" always;
add_header X-XSS-Protection "1; mode=block" always;
add_header Referrer-Policy "no-referrer-when-downgrade" always;
add_header Permissions-Policy "geolocation=(), microphone=(), camera=()" always;
add_header Cross-Origin-Opener-Policy "same-origin" always;
add_header X-Content-Type-Options "nosniff" always;
}
}