:80 { redir https://projekt-kiq.d-hive.de{uri} permanent } projekt-kiq.d-hive.de { root * /opt/projekt-kiq/site encode zstd gzip header { Strict-Transport-Security "max-age=31536000" X-Content-Type-Options "nosniff" X-Frame-Options "DENY" Referrer-Policy "strict-origin-when-cross-origin" Permissions-Policy "camera=(), geolocation=(), microphone=()" Content-Security-Policy "default-src 'self'; base-uri 'self'; object-src 'none'; frame-ancestors 'none'; form-action 'self'; script-src 'self'; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; font-src 'self' https://fonts.gstatic.com data:; img-src 'self' data:; connect-src 'self'" } # Reverse proxy API requests to Express backend handle /api/* { reverse_proxy localhost:3003 } @assets path /assets/* handle @assets { header Cache-Control "public, max-age=31536000, immutable" file_server } handle { header Cache-Control "no-cache, no-store, must-revalidate" try_files {path} /index.html file_server } }