# Map ISO timestamp to date-only string for daily log rotation map $time_iso8601 $log_date { "~^(?\d{4}-\d{2}-\d{2})" $date; default "unknown"; } log_format kmtn_json escape=json '{' '"time":"$time_iso8601",' '"remote_addr":"$remote_addr",' '"x_forwarded_for":"$http_x_forwarded_for"' '}'; access_log /logs/access-$log_date.log kmtn_json; server { listen 80; server_name _; root /usr/share/nginx/html; index index.html; # SPA fallback — Angular router handles its own paths location / { try_files $uri $uri/ /index.html; } # Proxy API calls to the backend service location /api/ { proxy_pass __API_UPSTREAM__; proxy_set_header Host $host; proxy_set_header Origin $http_origin; proxy_set_header Referer $http_referer; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $http_x_forwarded_proto; proxy_set_header X-Forwarded-Host $host; # Disable caching through the double-proxy chain (NPM → frontend nginx → API) # Without this, browsers cache responses keyed by the HTTPS origin, then send # conditional requests (If-None-Match) that get lost or mismatched in the proxy chain. proxy_cache off; add_header Cache-Control "no-store, no-cache, must-revalidate" always; add_header Pragma "no-cache" always; add_header Vary "*" always; } }