# ========================================================================== # Acepla — Configuración nginx para servir el sitio estático # Optimizada para: gzip, cache de assets, security headers, rutas limpias # ========================================================================== server { listen 80; server_name _; root /usr/share/nginx/html; index index.html; # ---- Security headers ---- server_tokens off; add_header X-Frame-Options "SAMEORIGIN" always; add_header X-Content-Type-Options "nosniff" always; add_header X-XSS-Protection "1; mode=block" always; add_header Referrer-Policy "strict-origin-when-cross-origin" always; # ---- Gzip ---- gzip on; gzip_vary on; gzip_min_length 256; gzip_proxied any; gzip_comp_level 6; gzip_types text/plain text/css text/xml text/javascript application/javascript application/x-javascript application/json application/xml application/xml+rss image/svg+xml font/woff font/woff2; # ---- Cache de assets estáticos (1 año) ---- location ~* \.(js|css|png|jpg|jpeg|gif|ico|svg|webp|woff|woff2|ttf|eot)$ { expires 1y; add_header Cache-Control "public, immutable"; add_header Vary Accept; access_log off; log_not_found off; } # ---- PDFs ---- location ~* \.pdf$ { expires 7d; add_header Cache-Control "public"; access_log off; } # ---- Bloquear acceso a archivos sensibles ---- location ~ /\. { deny all; access_log off; log_not_found off; } location ~* /\.(php|sql|env|git|htaccess) { deny all; access_log off; } # ---- Rutas: intentar archivo, luego directorio, luego 404 ---- location / { try_files $uri $uri/ $uri.html $uri/index.html =404; } # ---- Página 404 personalizada ---- error_page 404 /404/index.html; # ---- Compresión Brotli (si el módulo está disponible) ---- # brotli on; # brotli_comp_level 6; # brotli_types text/css application/javascript application/json image/svg+xml; }