From e0c84f4248c4ce159fd993a5fae80462ec4a10c4 Mon Sep 17 00:00:00 2001 From: Felipe Knorr Kuhn Date: Fri, 22 May 2026 01:09:05 +0900 Subject: [PATCH 1/4] Upgrade nginx to 1.30.1 --- docker/frontend/Dockerfile | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docker/frontend/Dockerfile b/docker/frontend/Dockerfile index 6bbb2d5f3..a35f9a761 100644 --- a/docker/frontend/Dockerfile +++ b/docker/frontend/Dockerfile @@ -13,7 +13,7 @@ RUN npm install --omit=dev --omit=optional RUN npm run build -FROM nginx:1.27.0-alpine +FROM nginx:1.30.1-alpine WORKDIR /patch From f8175b57701d10ed902e32420fe3cfdc1454dca3 Mon Sep 17 00:00:00 2001 From: Felipe Knorr Kuhn Date: Fri, 22 May 2026 04:46:02 +0900 Subject: [PATCH 2/4] Update variables_hash_max_size --- production/nginx/nginx.conf | 2 ++ 1 file changed, 2 insertions(+) diff --git a/production/nginx/nginx.conf b/production/nginx/nginx.conf index b81321153..1dd5b279c 100644 --- a/production/nginx/nginx.conf +++ b/production/nginx/nginx.conf @@ -17,6 +17,8 @@ http { include __NGINX_ETC_FOLDER__/mime.types; default_type application/octet-stream; + variables_hash_max_size 4096; + # HTTP basic configuration include mempool/production/nginx/http-basic.conf; include mempool/production/nginx/http-acl.conf; From fce35111aa577967cc205fe208d67e370628442a Mon Sep 17 00:00:00 2001 From: Felipe Knorr Kuhn Date: Fri, 22 May 2026 09:42:31 +0900 Subject: [PATCH 3/4] Move the variables config to the right place --- nginx.conf | 1 + production/nginx/nginx.conf | 2 -- 2 files changed, 1 insertion(+), 2 deletions(-) diff --git a/nginx.conf b/nginx.conf index 670764e20..04fb11fba 100644 --- a/nginx.conf +++ b/nginx.conf @@ -10,6 +10,7 @@ events { } http { + variables_hash_max_size 4096; sendfile on; tcp_nopush on; tcp_nodelay on; diff --git a/production/nginx/nginx.conf b/production/nginx/nginx.conf index 1dd5b279c..b81321153 100644 --- a/production/nginx/nginx.conf +++ b/production/nginx/nginx.conf @@ -17,8 +17,6 @@ http { include __NGINX_ETC_FOLDER__/mime.types; default_type application/octet-stream; - variables_hash_max_size 4096; - # HTTP basic configuration include mempool/production/nginx/http-basic.conf; include mempool/production/nginx/http-acl.conf; From a09e2d2c4625d3d87249b3e675f85e611d839b24 Mon Sep 17 00:00:00 2001 From: Felipe Knorr Kuhn Date: Sun, 31 May 2026 05:29:29 +0900 Subject: [PATCH 4/4] Move var to http-basic, mirror config for Docker --- docker/frontend/Dockerfile | 2 ++ docker/init.sh | 1 + http-basic.conf | 36 ++++++++++++++++++++++++++++++ nginx.conf | 38 ++------------------------------ production/nginx/http-basic.conf | 1 + 5 files changed, 42 insertions(+), 36 deletions(-) create mode 100644 http-basic.conf diff --git a/docker/frontend/Dockerfile b/docker/frontend/Dockerfile index a35f9a761..c17f241d3 100644 --- a/docker/frontend/Dockerfile +++ b/docker/frontend/Dockerfile @@ -21,6 +21,7 @@ COPY --from=builder /build/entrypoint.sh . COPY --from=builder /build/wait-for . COPY --from=builder /build/dist/mempool /var/www/mempool COPY --from=builder /build/nginx.conf /etc/nginx/ +COPY --from=builder /build/http-basic.conf /etc/nginx/ COPY --from=builder /build/nginx-mempool.conf /etc/nginx/conf.d/ RUN chmod +x /patch/entrypoint.sh @@ -30,6 +31,7 @@ RUN chown -R 1000:1000 /patch && chmod -R 755 /patch && \ chown -R 1000:1000 /var/cache/nginx && \ chown -R 1000:1000 /var/log/nginx && \ chown -R 1000:1000 /etc/nginx/nginx.conf && \ + chown -R 1000:1000 /etc/nginx/http-basic.conf && \ chown -R 1000:1000 /etc/nginx/conf.d && \ chown -R 1000:1000 /var/www/mempool diff --git a/docker/init.sh b/docker/init.sh index 3c5ec6aa3..f1cfd222f 100755 --- a/docker/init.sh +++ b/docker/init.sh @@ -12,6 +12,7 @@ wget -O ./backend/GeoIP/GeoLite2-ASN.mmdb https://raw.githubusercontent.com/memp localhostIP="127.0.0.1" cp ./docker/frontend/* ./frontend cp ./nginx.conf ./frontend/ +cp ./http-basic.conf ./frontend/ cp ./nginx-mempool.conf ./frontend/ sed -i"" -e "s/${localhostIP}:80/0.0.0.0:__MEMPOOL_FRONTEND_HTTP_PORT__/g" ./frontend/nginx.conf sed -i"" -e "s/${localhostIP}/0.0.0.0/g" ./frontend/nginx.conf diff --git a/http-basic.conf b/http-basic.conf new file mode 100644 index 000000000..90d99c65a --- /dev/null +++ b/http-basic.conf @@ -0,0 +1,36 @@ +variables_hash_max_size 4096; +sendfile on; +tcp_nopush on; +tcp_nodelay on; + +server_tokens off; +server_name_in_redirect off; + +access_log /var/log/nginx/access.log; +error_log /var/log/nginx/error.log; + +# reset timed out connections freeing ram +reset_timedout_connection on; +# maximum time between packets the client can pause when sending nginx any data +client_body_timeout 10s; +# maximum time the client has to send the entire header to nginx +client_header_timeout 10s; +# timeout which a single keep-alive client connection will stay open +keepalive_timeout 69s; +# maximum time between packets nginx is allowed to pause when sending the client data +send_timeout 69s; + +# number of requests per connection, does not affect SPDY +keepalive_requests 1337; + +# enable gzip compression +gzip on; +gzip_vary on; +gzip_comp_level 6; +gzip_min_length 1000; +gzip_proxied expired no-cache no-store private auth; +# text/html is always compressed by gzip module +gzip_types application/javascript application/json application/ld+json application/manifest+json application/x-font-ttf application/x-web-app-manifest+json application/xhtml+xml application/xml font/opentype image/bmp image/svg+xml image/x-icon text/cache-manifest text/css text/plain text/vcard; + +# limit request body size +client_max_body_size 10m; diff --git a/nginx.conf b/nginx.conf index 04fb11fba..c6b261cb0 100644 --- a/nginx.conf +++ b/nginx.conf @@ -10,46 +10,12 @@ events { } http { - variables_hash_max_size 4096; - sendfile on; - tcp_nopush on; - tcp_nodelay on; - - server_tokens off; - server_name_in_redirect off; + # HTTP basic configuration + include /etc/nginx/http-basic.conf; include /etc/nginx/mime.types; default_type application/octet-stream; - access_log /var/log/nginx/access.log; - error_log /var/log/nginx/error.log; - - # reset timed out connections freeing ram - reset_timedout_connection on; - # maximum time between packets the client can pause when sending nginx any data - client_body_timeout 10s; - # maximum time the client has to send the entire header to nginx - client_header_timeout 10s; - # timeout which a single keep-alive client connection will stay open - keepalive_timeout 69s; - # maximum time between packets nginx is allowed to pause when sending the client data - send_timeout 69s; - - # number of requests per connection, does not affect SPDY - keepalive_requests 1337; - - # enable gzip compression - gzip on; - gzip_vary on; - gzip_comp_level 6; - gzip_min_length 1000; - gzip_proxied expired no-cache no-store private auth; - # text/html is always compressed by gzip module - gzip_types application/javascript application/json application/ld+json application/manifest+json application/x-font-ttf application/x-web-app-manifest+json application/xhtml+xml application/xml font/opentype image/bmp image/svg+xml image/x-icon text/cache-manifest text/css text/plain text/vcard; - - # limit request body size - client_max_body_size 10m; - # proxy cache proxy_cache off; proxy_cache_path /var/cache/nginx keys_zone=cache:20m levels=1:2 inactive=600s max_size=500m; diff --git a/production/nginx/http-basic.conf b/production/nginx/http-basic.conf index fd5cc4b94..8988ce74c 100644 --- a/production/nginx/http-basic.conf +++ b/production/nginx/http-basic.conf @@ -1,4 +1,5 @@ # basics +variables_hash_max_size 4096; sendfile on; tcp_nopush on; tcp_nodelay on;