server { # Host networking is required for the loopback-only Archipelago RPC. # Keep nginx itself on loopback so the authenticated app gate owns every # externally reachable listener. listen 127.0.0.1:8337; server_name _; root /usr/share/nginx/html; index index.html; location = /healthz { access_log off; default_type text/plain; return 200 "ok\n"; } location = /manifest.webmanifest { default_type application/manifest+json; try_files $uri =404; } location = /app/archipelago-source/manifest.webmanifest { default_type application/manifest+json; rewrite ^/app/archipelago-source/(.*)$ /$1 break; try_files $uri =404; } # The normal dashboard proxy strips this prefix before forwarding, while # direct app-gate access preserves it. Supporting both keeps health/debug # access useful without making launch depend on any particular interface. location ^~ /app/archipelago-source/ { rewrite ^/app/archipelago-source/(.*)$ /$1 break; try_files $uri $uri/ /index.html; add_header X-Content-Type-Options "nosniff" always; add_header Referrer-Policy "strict-origin-when-cross-origin" always; } location / { try_files $uri $uri/ /index.html; add_header X-Content-Type-Options "nosniff" always; add_header Referrer-Policy "strict-origin-when-cross-origin" always; } }