Sign inSign up

absalomedia/sass-speed

By absalomedia

•Updated over 9 years ago

Nginx + Pagespeed + SASS modules

Image
0

516

absalomedia/sass-speed repository overview

⁠Nginx + Pagespeed + OpenSSL + SASS

Nginx 1.12.0 Pagespeed 1.13.34.2 OpenSSL 1.1.0e Sass for Nginx using Libsass 3.4.4

Built on a lightly modified Ubuntu Xenial⁠ base

⁠TLDR;

docker run -v "/path/to/www:/app/www" -p "80:80" -p "443:443" absalomedia/sass-speed

Nginx is compiled from mainline source, if you would like to build the stable version, clone this repository and edit the NGINX_VERSION number to suit.

Files are served from /app/www/

SSL configuration is stored in /etc/nginx/ssl

Nginx reads /etc/nginx/sites-enabled for its virtual hosts, and comes with some sane defaults for out-of-the-box webserving.

⁠Environment

Nginx is configurable via environment variables, which are applied to the configuration on each service start, so you can adjust server parameters on the fly with, for example:

export "UPLOAD_MAX_SIZE=10M"; sv restart nginx
variablevalue
APP_USERnginx
APP_GROUPnginx
UPLOAD_MAX_SIZE30M
NGINX_MAX_WORKER_PROCESSES8
docker run -e "UPLOAD_MAX_SIZE=10M" absalomedia/nginx-pagespeed
⁠On service start
  • nginx user is set to ${APP_USER:-$DEFAULT_APP_USER} (default is nginx)
  • adds user and group from {APP_USER:-$DEFAULT_APP_USER}:${APP_GROUP:-$DEFAULT_APP_GROUP}, some sanity checks for matching UID / GID
  • if ${CHOWN_APP_DIR:-$DEFAULT_CHOWN_APP_DIR} is true, chown -R ${APP_USER:-$DEFAULT_APP_USER}:${APP_GROUP:-$DEFAULT_APP_GROUP} /app/www\ (default true)
  • worker_processes is set to the number of available processor cores and adjusts /etc/nginx/nginx.conf to match, up to a maximum number of cores ${NGINX_MAX_WORKER_PROCESSES:-$DEFAULT_MAX_WORKER_PROCESSES}
  • client_max_body_size is set to ${UPLOAD_MAX_SIZE:-$DEFAULT_UPLOAD_MAX_SIZE}
⁠Security

Nginx is compiled from mainline source according to Ubuntu compile flags, with the following modifcations:

HTTPS is configured using modern sane defaults, including

  • Mozilla's intermediate cipher string - see https://wiki.mozilla.org/Security/Server_Side_TLS⁠
  • SSLv2 and SSLv3 are disabled, TLSv1 TLSv2 and TLSv3 are enabled
  • Automatic generation of a 2048bit DH parameter file if one is not provided
  • Self-signed SSL certificates are generated on build, and stored in /etc/nginx/ssl/default.key /etc/nginx/ssl/default.crt. To install your own certificates I recommend creating an ssl and sites-enabled folder and mounting these folders as volumes, alongside your www volume.

Nginx changelog: http://nginx.org/en/CHANGES⁠

⁠Docker Compose

An example docker-compose.yml file:

app:
  image: absalomedia/sass-speed
  ports:
    - "80:80"
    - "443:443"
  volumes:
    - /path/to/www:/app/www
    - /path/to/ssl:/etc/nginx/ssl
    - /path/to/sites-enabled:/etc/nginx/sites-enabled
  environment:
    - UPLOAD_MAX_SIZE=100M

Tag summary

Content type

Image

Digest

sha256:3e23d178f…

Size

344.6 MB

Last updated

over 9 years ago

docker pull absalomedia/sass-speed