# nginx config for CRDC Arrests Demo — static SPA + API reverse proxy with CORS. # When served via Docker, this proxies /api/v1/ requests to the CRDC API server-side, # adding Access-Control-Allow-Origin: * so browser-based fetch works without issues. server { listen 80; server_name _; # Proxy all /api/v1/ requests to the CRDC Arrest Rate API with CORS headers location /api/v1/ { proxy_pass https://crdc-api.civilytics.org/api/v1/; proxy_set_header Host crdc-api.civilytics.org; proxy_ssl_verify off; # Add CORS headers so browser-based requests work add_header Access-Control-Allow-Origin "*" always; add_header Access-Control-Allow-Methods "GET, OPTIONS" always; add_header Access-Control-Allow-Headers "*" always; if ($request_method = 'OPTIONS') { return 204; } } # Also support a simple proxy endpoint for git-pages-style deployments location /crdc-demo/proxy/ { # Extract the target path from query string and forward to CRDC API proxy_pass https://crdc-api.civilytics.org$arg_target; proxy_set_header Host crdc-api.civilytics.org; proxy_ssl_verify off; add_header Access-Control-Allow-Origin "*" always; add_header Access-Control-Allow-Methods "GET, OPTIONS" always; } # Serve static files from the Vite build output root /usr/share/nginx/html/crdc-demo/; # Adjust if base is different index index.html; location / { try_files $uri $uri/ /index.html; } # Civilytics design tokens: immutable cache headers for static assets location ~* \.(js|css|png|jpg|jpeg|gif|svg|woff2|ttf)$ { expires 1y; add_header Cache-Control "public, max-age=31536000, immutable"; try_files $uri =404; } # Health check endpoint for container orchestration location /healthz { access_log off; return 200 "ok"; add_header Content-Type text/plain; } }