server { listen 80; server_name _; root /usr/share/nginx/html; index index.html; # 前端静态资源 / SPA 回退 location / { try_files $uri $uri/ /index.html; } # 网关隔离:SSG 内部接口只存在于 backend 的 8091 端口(回环绑定,nginx 不反代)。 # 若有人从公网域名探测 /api/ssg/*,此处直接 404,确保构建期全量数据绝不从公网出口。 location /api/v1/ssg/ { return 404; } # 反向代理后端 API:浏览器走同源 /api,由 nginx 转发到 backend 容器(仅 8090 公开端口) location /api/ { proxy_pass http://backend:8090/; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; } }