server { listen 80; server_name _; root /usr/share/nginx/html; index index.html; # SPA history fallback: unknown paths serve the app shell so client-side # routing works on hard reloads and deep links. location / { include /etc/nginx/warmbly-security-headers.conf; try_files $uri $uri/ /index.html; } # Never cache the shell or the runtime config, so a redeploy or an env # change is picked up on the next load. The hashed assets they point to are # cached immutably below. location = /index.html { include /etc/nginx/warmbly-security-headers.conf; add_header Cache-Control "no-store" always; } location = /config.js { include /etc/nginx/warmbly-security-headers.conf; add_header Cache-Control "no-store" always; } location /assets/ { include /etc/nginx/warmbly-security-headers.conf; add_header Cache-Control "public, max-age=31536000, immutable" always; } }