Keep /var/www/html/ and identities owned by root, so nobody else can write
diff --git a/nginx/Dockerfile.entrypoint b/nginx/Dockerfile.entrypoint
index 515301c..05e17b4 100644
--- a/nginx/Dockerfile.entrypoint
+++ b/nginx/Dockerfile.entrypoint
@@ -29,7 +29,7 @@
     done
 }
 
-chown -R nginx:nginx /var/www/html/
+chown -R root:root /var/www/html/
 
 chmod -R a-w /etc/nginx/certs/ /etc/nginx/conf.d/sa.conf /var/www/html/