Files
garden-astro/deploy/nginx.conf
T
wesandClaude Opus 5 9da9a6cba2 Publish opted-in marimo notebooks at /notebooks
Notebooks from the marimo server can now appear in the garden. A notebook
opts in with an HTML comment in one of its markdown cells — invisible when
rendered, greppable in the .py source:

    <!-- garden:publish
    title: Dream of Spotification
    order: 30
    -->

Default-deny on purpose: garden.c0smere.net is public and the export bakes
each notebook's executed output into the page, not just its code.
export-notebooks.py also carries a NEVER_PUBLISH list (genome_*, coursework)
so a marker pasted into one of those refuses loudly instead of publishing.

Pipeline: export-notebooks.py runs each marked notebook in a one-shot
marimo container (same image/env/GPU as the live server, so it hits the real
databases) into notebooks-export/ + index.json; copy-notebooks.mjs stages
those to public/nb/; Astro reads index.json to build the pages and the
sidebar section.

Isolation choices worth keeping:

- Own timer and own lock, separate from the 5-min garden build — executing a
  notebook takes minutes and must never hold up a build tick.
- Cached on notebook content; both index.json and .cache.json go through
  write_if_changed, since auto-build.sh hashes mtimes under notebooks-export/
  and an unconditional rewrite would force a full rebuild every 30 minutes.
- Per-notebook timeout; a failure keeps the previous export and continues.
- Runs against a throwaway copy of the notebook dir, so notebooks that write
  scratch files don't dirty the notebooks repo.
- Notebooks are NOT injected into the garden collection — they aren't vault
  notes, and doing so would move noteCount and the sitemap.

build.format:'file' makes the listing a file (notebooks.html) beside a
directory of detail pages. Verified against the running nginx: /notebooks and
/notebooks/<slug> resolve through the generic try_files but /notebooks/ does
not, so nginx.conf gets an explicit location for the trailing-slash form.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-07-29 22:07:14 -04:00

33 lines
946 B
Nginx Configuration File

server {
listen 80;
server_name _;
root /usr/share/nginx/html;
charset utf-8;
# Quartz-compatible URLs: /A/B -> A/B.html, /Folder/ -> Folder/index.html
location / {
try_files $uri $uri.html $uri/index.html =404;
}
# The notebooks listing builds to notebooks.html *and* has a sibling
# notebooks/ directory of detail pages. try_files above resolves
# /notebooks and /notebooks/<slug>, but not the trailing-slash form —
# a bare directory has no index.html. Map it explicitly so every folder
# URL on the site keeps working with or without the slash.
location = /notebooks/ {
try_files /notebooks.html =404;
}
location /assets/ {
expires 7d;
add_header Cache-Control "public";
}
location /_astro/ {
# content-hashed filenames — safe to cache hard
expires 365d;
add_header Cache-Control "public, immutable";
}
}