server { listen 80; listen [::]:80; root /usr/share/nginx/html; index index.html; # SPA fallback — toutes les routes vers index.html location / { try_files $uri $uri/ /index.html; } # Proxy vers le backend pour les routes API (v1 et Admin) location /api/ { proxy_pass http://backend:7000; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; } # Proxy pour les fichiers signés (thumbnails, downloads) location /files/ { proxy_pass http://backend:7000; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; } location /admin/api/ { proxy_pass http://backend:7000; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; } location /ws/ { proxy_pass http://backend:7000; proxy_http_version 1.1; proxy_set_header Upgrade $http_upgrade; proxy_set_header Connection "upgrade"; } location /health { proxy_pass http://backend:7000; } location /metrics { proxy_pass http://backend:7000; } # Cache agressif pour les assets buildés (hash dans le nom) location ~* \.(js|css|png|svg|woff2)$ { expires 1y; add_header Cache-Control "public, immutable"; } }