nginx-configNGINX 1.30.5

Reverse proxy, workload, runtime image, and generator research

Research checked on 2026-09-20 and updated on 2026-10-01 for the Astro builder and the TypeScript renderer (schema v2). Sources are upstream NGINX, Docker, and GitHub documentation. This note separates documented behavior from choices that still need a workload test; there is no universally fastest buffer, timeout, cache size, or connection count.

Current baseline

Reverse proxy rules

Connections and headers

Buffering, streams, timeouts, and retries

Proxy cache is opt-in

Workload presets

Static files and SPA

Go and other HTTP services

PHP-FPM

Safe generator architecture

Runtime image

GHCR publishing

Acceptance checks

  1. Every generated preset and checked-in example passes nginx -t inside the pinned free stable 1.30.5 image.
  2. Generator snapshots cover every option alone and the supported combinations; hostile values containing newline, semicolon, brace, comment, or whitespace are rejected before rendering.
  3. An echo backend proves a forged incoming X-Forwarded-For, X-Real-IP, Forwarded, and X-Forwarded-Proto cannot override the edge identity. When trusted-load-balancer normalization is added manually, a separate test proves only an allowlisted hop changes $remote_addr.
  4. Cache tests prove authorized/session requests bypass the cache, Set-Cookie responses are not stored, different Host values cannot share an object, and only GET/HEAD populate the public cache.
  5. An SSE test receives the first event promptly and keeps the connection alive with heartbeat data. A WebSocket test completes a 101 upgrade and echo.
  6. Upload tests cover just below and above client_max_body_size. The response-streaming option keeps proxy_request_buffering on while disabling response buffering. A separately reviewed upload-streaming location, when used, must prove that the backend receives data before the full body arrives; the normal location buffers it.
  7. Retry tests fail the first backend and succeed on the second for an idempotent request, then prove a sent POST is not duplicated.
  8. Static/SPA tests prove a real asset is served, a missing asset returns 404, an application route falls back to index.html, hashed assets are immutable, and index.html is revalidated.
  9. PHP tests prove only an existing .php file reaches PHP-FPM, in any letter case. Proxy tests prove host, scheme, and normalized client address, upstream connection reuse, and that an untrusted sender cannot set them. HTTPS-upstream tests fail an untrusted certificate.
  10. The built runtime runs as UID 101, starts with a read-only root and only /tmp writable, has no Linux capabilities, becomes healthy through HTTP, serves its default or mounted site on 8080 for Host: localhost, and rejects unknown hosts without serving application content.
  11. Pull-request CI builds without registry credentials. A trusted branch/tag dry run produces the expected OCI labels and tags; the publish job uses only GITHUB_TOKEN, pushes GHCR successfully when triggered, and emits an attestation tied to the pushed digest.