Entry-Point Runtime — Nginx
Heuristics the Stella Ops scanner uses to classify a container entry point as an Nginx web server or reverse proxy, plus the evidence it attaches and the edge cases it guards against. For the shared detector contracts, scoring, and calibration, see the Runtime Detector Overview. When Nginx fronts an application runtime (commonly PHP-FPM), the container is classified as a Supervisor rather than as Nginx alone.
Signals to gather
argv0equalsnginx.- Config files:
/etc/nginx/nginx.conf,conf.d/*.conf,/usr/share/nginx/html. - Environment (
NGINX_ENTRYPOINT_QUIET_LOGS,NGINX_PORT,NGINX_ENVSUBST_TEMPLATE). - Listening sockets on 80/443 (dynamic mode) or
EXPOSE 80(static). - Modules or scripts shipped with the official Docker entrypoint (
docker-entrypoint.shcollapsing tonginx -g "daemon off;").
Implementation notes
- Parse
nginx.conf(basic directive traversal) to extract worker processes, include chains, and upstream definitions. - Handle official entrypoint idioms (
envsubsttemplating) via ShellFlow. - Distinguish pure reverse proxies from PHP-FPM combos; when both
nginxandphp-fpmrun, classify the container asSupervisor. - Record static web content presence (
/usr/share/nginx/html/index.html).
Evidence & scoring
- Boost for confirmed config and workers.
- Add evidence for templating features, env substitution, or modules.
- Penalise if binary exists without config (likely not the entry point).
Edge cases
- Alpine images may place configs under
/etc/nginx/conf.d; include both. - Custom builds might rename the binary (
openresty,tengine); consider aliases if common. - Windows Nginx is not supported; fall back to
Other.
Related
- Runtime Detector Overview — shared contracts, scoring, calibration.
- Supervisor detector — Nginx + PHP-FPM (or other backend) combos.
- Entry-Point Runtime — PHP-FPM — the most common backend behind Nginx.
