From 376f9f6c0848d10adb2b21b1dca3e81be9178d80 Mon Sep 17 00:00:00 2001 From: ivan Date: Mon, 7 Sep 2026 13:52:56 +0500 Subject: [PATCH] ++ --- apps/django/brusnika-stage/kustomization.yaml | 1 + .../brusnika-stage/nginx-configmap.yaml | 177 ++++++++++++++++++ 2 files changed, 178 insertions(+) create mode 100644 apps/django/brusnika-stage/nginx-configmap.yaml diff --git a/apps/django/brusnika-stage/kustomization.yaml b/apps/django/brusnika-stage/kustomization.yaml index d2c4921..92074a1 100644 --- a/apps/django/brusnika-stage/kustomization.yaml +++ b/apps/django/brusnika-stage/kustomization.yaml @@ -3,6 +3,7 @@ apiVersion: kustomize.config.k8s.io/v1beta1 kind: Kustomization namespace: django resources: + - nginx-configmap.yaml - sarex-frontend.yaml - sarex-backend.yaml - celery.yaml diff --git a/apps/django/brusnika-stage/nginx-configmap.yaml b/apps/django/brusnika-stage/nginx-configmap.yaml new file mode 100644 index 0000000..776662c --- /dev/null +++ b/apps/django/brusnika-stage/nginx-configmap.yaml @@ -0,0 +1,177 @@ +--- +apiVersion: v1 +kind: ConfigMap +metadata: + name: nginx-configmap + namespace: django +data: + nginx.conf: | + worker_processes auto; + + pid /var/run/nginx.pid; + + events { + use epoll; + worker_connections 1024; + } + + http { + + # Basic Settings + large_client_header_buffers 8 128k; + sendfile on; + tcp_nopush on; + tcp_nodelay on; + keepalive_timeout 300; + types_hash_max_size 2048; + client_max_body_size 5000M; + client_header_buffer_size 5M; + # server_tokens off; + # server_names_hash_bucket_size 64; + # server_name_in_redirect off; + include /etc/nginx/mime.types; + default_type application/octet-stream; + + # Logging Settings + access_log /var/log/nginx/access.log; + error_log /var/log/nginx/error.log; + + # GZIP Settings + gzip on; + gzip_vary on; + gzip_proxied any; + gzip_comp_level 6; + gzip_buffers 16 8k; + gzip_http_version 1.1; + gzip_types text/plain text/css application/json application/javascript text/xml application/xml application/xml+rss text/javascript; + + log_format main '$remote_addr - $remote_user [$time_local] "$request" ' + '$status $body_bytes_sent "$http_referer" ' + '"$http_user_agent" "$http_x_forwarded_for"'; + + server { + listen 80; + listen [::]:80; + root /opt/react_client/; + + add_header 'Access-Control-Allow-Origin' '*' always; + add_header 'Access-Control-Allow-Methods' '*' always; + add_header 'Access-Control-Allow-Headers' '*' always; + + location = /static/index.bundle.js { + add_header Cache-Control 'no-store no-cache, must-revalidate, proxy-revalidate, max-age=0'; + if_modified_since off; + expires off; + } + + location ~^/api/pm/ { + proxy_set_header Host $host; + proxy_pass http://backend-svc.pm.svc.cluster.local:8000; + } + + location ~^/(api|admin)/ { + proxy_set_header Host $host; + proxy_pass http://backend:8000; + } + + location ~^/flows/static/ { + rewrite /flows/static/(.+) /$1 break; + proxy_pass http://frontend-service.flows:80; + } + + location = ~^/orchestrator/ { + rewrite ^/orchestrator$ /api/ break; + proxy_pass http://cde.orchestrator.svc.cluster.local:8080; + } + + location = ~^/orchestrator/api/process { + rewrite ^/orchestrator/api/process$ /api/process break; + proxy_pass http://cde.orchestrator.svc.cluster.local:8080; + } + + location ~ ^/orchestrator/api/process/(.*)$ { + rewrite ^/orchestrator/api/process/(.*)$ /api/process/$1 break; + proxy_pass http://cde.orchestrator.svc.cluster.local:8080; + } + + location = ~^/orchestrator/api/sign { + rewrite ^/orchestrator/api/sign$ /api/sign break; + proxy_pass http://cde.orchestrator.svc.cluster.local:8080; + } + + location = /static/pdf-runtime/assets/mupdf-wasm.wasm { + alias /opt/react_client/static/pdf-runtime/assets/mupdf-wasm.wasm; + add_header Content-Type application/wasm always; + add_header Cache-Control "public, max-age=31536000, immutable" always; + add_header Access-Control-Allow-Origin "*" always; + add_header Access-Control-Allow-Methods "GET, OPTIONS" always; + add_header Access-Control-Allow-Headers "DNT,Keep-Alive,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range,Authorization" always; + } + + location = /workspaces-v2/worker/static/viewer-pdf/mupdf-wasm.js { + alias /opt/react_client/static/viewer-pdf/mupdf-wasm.js; + add_header Content-Type application/javascript always; + add_header Cache-Control "public, max-age=31536000, immutable" always; + add_header Access-Control-Allow-Origin "*" always; + add_header Access-Control-Allow-Methods "GET, OPTIONS" always; + add_header Access-Control-Allow-Headers "DNT,Keep-Alive,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range,Authorization" always; + } + + location = /workspaces-v2/worker/mupdf.worker-3.3.9.js { + alias /opt/react_client/static/pdf-runtime/mupdf.worker-3.3.9.js; + add_header Content-Type application/javascript always; + add_header Cache-Control "public, max-age=31536000, immutable" always; + add_header Access-Control-Allow-Origin "*" always; + add_header Access-Control-Allow-Methods "GET, OPTIONS" always; + add_header Access-Control-Allow-Headers "DNT,Keep-Alive,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range,Authorization" always; + } + + location = /workspaces-v2/worker/static/viewer-pdf/mupdf.js { + alias /opt/react_client/static/viewer-pdf/mupdf.js; + add_header Content-Type application/javascript always; + add_header Cache-Control "public, max-age=31536000, immutable" always; + add_header Access-Control-Allow-Origin "*" always; + add_header Access-Control-Allow-Methods "GET, OPTIONS" always; + add_header Access-Control-Allow-Headers "DNT,Keep-Alive,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range,Authorization" always; + } + + location = /workspaces-v2/worker/static/viewer-pdf/mupdf-wasm.wasm { + add_header Content-Type application/wasm always; + alias /opt/react_client/static/viewer-pdf/mupdf-wasm.wasm; + } + + location ~ ^/workspaces-v2/(.+)\.wasm$ { + rewrite /workspaces-v2/(.+) /$1 break; + proxy_pass http://workspaces-v2-frontend-static-service.workspaces.svc.cluster.local:8080; + + add_header Content-Type application/wasm; + proxy_set_header Accept application/wasm; + } + + location ~ ^/workspaces-v2/(.+)\.js$ { + rewrite /workspaces-v2/(.+) /$1 break; + proxy_pass http://workspaces-v2-frontend-static-service.workspaces.svc.cluster.local:8080; + } + + location @index { + add_header Cache-Control 'no-cache, must-revalidate, proxy-revalidate, max-age=0'; + if_modified_since off; + expires off; + try_files /static/index.html =404; + } + + location ~^/workflows/(.+).js { + rewrite /workflows/(.+) /$1 break; + proxy_pass http://frontend-servece.workflow.svc.cluster.local:8080; + } + + + location /service-worker.js { + try_files /static/$uri @index; + } + + location / { + try_files $uri @index; + } + } + }