server { listen 80; add_header Content-Security-Policy "upgrade-insecure-requests"; index index.php index.html; server_name localhost; root /var/www/public; location / { try_files $uri $uri/ /index.php?$query_string; } location ~ \.php$ { proxy_set_header X-Forwarded-Proto $scheme; include fastcgi_params; fastcgi_pass app:9000; fastcgi_index index.php; fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name; } location ~ /\.ht { deny all; } }