server { # Loopback ONLY. This container is host-networked, so this nginx binds the # HOST's address directly — `listen 8175;` meant every interface, and the # app gate could never stand in front of it (there is no podman publish to # pin, and the manifest declared no port, so the gate neither protected it # nor reported it — it served this page to anyone who asked, on LAN, # Tailscale and the mesh alike). Binding loopback lets the daemon claim the # external addresses and authenticate them; see appgate::listener. listen 127.0.0.1:8175; server_name _; proxy_intercept_errors on; error_page 500 502 503 504 = @wait_page; # Serve our own wait-page/icon assets locally first, but fall back to the # real fedimint guardian (:8177) for ITS bundled /assets/*.css|js. Without # the fallback, the guardian UI's stylesheets resolve to this local root, # 404, and the app renders unstyled (B13 fixed the local icon; this fixes # the guardian UI's own CSS). location /assets/ { root /usr/share/nginx/html; add_header Cache-Control "public, max-age=3600" always; try_files $uri @guardian_assets; } location @guardian_assets { proxy_pass http://127.0.0.1:8177; proxy_http_version 1.1; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; } location / { proxy_pass http://127.0.0.1:8177; proxy_http_version 1.1; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; proxy_set_header Upgrade $http_upgrade; proxy_set_header Connection "upgrade"; } location @wait_page { root /usr/share/nginx/html; add_header Cache-Control "no-store" always; try_files /index.html =503; } }