# Run nginx in foreground. daemon off; # This is run inside Docker. user root; # Pid storage location. pid /var/run/nginx.pid; # Set number of worker processes. worker_processes 1; # Enables the use of JIT for regular expressions to speed-up their processing. pcre_jit on; # Write error log to Hass.io add-on log. error_log /proc/1/fd/1 error; # Load allowed environment vars env HASSIO_TOKEN; # Load dynamic modules. include /etc/nginx/modules/*.conf; # Max num of simultaneous connections by a worker process. events { worker_connections 512; } http { include /etc/nginx/includes/mime.types; log_format hassio '[$time_local] $status ' '$http_x_forwarded_for($remote_addr) ' '$request ($http_user_agent)'; access_log /proc/1/fd/1 hassio; client_max_body_size 4G; default_type application/octet-stream; gzip on; keepalive_timeout 65; sendfile on; server_tokens off; tcp_nodelay on; tcp_nopush on; map $http_upgrade $connection_upgrade { default upgrade; '' close; } # Ingress needs Portainer to answer uncompressed, so the responses carry a # Content-Length and stay on the relay's buffered path. Direct access on # 9099 does not go through the relay, so it keeps compression. # Keyed on the direct-access port rather than the ingress port: the ingress # port is templated from the add-on config, so defaulting to identity keeps # ingress correct even if that port ever changes. map $server_port $upstream_accept_encoding { default identity; 9099 $http_accept_encoding; } include /etc/nginx/includes/resolver.conf; include /etc/nginx/includes/upstream.conf; include /etc/nginx/servers/*.conf; }