server {
    listen [::]:80 default_server ipv6only=off;
    return 301 https://$host$request_uri;
}

server {
    listen [::]:443 ssl http2 default_server ipv6only=off;

    add_header Strict-Transport-Security "max-age=31536000;";

    root /srv/portal;
    index index.html;

    location / {
        try_files $uri $uri/ =404;
    }
}