server { listen ${PORT}; server_name localhost; root /app/www; # Security headers add_header X-Frame-Options "SAMEORIGIN"; add_header X-XSS-Protection "1; mode=block"; add_header X-Content-Type-Options "nosniff"; # Compression gzip on; gzip_types text/plain text/css application/json application/javascript text/xml application/xml application/xml+rss text/javascript; location / { try_files $uri $uri/ /index.html; expires -1; } # Cache static assets location /assets { expires 1y; add_header Cache-Control "public, no-transform"; } }