armokweb
armokweb copied to clipboard
Serve static files with nginx outside the container
We should assume that the container could get completely compromised if a malicious user enters the right DFHack Lua commands. Only proxy into it for accessing the websocket API endpoint; don't just blindly proxy to it for everything.