feat: per-file Cache-Control, navigation-scoped SPA fallback, nosniff, non-root image; v1.7.0

- Cache-Control per file: no-cache for index.html + service workers, immutable 1y for
  content-hashed assets, 1h for the rest (Vite/CRA/Angular). Closes the stale-release
  trap at the HTTP layer that the v1.6.0 image fix closed at the container layer.
- SPA fallback scoped to navigation: a missing asset (path w/ extension) or a non-HTML
  Accept now returns 404 instead of index.html (no more HTML-as-JS 'Unexpected token <').
- X-Content-Type-Options: nosniff on every response.
- Image runs as a non-root 'spa' user.
- README: caching table, fallback contract, and the Angular dist/<project>/browser/ note.
This commit is contained in:
2026-08-18 17:55:56 -06:00
parent bbc588d933
commit b73b9ee022
9 changed files with 343 additions and 18 deletions
+7 -1
View File
@@ -10,7 +10,8 @@ RUN CGO_ENABLED=0 GOOS=linux go build \
./cmd/spa-server
FROM alpine:3.21
RUN apk add --no-cache ca-certificates tzdata
RUN apk add --no-cache ca-certificates tzdata \
&& addgroup -S spa && adduser -S -G spa -H -s /sbin/nologin spa
WORKDIR /app
COPY --from=builder /app/spa-server .
@@ -32,5 +33,10 @@ LABEL dev.nochebuena.healthz="/health"
# previous build — a silent stale deploy (worse for PWAs, whose service worker then
# caches the stale ngsw.json). A runtime bind-mount works with or without it, and a
# child image cannot un-declare an inherited VOLUME, so it must not be declared at all.
# Drop root: the server is a static binary serving read-only files on a >1024 port,
# so it needs no privilege. COPY'd assets are world-readable, so the unprivileged
# user reads /srv/www without a chown.
USER spa
EXPOSE 8080
ENTRYPOINT ["/app/spa-server"]